Using Entrust HSMs to Deliver eIDAS Compliance
What is eIDAS?
Since 2016 businesses and other legal entities operating within the European Union (EU) need to follow the EU regulation known as the Electronic Identification and Trust Services (eIDAS) regulations for electronic transactions. The eIDAS rules protect EU citizens, consumers, and commercial entities using public services via electronic transactions, both within EU member states and the internal market, and when dealing with non-EU organisations.
The onus on delivering eIDAS regulation falls on any organisation that supplies services to the public that require electronic services. For example, electronic identification, electronic seals (in the case of companies acting as pseudo-individuals), electronic trust services, qualified electronic signatures, digital signatures, qualified certificates, electronic document verification, and others.
Companies that are eIDAS Trust Service Providers (TSPs) provide trust services. These companies offer third-party trust services that underpin the requirements needed to deliver digital ID, signatures, and all the authentication required for full eIDAS implementation and compliance.
Entrust is a TSP that offers a complete portfolio of high assurance solutions for eIDAS, including identity, digital signing & time stamping, digital certificates, and hardware security modules (HSMs). Entrust’s series of nShield HSMs securely store all the cryptographic keys needed for eIDAS services. They allow users to safely enter credentials and sign documents using a smartphone, a tablet, a computer, or any other electronic device with web browsing capability. An HSM acts as a qualified signature creation device in this workflow.
In the sections below, we outline at a high level what’s required to deliver trusted services under eIDAS. For a deeper dive into the technicalities of eIDAS and how Entrust’s HSMs and ancillary services can provide the solutions to deliver eIDAS, download this comprehensive and free Entrust eBook: The eIDAS Regulation for Dummies.
Renaissance and Entrust are partners within the Ireland market. Contact us today to find out more about eIDAS and Entrust solutions.
Electronic IDs and Trust Services
Electronic IDs
eIDAS harmonises electronic identification (eID) solutions across EU member states. Before eIDAS many member states had eID in place that citizens could use to access government and other services. But with the free movement of people, there was a need for eID cards and other personal identifiers to be readable across all member states. Note that there is no centralised database of EU citizens to make this work. Rather, if a citizen from one EU member state used their eID in another, the request for verification goes to their home country for authentication. Each Member State maintains the identity information for its citizens.
eIDs under eIDAS are authenticated in one of three ways, and all member states must support these and use two of them to ID someone:
- Something that only the signer knows, such as a password or PIN.
- Something that only the signer has, such as a smart card or smartphone.
- Some unique, measurable physical characteristic of the signer, such as a fingerprint.
eID mutual recognition is now in legal effect across the EU Member States and became mandatory in September 2018.
Trust Services
Trust services are a category of service used for authentication and advanced electronic signatures for protecting electronic transactions.
Trust services can include the following:
- Issuing certificates for signing, sealing, and website identification, such as certificate authorities providing public key infrastructure (PKI) services.
- Issuing digitally signed time stamps.
- Long-term preservation of signed data ensuring the long-term validity of electronic signatures on archived electronic documents.
- Electronic registered delivery services, where evidence of delivery from an identified source is required.
- Electronic signatures and seal validation.
The European Telecommunications Standards Institute (ETSI) has established standards for the essential services that TSPs are expected to provide, including public key certificates and time-stamping services. The European Union recognises ETSI as one of the three official European Standards Organisations (ESO).
The eIDAS Regulation treats eIDs and trust services as having independent requirements. It views eIDs as equivalent to government-issued identity cards, whereas trust services are commercially run services with governmental oversight. For more details on how they relate and overlap, consult the eBook linked above.
Electronic Signatures and Electronic Seals
Electronic Signatures
Electronic signatures and electronic seals replicate the trust placed in a physical handwritten signature on a document such as a contract. The eIDAS Regulation defines two types of electronic signatures: advanced electronic signatures and qualified electronic signatures.
The requirements for an advanced electronic signature are less stringent than those for a qualified electronic signature. At a minimum, it must be:
- Uniquely linked to the signatory.
- Capable of identifying the signatory.
- Created in a way that ensures the signatory can maintain sole control.
- Connected to the data it relates to so that any subsequent change to the data is detectable.
A qualified electronic signature must do all of those, plus it must also have:
- A qualified signature creation device, such as a smart card or HSM, that is certified by Common Criteria and meets the requirements of the eIDAS Regulation. Entrust HSMs fulfil this.
- A qualified public key certificate issued by a qualified TSP. One audited by an accredited organisation and found to address the requirements of the eIDAS Regulation. Entrust qualified certificate services deliver this.
Electronic Seals
The eIDAS Regulation introduces the concept of an electronic seal that organisations can use in situations where individual signatures aren’t suitable. An electronic seal is similar to an electronic signature in that it uses the same technology. Like electronic signatures, electronic seals can be either advanced or qualified. However, an electronic seal has a different legal meaning in the following ways:
- The source of an electronic seal is generally assumed to be a legal entity or organisation, whereas an electronic signature comes from an individual.
- Seal creation is under the control of one or more individuals authorised to represent the organisation.
- Seals don’t provide the same legal indication of intent by an individual, but they do provide assurances as to the authenticity of the information provided by a business.
Seals are important and increasingly used to ensure authenticity and integrity between organisations. See the Entrust eIDAS eBook for a much deeper dive into eSignatures and eSeals.
Entrust HSMs in the eIDAS World
Entrust nShield Hardware Security Modules are the ideal solution to generate and protect the crucial PKI keys, certificates and other items used to secure data and other services within eIDAS governed transactions. Under eIDAS, several kinds of trusted services require HSMs to be in place for the TSP to become qualified. The Entrust HSMs are fully compliant with this requirement.
Entrust HSMs are also future-proofed via their full integration with the public and private cloud providers that are increasingly the default for application deployment and other services delivery online.
Selecting the right HSM for your needs and your future growth is essential. HSMs are a significant purchase, and they do not all deliver the same functionality. Entrust HSMs are the ideal choice, and they outline the reasons why in the eBook.
Next Steps
Entrust are a top tier trust service provider who can deliver all of the products a business needs to fulfil their eIDAS requirements. From physical HSMs to cloud-based certificates and other security services, Entrust has the products and expertise you need.
Read the free eBook to discover more detail than we cover in this article. And contact Renaissance if you want to talk about Entrust HSMs, other Entrust solutions, or any other cybersecurity related topic.

