QoeSiGN: Towards Qualified Collaborative eSignatures
Karl W. Koch, Stephan Krenn, Alexandra Hofer

TL;DR
This paper introduces QoeSiGN, a novel framework that integrates privacy-preserving collaborative computations into qualified electronic signatures, enhancing robustness, crypto agility, and user involvement while addressing legal and practical challenges.
Contribution
It proposes a new approach combining P2C2 technologies with QES, providing flexible instantiation options and addressing key threat and requirement challenges in QES systems.
Findings
QoeSiGN improves crypto agility and user involvement in QES.
It offers multiple instantiation options like multi-party HSMs and secure multi-party computation.
The framework enhances robustness and compliance with legal requirements.
Abstract
eSignatures ensure data's authenticity, non-repudiation, and integrity. EU's eIDAS regulation specifies, e.g., advanced and qualified (QES) eSignatures. While eSignatures' concrete legal effects depend on the individual case, QESs constitute the highest level of technical protection and authenticity under eIDAS. QESs are based on a qualified certificate issued by a qualified trust service provider (QTSP). Despite legal requirements, technically, a QTSP represents a single point of failure. Contrary, privacy-preserving collaborative computations (P2C2s) have become increasingly practical in recent years; yet lacking an extensive investigation on potential integrations in the QES landscape. We perform a threat analysis on the QES-creation process of Austria's national eID, using STRIDE and a DREAD-like model to extract requirement challenges (RCs) primarily related to: (1) Distributed…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsCryptography and Data Security · Security and Verification in Computing · IoT and Edge/Fog Computing
