International standards, high security
According to the Ministry of Science and Technology 's Communications Center, the appendix of Circular No. 15/2025/TT-BKHCN requires the application of new international security standards, including a minimum key length of 2048 bits for the RSA algorithm and 256 bits for ECDSA. In addition, the application of digital signature standards such as PAdES, XAdES and CAdES according to European standards is also encouraged.
Circular 15/2025/TT-BKHCN sets higher and stricter technical requirements for digital signature and signature verification software.
Transparency, great reliability
The digital signature software must be able to check the validity of the digital signature certificate before the user signs it. At the same time, the software must also support timestamping and ensure the integrity of the data after signing. The digital signature verification software must be able to verify the signature according to the "trust path" and ensure that the digital signature certificate is linked to the original certificate of the National Electronic Authentication Center (NEAC) or a foreign trusted list. More importantly, the software must notify the validity of the verification result in Vietnamese and provide detailed information about the signer, the time of signing and the integrity of the data.
Centralized connection
The Circular introduces the eSign Portal, a public digital signature certification service connection portal, developed by the Ministry of Science and Technology . This is a centralized connection model, helping to connect organizations providing public digital signature certification services (CA) with information systems serving electronic transactions such as public service portals, banking systems, taxes, and customs.
Organizations providing public digital signature certification services and information systems serving electronic transactions using digital signatures connect to the eSign Portal to perform digital signatures. Connecting to a centralized system will help simplify the integration process for application development units (only need to connect to one hub instead of connecting to each individual CA), while ensuring synchronization, security and compatibility nationwide. The National Electronic Authentication Center (NEAC) is the focal point to support and guide the connection to the eSign Portal.
Hien Thao
Source: https://doanhnghiepvn.vn/cong-nghe/quy-dinh-moi-ve-phan-mem-ky-so-chuan-quoc-te-bao-mat-cao-ket-noi-tap-trung/20250820110239793
Comment (0)