FLAGSHIP REMOTE SIGNING PRODUCT

Trusted SIC
QuantumSafe Remote Signing Gateway

A web-first signing interaction and orchestration layer that binds signer authentication, explicit transaction approval, short-lived signature activation, multi-CA routing, protected HSM/QSCD execution and verifiable long-term evidence.

WHY TRUSTED SIC

One governed signing experience across certificate providers and cryptographic profiles.

Business applications should not implement a different user journey, activation protocol and evidence model for every CA or signing provider. Trusted SIC provides one policy-controlled gateway while preserving the security boundary and contractual responsibility of each connected trust service.

Passkey-native approval

FIDO2/WebAuthn authentication and optional transaction-confirmation patterns bind the signer to the approved document or transaction.

Multi-CA abstraction

Routing rules select the approved CA, certificate, signing account and profile without exposing provider-specific complexity to the relying application.

Evidence by design

Authentication, consent, SAD, signing operation, timestamp and validation results are correlated into one evidence package.

REFERENCE ARCHITECTURE

Three product layers with explicit trust boundaries.

01 · EXPERIENCE

Trusted SIC Experience Layer

Document preview, transaction context, signer choice, consent, Passkey prompt, cross-device flow and signing-status receipt.

  • Web and mobile journey
  • RP branding and locale policy
  • Accessible transaction confirmation
02 · ACTIVATION

Trust & Signature Activation Layer

Validates OIDC identity and WebAuthn assertion, enforces nonce/timestamp/replay controls, binds the approved hash and issues a short-lived SAD or equivalent activation authorization.

  • Credential-to-signing-account binding
  • Risk-based step-up
  • Purpose, key, hash and expiry constraints
03 · EXECUTION

Multi-CA QuantumSafe Signing Layer

Routes the approved request to a CSC-compatible connector or Mobile-ID adapter, invokes HSM/QSCD/SAM, packages signatures and collects TSA/VA evidence.

  • PAdES, CAdES, XAdES and ASiC
  • Classical, hybrid and controlled PQC profiles
  • Provider failover under approved policy

END-TO-END JOURNEY

From relying application to independently verifiable evidence.

01

Create signing request

RP submits document hashes, signer context, requested assurance, format and evidence policy.

02

Resolve signer & provider

Trusted SIC maps the identity to eligible signing accounts, certificates and CA routes.

03

Display transaction

The user sees document identity, purpose, amount or transaction facts before approval.

04

Passkey approval

WebAuthn assertion is verified with challenge, origin, RP ID, user presence and policy data.

05

Issue activation

A short-lived SAD binds signer, credential, document hash, transaction, key and expiry.

06

Execute protected signing

HSM/QSCD/SAM performs the approved classical, hybrid or controlled PQC operation.

07

Package & timestamp

Signature container, certificate path, OCSP/CRL and trusted timestamp are assembled.

08

Return evidence receipt

RP receives result, verification report, audit correlation and renewal policy.

PQC TRANSITION PROFILES

Controlled options instead of a single generic “supports PQC” claim.

PROFILE A

PQC-only closed ecosystem

ML-DSA or another approved project profile is used where every issuer, signer and verifier is governed by the same acceptance record.

  • Controlled PoC or closed relying-party group
  • Exact parameter set and provider version
  • No blanket public interoperability claim
PROFILE B

Classical signature + PQC evidence

A widely verifiable classical signature remains the primary artifact while a PQC signature or evidence object is bound to the same manifest and transaction.

  • Backward-compatible relying-party path
  • ASiC or evidence-envelope packaging
  • Dual evidence and renewal policy
PROFILE C

Dual validation

Classical and PQC verification paths produce independent results consolidated into a signed validation report.

  • Explicit partial-success policy
  • Verifier capability reporting
  • Migration and rollback evidence

PRODUCT COMPONENTS

A product model that sales, architects and developers can all understand.

UX

Signing Experience SDK

Embeddable web/mobile journey for preview, signer selection, consent, approval and status.

FIDO

Passkey & WebAuthn Gateway

Registration, challenge generation, assertion validation, device/risk policy and audit facts.

SAD

Signature Activation Service

Issues purpose-bound, short-lived authorizations tied to signer, hash, key, transaction and expiry.

CA

Multi-CA Router

Provider discovery, certificate selection, policy routing, connector health and approved failover.

SIGN

QuantumSafe Signing Core

HSM/QSCD/SAM execution for classical, hybrid and release-approved PQC profiles.

EVID

Evidence & Validation Service

ASiC packaging, timestamping, revocation evidence, verification reports and renewal scheduling.

INTEGRATED TRUSTED SIC MODULE

ASiC Signer & Evidence Packager

ASiC is governed as an integrated Trusted SIC module that carries the approved signing transaction from signature creation to independent validation and long-term preservation.

MAN

Dossier manifest

Object hashes, signer intent, transaction context and policy identifiers.

SIG

Detached signature set

Classical, hybrid-evidence or controlled PQC artifacts over one governed manifest.

TSA

Trusted time & validation

RFC 3161 timestamps, certificate path, OCSP/CRL and validation report.

LTA

Preservation lifecycle

Renewal schedule, archive timestamps, evidence hashes and export-ready dossier.

API

Packaging API

Create, inspect, verify, renew and export ASiC-S/ASiC-E packages under an approved release profile.

UX

Inspection experience

Human-readable dossier summary, signer facts, validation status and evidence receipt.

STANDARDS & INTERFACES

Interoperability baseline

  • FIDO2 / WebAuthn for strong signer authentication
  • SPC-style transaction confirmation where browser and use-case support is approved
  • OIDC/OAuth 2.0 for identity and delegated authorization
  • CSC API v2.2 alignment where applicable; Mobile-ID extensions are separately identified
  • ETSI remote-signing/QSCD concepts and signature-format profiles
  • PAdES, CAdES, XAdES, ASiC, RFC 3161, OCSP and CRL evidence

CONTROLLED PILOT BOUNDARY

What must be evidenced

  • Browser, authenticator and WebAuthn support matrix
  • CA/HSM/QSCD connector and failure-mode matrix
  • Signing format, algorithm, parameter set and verifier matrix
  • Authentication, activation, anti-replay and sole-control test corpus
  • Performance for interactive, batch and high-frequency journeys
  • Independent security assessment before broader availability

START A CONTROLLED EVALUATION

Review the product, API, manual and evidence gate together.

Trusted SIC is presented as a controlled pilot profile; exact implementation and availability remain release-specific.