Workshop on Security Procedures for the Interchange of Electronic Documents:

1993

The impetus for the workshop and some of the issues that were planned for consideration are discussed in the Announcement paper included in this report.The fundamental reason for the workshop was that rules for the use of security procedures needed to be devised for the electronic transmission of documents between organizations.This transmission process, usually utilizing electronic data interchange (EDI) standards, is being implemented to reduce paperwork, reduce response times between buyers and sellers, reduce requirements for inventory on-hand, reduce transcription errors, and allow for the computer-based filing and analysis of transmitted documents without the need for re-entry of the data.Applications include purchasing, regulatory and environmental reporting, customs and tariff filings, benefits management, and claims and disbursement informa- tion.Sequencing integrity -ordering of received documents in the sequence intended by the originator, as repetitions, omissions, and mis-orderings are easily identified.Conf identialitv -prevention of unauthorized disclosure.10.In cases of lower risk, confidence in message integrity may be obtained by reasonableness checks on data values, and by the matching recalculation by the recipient of real and hash totals that cover the essential parameters of the document.Additionally, document integrity may be further assured by the successful retransmission of its essential content back to the originator.8 Commentary to 10 ; In a commercial environment, data integrity may be much more significant than confidentiality.Reasonableness checks and recalculations on data values make sense, even if there is no concern whatsoever about the transmission link.Data values may be in error due to mistakes at the interchange partner's com- puter, and the risk of monetary loss in making decisions on incor- rect data may be high.Weiss reports that the Model Agreement states that "Consistency checking of the payment amount with prior transactions or customer profiles" is a verification technique.Retransmission back to the originator may be simple to execute.It may only require the turnaround of the message as received, with the addition of an indication of acknowledgment meaning, for exam- ple, "We have received your message stating ..." or "We agree to carry out the request in your message that ..." Cryptographic Techniques for Confidence Under High Risk: 11.In cases of highest risk, the use of cryptographic techniques is necessary to assure document integrity and originator authentication.Techniques using public key encryption, i.e., digital signatures, should be considered when the risk for loss of integrity or failure of authentication exceeds the cost associated with the use of such techniques.\ -5=-,

Read the paper · More papers on PaperTik