Legislative Landscape and QES Requirements in Ukraine
In the context of rapid digitalization, Ukrainian businesses are actively transitioning to electronic document management (EDM), where qualified electronic signatures (QES) play a central role. The legal force of electronic documents signed with QES is ensured by the Law of Ukraine "On Electronic Trust Services" No. 2155-VIII of October 5, 2017, which replaced the previous Law "On Electronic Digital Signature." This law defines QES as an advanced electronic signature created using a qualified electronic signature tool and based on a qualified public key certificate. Additionally, the Law of Ukraine "On Electronic Documents and Electronic Document Management" No. 851-IV establishes the basic rules for the circulation and storage of electronic documents.
According to the legislation, an electronic document signed with QES has the same legal force as a paper document with a handwritten signature, provided all requirements are met. This requires companies not only to have the technical capability for signing but also to ensure the integrity, accessibility, and verifiability of electronic documents throughout their entire storage period.
Key Challenges of Integrating QES into Corporate EDM Systems
Integrating various types of QES, including the popular Diia.Signature, into existing corporate electronic document management (EDM) systems presents a number of challenges for heads of document management departments, IT directors, and corporate system architects:
- Diversity of Providers and Formats: There are many qualified electronic trust service providers (QESTPs) on the Ukrainian market, each potentially using its own software interfaces and signature formats. This leads to difficulties in ensuring unified operation with different types of QES, including Diia.Signature, which integrates via API.
- Lack of Centralized Signature Management: Without a unified QES management mechanism, there is a risk of losing control over the signature lifecycle, their validity, and the signatories' powers, which can lead to the loss of legal force of documents.
- Ensuring Long-Term Legal Validity and Archiving: The maximum validity period of a qualified QES certificate is typically two years. This creates a problem of verifying the authenticity of a signature after the certificate expires. It is necessary to ensure long-term archiving of electronic documents in a way that their legal validity is preserved for the periods established by law, which can be decades or permanent.
- Cybersecurity and Data Protection: Storing and processing electronic documents signed with QES requires a high level of protection against unauthorized access, modification, or loss. This includes the use of hardware tokens, encryption, and two-factor authentication.
- Cross-Border Recognition: Currently, Ukrainian QES are not always recognized abroad, and vice versa, which complicates international cooperation, although Ukraine is taking steps towards mutual recognition with the EU.
Architectural Solutions for Seamless QES Integration
To overcome the aforementioned challenges, companies can choose one of several architectural approaches for integrating QES into their EDM systems:
- Direct Integration (Point-to-Point): This approach involves direct connection of the EDM system to the API of each individual QESTP.
- Advantages: Relative ease of implementation for a small number of providers, low initial costs.
- Disadvantages: High complexity of scaling when adding new QESTPs, dependence on the specific APIs of each provider, difficulties in centralized management and updates.
- Using an Intermediate Layer (Middleware/Integration Bus): This approach involves developing or implementing a separate intermediate layer (adapter or bus) that standardizes the interaction between the EDM system and various QESTPs.
- Advantages: Reduced complexity of the EDM system, centralized signature management, easier addition of new QESTPs without significant changes to the EDM system, possibility of implementing unified security and archiving policies.
- Disadvantages: Additional costs for developing/implementing middleware, potential single point of failure if the middleware is not highly available.
- Microservices Approach: QES integration is implemented as a set of independent microservices, each responsible for a specific functionality (e.g., signature creation, verification, certificate management, interaction with a specific QESTP).
- Advantages: High scalability, flexibility in technology selection, fault tolerance (failure of one microservice does not affect others), ease of development and deployment, ideally suited for cloud architectures.
- Disadvantages: Higher initial architectural complexity, need for orchestration and monitoring tools, increased qualification requirements for the team.
Ukrainian companies seeking to optimize their document management processes often turn to the experience of integrators and developers of corporate systems, such as those represented at https://intecracy.com/ and https://inbase.com.ua/, for implementing comprehensive solutions.
Long-Term Archiving and QES Verification
Particular attention should be paid to ensuring the long-term archiving of electronic documents with QES. For this purpose, it is critical to use formats that support extended attributes for verifying the legitimacy of a signature even after the certificate expires. In Ukraine, CAdES-X Long is such a standard, which stores information about timestamps, signatory and provider certificates, the root certificate of the certification authority, and OCSP server responses. This allows for long-term confirmation of the signature's validity.
Electronic document management systems must ensure:
- Storage of electronic documents on electronic media in a form that allows verification of their integrity.
- Availability of information for further use and the ability to restore the document in its original format.
- Preservation of information about the origin, purpose, date, and time of sending/receiving the document.
- Regular updating and copying of documents to new media if the storage period exceeds the service life of the current medium.
Checklist for Choosing a QES Integration Architecture
- Does the chosen architecture comply with the requirements of the Law of Ukraine "On Electronic Trust Services" and "On Electronic Documents and Electronic Document Management"?
- What are the current and future needs regarding the number of QESTPs and types of QES (including Diia.Signature) that need to be supported?
- What level of scalability and flexibility is required to adapt to changes in legislation and technologies?
- What resources (human, financial) are available for the implementation and support of the chosen solution?
- How critical is the centralization of signature management and monitoring?
- What mechanisms for long-term archiving of the legal validity of documents are provided?
- What cybersecurity and personal data protection requirements need to be considered?
- Does your IT team have experience integrating with cloud services and APIs?
Related solutions: Intecracy solutions and inbase.com.ua solutions.