Electronic signatures, FIDO tokens, and HSMs evaluated against eIDAS and ANSSI standards share one make-or-break dependency: a precisely defined security boundary. When the boundary is ambiguous, evaluation stalls. Here is how we defined it cleanly and supported a leading Trust Service Provider through certification.
A qualified Trust Service Provider needed to validate and certify the core systems behind its electronic signature, strong authentication, and PKI services — spanning FIDO/U2F authenticators, an eIDAS remote signature solution, and the underlying PKI infrastructure.
This was not a single-product evaluation. The scope covered three distinct fronts: a FIDO/U2F USB authenticator running on a smart card; an eIDAS-compliant remote signature solution (QSCD/QSCDev) tying together HSMs, Signature Activation Modules, and complex cryptographic lifecycles; and vulnerability and risk assessment across the PKI infrastructure. The decisive issue was boundaries. When technical layers, hardware components, and organizational processes overlap, laboratories and authorities such as ANSSI need unambiguous clarity on where the security perimeter starts and stops. Without it, evaluations stall, costs rise, and timelines slip — so the perimeter had to be settled before evaluation began, not argued during it.
01
Defined the assurance perimeter early for the remote signature architecture, tracing every link from the HSM and its cryptographic functions through to the operator’s operational environment.
02
Authored and refined the technical documentation the labs depend on: Security Targets, cryptographic design files, and precise administrator and user guidance
03
Built risk assessments for the PKI systems that mapped countermeasures to actual assets and operator roles, tied to how the system is really used.
04
Ran crypto-engineering and compliance-authority expertise as one workflow, so the architecture, the Security Target, and the evidence stayed consistent with each other throughout.
The value came from speaking two languages in one workflow: high-assurance cryptographic engineering and the expectations of compliance authorities. Settling the architectural boundaries upfront removed the guesswork that usually drags out formal audits, turning a typically uncertain process into a predictable path to certification. For any multi-layer evaluation involving hardware, cryptography, and organizational processes, defining the perimeter first is the highest-leverage move available.
We’ll send you access by email.