Developers: | Krypto-PRO |
Last Release Date: | 2016/12/12 |
Technology: | Cybersecurity - Means of enciphering |
For March 31, 2017 Crypto Pro of DSS is the hardware and software system intended for the centralized, protected storage of private keys of users, remote execution of operations of creation of the electronic signature (ES) for the benefit of users in interaction with Crypto Pro of HSM.
Possibilities of Crypto Pro of DSS
- creation of the EDS under any electronic document;
- client part is not required;
- for work with Crypto Pro of DSS only the web browser;
- there is no need of installation of means of the EDS on each workplace of the user;
- reduction of risk of a compromise of keys of users due to their centralized protected storage;
- possibility of embedding of functions of creation of the EDS in the applied systems based on standard means of the HTTP protocol and web services;
- possibility of application of different authentication schemes of the user for access to its keys.
The supported formats of the electronic signature
- The electronic signature GOST 34.10 – 2001;
- Advanced signature (CAdES-BES and CAdES-X Long Type 1);
- Signature of XML documents (XML Digital Signature, XMLDSig);
- Signature of the documents PDF;
- Signature of the documents Microsoft Office.
Requirements to software
Crypto Pro of DSS provides to users the interactive web interface for management of cryptographic keys and creation of the EDS under the document which the user loads on Crypto Pro of DSS. It is possible to use functions of Crypto Pro of DSS from any device on any hardware platform, any OS where there is a web browser - only the web browser is necessary for the user for work with Crypto Pro of DSS.
Security
Keys of users are stored in the protected module of Crypto Pro of HSM. Each user gets access to the keys after passing of the procedure of reliable authentication on Crypto Pro of DSS.
Are available to the administrator of Crypto Pro of DSS:
- creation of the user;
- removal of the user;
- generation of a user key;
- query design on release of the certificate;
- reset of the password in case of its loss by the user.
Authentication methods
Depending on setup, Crypto Pro of DSS can implement the following methods of user authentication:
- classical one-factor authentication by the login and the password;
- two-factor authentication using digital certificates and USB tokens or smart cards;
- two-factor authentication with additional input of the one-time password delivered to the user by means of the SMS (OTP-via-SMS).