BS EN 419241-2 discusses trustworthy systems supporting server signing. BS EN 419241-2 is the second part of the BS EN 419241 series of standards that specifies a protection profile for a Signature Activation Module (SAM), which is aimed to meet the requirements of a QSCD as specified in Regulation (EU) No 910/2014 [eIDAS].
BS EN 419241-2 on connectors for electronic equipment is useful for:
A trustworthy system supporting server signing (TW4S) is a system that offers remote digital
signatures as a service. It ensures that signer’s signing key or keys are only used under the sole
control of the signer for the intended purpose.
The TOE is a software component, which implements the Signature Activation Protocol (SAP). It
is either deployed within the tamper protected part of the Cryptographic Module or alternatively in a dedicated tamper-protected environment, that is connected to the Cryptographic Module via a trusted channel. It uses the Signature Activation Data (SAD) from the signer to activate the corresponding signing key for use in a Cryptographic Module. Together the TOE and Cryptographic Module are a QSCD.
The TW4S uses a Cryptographic Module to generate the signing key and create the digital signature value. ISO/TS 16175-2 identifies and defines the security objectives for the TOE and its operational environment. These security objectives reflect the stated intent, counter the identified threats, and take into account the assumptions.
EN 419241-2:2019