Platform security
Robust authentication of players and partners
Collaborative Platform (EP) users are authenticated in depth on the Platform, thanks to SSL V3 technology. The electronic certificate including encoding keys is unique to each user and is contained in a physical personally delivered support such as micro-chipped card or dongle.
In addition, the ENX routers, entry points for the network at each partner, carry out a mutual authentication as part of the operation of the IPSec tunnels.
Confidentiality and Integrity
Data confidentiality is assured at three levels:
At network level: the ENX operators guarantee flow separation within ENX from any other flows, using Frame relay or MPLS technologies.
In the IP layer (between two partners): implementation of IPSec encoded tunnel technology.
At application level (between two machines): use of the HTTPS protocol, supplementary authentication and encoding.
Availability
The ENX net has a guaranteed level of service and data rate. The hosting contract for the Collaborative Platform Hub also provides for a high level of availability. The complete chain that exists between two partners therefore offers an overall level of availability that exceeds that of the Internet.
Non-repudiation
Exchanges via the Collaborative Platform Hub are traced and the logs are recorded. Non-repudiation is guaranteed through the use of user certificates enabling encoding but also the application of electronic signatures.
Compartmentalisation of players and resources into communities or clubs
The services offered by the Collaborative Platform (EP) enable users to create working communities that bring together partners and organise the sharing of resources specific to the community (applications, exchange scenarios, bulletins, etc.). Access to resources is thus compartmentalised between the various communities. The management of this is decentralised to partner level.
Clubs are limited communities restricted to a small number of users. The existence of a club and its resources is only visible to its members.
The Collaborative Platform agreement
Any partner that applies to use the Collaborative Platform (EP) must read the Collaborative Platform agreement and ensure it is signed by an approved signatory authority. This agreement covers technical, legal, financial and user aspects of the Collaborative Platform. On security matters, this agreement refers to the Collaborative Platform internal security policy (ISP) and the Certification Policies (“PC”). Signature of this agreement engages the partner.
|