Purpose of This Document
This article outlines the core ETSI and NIST technical standards that underpin the cryptographic implementations in Virifi’s Solution Proposal. These standards ensure interoperability, legal compliance, and resilience to both current and emerging threats — including quantum-based attacks.
ETSI (European Telecommunications Standards Institute)
ETSI provides the technical specifications for eIDAS-compliant electronic signatures used across the EU and by regulated entities globally. The following standards are directly implemented:
Signature Format Standards
ETSI EN 319 142-1 (PAdES)
Digital signatures embedded into PDF files.
ETSI EN 319 132-1 (XAdES)
XML-based digital signature structures for data contracts, workflows.
ETSI TS 119 182-1 (JAdES)
JSON-compatible signatures aligned with JOSE, for APIs and modern applications.
ETSI EN 319 122-1 (CAdES)
Signatures for CMS-based (binary) systems, system-to-system communication.
Validation & Reporting
ETSI TS 119 102-2 – Signature Validation Reports (XAdES, PAdES, etc.)
Provides machine-readable validation status and diagnostics.
NIST (National Institute of Standards and Technology)
NIST defines cryptographic standards for secure digital signatures and key management, widely adopted in both federal and international domains.
Post-Quantum Cryptography
FIPS 204 – ML-DSA (Module-Lattice-Based Digital Signature Algorithm)
Post-quantum secure signature algorithm used in our Cloud HSM configurations.
Traditional Standards (Referenced Where Applicable)
FIPS 140-2 / 140-3 – Hardware cryptographic module validation
FIPS 186-5 – Digital Signature Standard (covers RSA, DSA, ECDSA)
SP 800-57 / SP 800-131A – Key management, cryptoperiods, algorithm transition guidelines
Why These Standards Matter
Compliance with CBJ Requirements – Both ETSI eIDAS and NIST standards are explicitly referenced in the CBJ Digital Signature Challenge.
Legal Validity – ETSI ensures signatures hold weight across EU and affiliated jurisdictions.
Security Future-Proofing – FIPS 204 aligns with post-quantum strategy.
Technical Interoperability – Systems that use these standards are compatible across regulated financial infrastructures.
