Please use this identifier to cite or link to this item: https://hdl.handle.net/10216/88027
Author(s): Pedro Rui Figueiredo da Cunha
Title: Assinaturas de Longo Prazo
Issue Date: 2015-02-27
Abstract: Digital signatures are a requirement for the future. Information in general and documents in particular (the standard being PDF) is increasingly becoming more about bits and bytes and less about paper. But the only way to ensure that this happens successfully is to make a digital signature in all things as equivalent to a traditional one. A signature in itself has undergone major modification throughout the time, from wax seals to hand-written signatures. The next step is digitalization. However, simple digital signatures are not sufficient, since they have a very limited lifespan. This thesis approaches the method of long-term digital signatures in a way that, since there is no definite evaluation between the standards that exist today, there is no clear way to define which one is the best. Hence, one of the goals will be to try and demonstrate in which situation should each one be used and try and make it more definite which one is preferable. Since there is no single or "best" standard, there isn't also a software that can be defined as the one to use where long-term digital signatures are concerned. After a series of tests using the three standards, this dissertation proposes not only a case-by-case use of each standard, but also a software that was developed to aid in the growth of digital signatures as the main method of signing documents and files. The main conclusions are that CAdES is the by-default standard to be used. It is both faster and occupies the least amount of space on disk, which, even though a one for one comparison with XAdES doesn't seem a lot, if we consider thousands of files to be signed, it can reach significant savings. One main disadvantage is that CAdES signatures can't be seen in the file. An mp3 file with a signature will appear as a simple mp3 file. Which is not the case of a XAdES signature, since the output is in XML language. This format can break the functionality of the files, though, if attached to them, hence we save it for XML files, since it made sense to maintain the same formatting scheme of the original file. PAdES is used in one and only one circumstance: to sign PDF files in which the signature is to be included inside the PDF. PAdES uses CAdES as its main signature creation method, but it makes it so that PDF readers that show signatures can display the ones created using PAdES. This is specially important for enterprise use and official documents.
Description: Assinaturas digitais são um requerimento para o futuro. A informação em geral e a documentação em particular estão a manifestar-se cada vez mais em bits e bytes e cada vez menos em papel. Mas a única forma de garantir que isto acontece com sucesso é através da criação de assinaturas digitais, em tudo equivalentes às tradicionais. O próprio conceito de assinatura sofreu alterações ao longo do tempo, desde selos com cera até às assinaturas manuscritas. O próximo passo é a digitalização. Contudo, assinaturas digitais simples não são suficientes, visto que têm um período de vida muito limitado. Esta tese aborda o método de assinaturas digitais de longo-prazo de uma forma através da qual se demonstra em que situações cada um dos standards deve ser usado e se define qual deles é preferível. Visto que, na falta de uma ou da melhor especificação, não haverá consequentemente um software definido como recomendável no que às assinaturas de longa duração diz respeito. Após uma série de testes, utilizando os três standards, propomos não só a sua utilização caso a caso, como também um software desenvolvido para ajudar no crescimento do uso de assinaturas digitais enquanto principal método para assinar ficheiros e documentos. Concluímos que o CAdES é o standard a ser usado por defeito. É, ao mesmo tempo, mais rápido e ocupa o menor espaço em disco. Sem prejuízo de numa comparação um para um com o XAdES a diferença não ser muita, se considerarmos milhares de ficheiros que precisam de ser assinados, o CAdES consegue atingir poupanças bastante significativas. Contudo, este standard tem uma principal desvantagem em relação ao XAdES: se a assinatura for incluída num ficheiro, não há maneira de saber (à "vista desarmada") que ela está lá. Isto é, um ficheiro mp3 continuará a pare- cer apenas um simples ficheiro mp3, o que não acontece usando o XAdES, visto que a assinatura é sempre em XML. No entanto, este formato pode quebrar a funcionalidade original do ficheiro, pelo que será usado apenas em ficheiros já de si em XML, visto que, para estes, faz sentido manter tudo na mesma linguagem de anotação. Por fim, o PAdES é usado numa única circunstância: para assinar docu- mentos em PDF cuja assinatura tenha de ser incluída com o próprio documento. O PAdES usa, internamente, para assinar ficheiros, o CAdES, mas fá-lo de forma a que os leitores de PDF que conseguem ler assinaturas as possam mostrar, o que é especialmente importante para uso empre- sarial e para documentos oficiais.
Subject: Engenharia electrotécnica, electrónica e informática
Electrical engineering, Electronic engineering, Information engineering
Scientific areas: Ciências da engenharia e tecnologias::Engenharia electrotécnica, electrónica e informática
Engineering and technology::Electrical engineering, Electronic engineering, Information engineering
DOI: 10.34626/xde5-9187
TID identifier: 201317494
URI: https://hdl.handle.net/10216/88027
Document Type: Dissertação
Rights: openAccess
Appears in Collections:FEUP - Dissertação

Files in This Item:
File Description SizeFormat 
34512.pdfLong-Term Digital Signatures1.29 MBAdobe PDFThumbnail
View/Open


Items in DSpace are protected by copyright, with all rights reserved, unless otherwise indicated.