FIDO2/WebAuthn authentication and optional transaction-confirmation patterns bind the signer to the approved document or transaction.
FLAGSHIP REMOTE SIGNING PRODUCT
Trusted SIC
QuantumSafe Remote Signing Gateway
A web-first signing interaction and orchestration layer that binds signer authentication, explicit transaction approval, short-lived signature activation, multi-CA routing, protected HSM/QSCD execution and verifiable long-term evidence.
WHY TRUSTED SIC
One governed signing experience across certificate providers and cryptographic profiles.
Business applications should not implement a different user journey, activation protocol and evidence model for every CA or signing provider. Trusted SIC provides one policy-controlled gateway while preserving the security boundary and contractual responsibility of each connected trust service.
Routing rules select the approved CA, certificate, signing account and profile without exposing provider-specific complexity to the relying application.
Authentication, consent, SAD, signing operation, timestamp and validation results are correlated into one evidence package.
REFERENCE ARCHITECTURE
Three product layers with explicit trust boundaries.
Trusted SIC Experience Layer
Document preview, transaction context, signer choice, consent, Passkey prompt, cross-device flow and signing-status receipt.
- Web and mobile journey
- RP branding and locale policy
- Accessible transaction confirmation
Trust & Signature Activation Layer
Validates OIDC identity and WebAuthn assertion, enforces nonce/timestamp/replay controls, binds the approved hash and issues a short-lived SAD or equivalent activation authorization.
- Credential-to-signing-account binding
- Risk-based step-up
- Purpose, key, hash and expiry constraints
Multi-CA QuantumSafe Signing Layer
Routes the approved request to a CSC-compatible connector or Mobile-ID adapter, invokes HSM/QSCD/SAM, packages signatures and collects TSA/VA evidence.
- PAdES, CAdES, XAdES and ASiC
- Classical, hybrid and controlled PQC profiles
- Provider failover under approved policy
END-TO-END JOURNEY
From relying application to independently verifiable evidence.
Create signing request
RP submits document hashes, signer context, requested assurance, format and evidence policy.
Resolve signer & provider
Trusted SIC maps the identity to eligible signing accounts, certificates and CA routes.
Display transaction
The user sees document identity, purpose, amount or transaction facts before approval.
Passkey approval
WebAuthn assertion is verified with challenge, origin, RP ID, user presence and policy data.
Issue activation
A short-lived SAD binds signer, credential, document hash, transaction, key and expiry.
Execute protected signing
HSM/QSCD/SAM performs the approved classical, hybrid or controlled PQC operation.
Package & timestamp
Signature container, certificate path, OCSP/CRL and trusted timestamp are assembled.
Return evidence receipt
RP receives result, verification report, audit correlation and renewal policy.
PQC TRANSITION PROFILES
Controlled options instead of a single generic “supports PQC” claim.
PQC-only closed ecosystem
ML-DSA or another approved project profile is used where every issuer, signer and verifier is governed by the same acceptance record.
- Controlled PoC or closed relying-party group
- Exact parameter set and provider version
- No blanket public interoperability claim
Classical signature + PQC evidence
A widely verifiable classical signature remains the primary artifact while a PQC signature or evidence object is bound to the same manifest and transaction.
- Backward-compatible relying-party path
- ASiC or evidence-envelope packaging
- Dual evidence and renewal policy
Dual validation
Classical and PQC verification paths produce independent results consolidated into a signed validation report.
- Explicit partial-success policy
- Verifier capability reporting
- Migration and rollback evidence
PRODUCT COMPONENTS
A product model that sales, architects and developers can all understand.
Signing Experience SDK
Embeddable web/mobile journey for preview, signer selection, consent, approval and status.
Passkey & WebAuthn Gateway
Registration, challenge generation, assertion validation, device/risk policy and audit facts.
Signature Activation Service
Issues purpose-bound, short-lived authorizations tied to signer, hash, key, transaction and expiry.
Multi-CA Router
Provider discovery, certificate selection, policy routing, connector health and approved failover.
QuantumSafe Signing Core
HSM/QSCD/SAM execution for classical, hybrid and release-approved PQC profiles.
Evidence & Validation Service
ASiC packaging, timestamping, revocation evidence, verification reports and renewal scheduling.
INTEGRATED TRUSTED SIC MODULE
ASiC Signer & Evidence Packager
ASiC is governed as an integrated Trusted SIC module that carries the approved signing transaction from signature creation to independent validation and long-term preservation.
Dossier manifest
Object hashes, signer intent, transaction context and policy identifiers.
Detached signature set
Classical, hybrid-evidence or controlled PQC artifacts over one governed manifest.
Trusted time & validation
RFC 3161 timestamps, certificate path, OCSP/CRL and validation report.
Preservation lifecycle
Renewal schedule, archive timestamps, evidence hashes and export-ready dossier.
Packaging API
Create, inspect, verify, renew and export ASiC-S/ASiC-E packages under an approved release profile.
Inspection experience
Human-readable dossier summary, signer facts, validation status and evidence receipt.
STANDARDS & INTERFACES
Interoperability baseline
- FIDO2 / WebAuthn for strong signer authentication
- SPC-style transaction confirmation where browser and use-case support is approved
- OIDC/OAuth 2.0 for identity and delegated authorization
- CSC API v2.2 alignment where applicable; Mobile-ID extensions are separately identified
- ETSI remote-signing/QSCD concepts and signature-format profiles
- PAdES, CAdES, XAdES, ASiC, RFC 3161, OCSP and CRL evidence
CONTROLLED PILOT BOUNDARY
What must be evidenced
- Browser, authenticator and WebAuthn support matrix
- CA/HSM/QSCD connector and failure-mode matrix
- Signing format, algorithm, parameter set and verifier matrix
- Authentication, activation, anti-replay and sole-control test corpus
- Performance for interactive, batch and high-frequency journeys
- Independent security assessment before broader availability
START A CONTROLLED EVALUATION
Review the product, API, manual and evidence gate together.
Trusted SIC is presented as a controlled pilot profile; exact implementation and availability remain release-specific.
