【24h】

Digital Signatures Workflows in Alfresco

机译:Alfresco中的数字签名工作流程

获取原文

摘要

There are some obstacles, towards a paperless office. One of them is the collection of signatures, since nearly half of all documents are printed for the sole purpose of collecting them. Digital signatures can have the same legal evidential validity as handwritten signatures, provided they are based on certificates issued by accredited certification authorities and the associated private keys are stored on tamper proof token security devices like smart cards. In this article, we propose a platform for secure digital signature workflow management that integrates secure token based digital signatures with the Enterprise Content Management Alfresco, where each user can associate a set of smart cards to his account. The documents can then be signed with the citizen card or other smart card that has digital signatures capabilities. We have implemented an Alfresco module that allows us to explore several workflow techniques to implement real task secure digital signatures workflows, as people for example do when they pass a paper document between various departments to be signed. Since all users can see the current state of the documents being signed during the entire signage process, important security properties like system trust are preserved. We also describe an external validation web service, that provides a way for users to validate signed documents. The validation service then shows to the user important document security properties like timestamps, certificates attributes and highlights the document integrity in face of the digital signatures that have been collected in the workflows defined by our module in Alfresco.
机译:无纸化办公室存在一些障碍。其中之一是签名的收集,因为几乎所有文档的一半都是出于收集签名的目的而打印的。数字签名可以具有与手写签名相同的法律证据效力,但前提是它们基于授权的证书颁发机构颁发的证书,并且相关的私钥存储在防篡改令牌安全设备(如智能卡)中。在本文中,我们提出了一个用于安全数字签名工作流管理的平台,该平台将基于安全令牌的数字签名与企业内容管理Alfresco集成在一起,每个用户都可以在其中将一组智能卡关联到他的帐户。然后可以使用公民卡或其他具有数字签名功能的智能卡对文档进行签名。我们已经实现了一个Alfresco模块,该模块使我们能够探索几种工作流技术来实现真实任务安全的数字签名工作流,例如人们在要签署的各个部门之间传递纸质文档时所做的工作。由于所有用户都可以在整个标牌过程中看到正在签名的文档的当前状态,因此可以保留重要的安全属性,例如系统信任。我们还描述了一个外部验证Web服务,该服务为用户提供了一种验证签名文档的方法。然后,验证服务会向用户显示重要的文档安全性属性(例如时间戳,证书属性),并在Alfresco模块定义的工作流中收集的数字签名面前突出显示文档的完整性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号