SafeGuard Sign&Crypt for SAP R/3
Secure Store and Forward Interface Software for SAP R/3
SafeGuard Sign&Crypt for SAP R/3 implements the Secure Store and Forward (SSF) framework in SAP applications to enable secure transfer and storage of digital transactions. The SSF framework integrates digital signatures at the heart of several SAP modules and leverages the use of ERP systems for legally binding transactions.
The Challenge
Large enterprises rely on information technology more than ever and its enterprise resource planning (ERP) software like SAP R/3 that lies at the heart of their computing activity. Few people think of ERP in terms of rapid change but it may well be enterprises with these systems that will reap the largest benefits from integrating digital signatures into real life business processes.
ERP is geared towards the creation of an integrated infrastructure that glues together essential business processes. It is a demand-to-delivery environment where technology is applied to give the best possible connection for customers and suppliers to the company’s internal processes. Therefore, it is increasingly important to secure electronic transactions over public networks. When electronic transactions are performed, business data, such as invoices, orders and payments leave the secured area of the ERP system to be exchanged over insecure networks or to be stored on external data carriers.
In December 2001 the European Council issued a new directive on VAT invoicing that allows companies in all 15 EU member states to replace their paper-based invoicing with electronic invoicing, even for cross border transactions. The new directive states that electronic signatures are one of the means to implement such a system.
The combination of adequate legislation like the new European Directive, established ERP applications like SAP R/3 and best of breed security solutions like SafeGuard Sign&Crypt forms the framework in which businesses can create cost saving business applications.
The Product
SafeGuard Sign&Crypt for SAP R/3 implements the Secure Store and Forward (SSF) framework in SAP applications and can replace paper documents and handwritten signatures by automated workflow processes and digital documents that can be validated by digital signatures.
SafeGuard Sign&Crypt for SAP R/3 also effectively protects R/3 data and documents when saved on external data carriers or when transmitted over possibly insecure public networks. In the SSF framework, R/3 data and documents are encrypted and wrapped in secure formats before being stored or transferred.
Using SafeGuard Sign&Crypt for SAP R/3 offers integrity and confidentiality of data, authenticity of sender/originator and non-repudiation to R/3 data and documents.
Familiar Operating Environment
SafeGuard Sign&Crypt for SAP R/3 is certified by SAP as SSF Interface Software. SSF is seamlessly integrated into different SAP R/3 modules and hence provides the user with a familiar operating environment.
Hardware and Software
For maximum security, SafeGuard Sign&Crypt for SAP R/3 should be used with a PKCS#11-based smart card and a smart card reader or a PKCS#11 token. The signature is provided using the signature component on the smart card or token, while the software’s verification component ensures the validation of the signature.
Characteristics
SafeGuard Sign&Crypt is based on accepted public key technology and standard protocols.
Standardized Security
SafeGuard Sign&Crypt for SAP R/3 supports SAP’s SSF API. The format used for signed and/or encrypted data is PKCS#7. Furthermore, the use of SSF functions applies X.509v3 as the standard for public key certificates. Moreover, SafeGuard Sign&Crypt for SAP R/3 supports CRL and OCSP for certificate validation.
Effective Encryption
SafeGuard Sign&Crypt uses AES (128, 192 or 256 bit), Triple DES (168 bit) or IDEA (128 bit) for strong encryption.
Signature via Smartcard
SafeGuard Sign&Crypt supports all standard PKCS#11-enabled smart cards and tokens and supports biometric authentication and PIN pad readers to further enhance security. This provides a higher level of security than conventional software keys since the private key never leaves the card or token.
Secure Key
Users obtain key pairs, certificates and (optionally) smart cards or tokens from the SafeGuard PKI (Public Key Infrastructure) of Utimaco Safeware.
System Requirements
Hardware
Computer with Intel Pentium or compatible processor
Operating Systems
• Microsoft Windows NT version 4.0
• Microsoft Windows 2000
Security Features
Key Management
SafeGuard PKI
Algorithms
AES, Triple DES, IDEA, DES, RC2, Safer, Square; RSA; SHA-1, MD5, RIPEMD160
Standards
X.509v3, LDAPv2, CRLv2, OCSP, PKCS#7, PKCS#11 and PKCS#12
Tokens
PKCS#12 key files, PKCS#11-based smart cards and tokens * and Utimaco Safeware smart cards
Certification
By SAP AG
Certified Functions
General SSF Prerequisites (PKCS#7), Public Key Algorithms: RSA, Hash Algorithms, Symmetric Encryption Algorithms,
Optional functionality: SsfDigest, SsfVerify