Pourquoi un certificat SSL, lequel?

pourquoi-ssl

Offer a trustworthy environment ...

Discover Keynectis

Attention: open in a new window. PrintE-mail

Focus on how the Certify.Center® signature and signature validation solution works

Signature and signature validation: How does it work?

A signature and signature validation system is a system on a network that is accessible by applications that use a calling client to query it. This system must allow synchronous queries, i.e. it must immediately respond to any and all requests. The diagram below illustrates the operational flow of a signature or signature validation request.

 

Illustration of how a signature and signature validation solution works

 

Concretely, the client creates either a hash of the digital file to be signed or the document itself and then sends it to the Certify.Center® signature system. The signature system takes this information as input, signs it with the certificate associated with the calling client, and then adds a timestamp proof and proof of OCSP validation. This creates the document signature, which is immediately returned online to the calling client. From this point forward, the client can validate it, store it, link it to the initial digital file, and so on.

Main features of the Certify.Center® centralized signature and signature validation solution from Keynectis

The main features of the Certify.Center® software from Keynectis are:

  • Management of several signature and signature validation formats:
    • PDF (with automatic signature recognition by Adobe tools)
    • XADES format, widely used by European public administration
    • CMS or PKCS#7 for traditional signature applications
  • Multiple signature or signature validation instances with the same software license: several signature or signature validation services can be provided from the same platform hosting a single Certify.Center® license
  • High performance
  • High system or service availability with possible use of load balancing
  • Integration with RFC3161-compliant servers or timestamping services enabling easy integration and guaranteed interoperability.
  • Integration with RFC2560-compliant servers or validation services enabling easy integration and guaranteed interoperability.
  • Signature or signature validation request interface secured via SSL channel, with possible mutual authentication
  • Signature system security based on the use of hardware security modules (HSM) via the PKCS#11 protocol
  • Remote administration interface via Web pages: ease of use