K-INFO
HU
EN
Login

Electronic Signatures within the Public Key Infrastructure

Elektronikus aláírások a nyilvános kulcsú infrastruktúrában
A tantárgyleírás hatályossága
Hatályosság kezdete:
2026. March 21.
Hatályosság vége:
Subject name (Hungarian, English)
Elektronikus aláírások a nyilvános kulcsú infrastruktúrában
Electronic Signatures within the Public Key Infrastructure
Subject code BMEVIHIA034
Subject type
Training Level
Course types and hours (weekly/semester)
Course type lecture tutorial laboratory
hours (weekly) 2 0 0
type (linked/independent)
Assessment type vizsga
Credits 2
Subject coordinator
Dr. Félegyházi Márk
Responsible department
Hálózati Rendszerek és Szolgáltatások Tanszék
Faculty Villamosmérnöki és Informatikai Kar
Subject website
Primary curriculum type
Direct prerequisites – Strong prerequisite none
Direct prerequisites – Weak prerequisite none
Direct prerequisites – Parallel prerequisite none
Direct prerequisites – Milestone prerequisite none
Direct prerequisites – Exclusion none

Objectives

Programme
  • Introduction
Students gain an overview of the basic terms of PKI, such as: certificate, certificate authority, relying party and the concepts of encryption, authentication and electronic signature.
  • Cryptographic background
The concept of a cryptographic key is introduced and Kerckhoffs’ principle is explained. A brief summary is provided on cryptographic primitives necessary for understanding PKI: the basics of public key cryptography and cryptographic hash functions are explained. The RSA cryptosystem is outlined as an example for a public key cryptosystem.
  • Certificate
The concepts of public key certificate and certificate policy are explained. The structure and the lifecycle of a certificate (registration, issuance, use, verification, revocation, expiration etc) are explained. It is also justified why it is not possible to have just one certificate and to use it everywhere.
  • Certificate Authority (CA)
Students gain an understanding of what a certificate authority is, how it operates and what security measures it implements.
  • Certification chains
Certificate authorities can be interconnected via ‘cross-certification’ that allows an end-user trusting one CA to verify and accept certificates issued by another one. Various PKI structures (hierarchical, bridged, mesh etc) are demonstrated. Possible problems and their solutions are addressed.
  • Electronic signatures
The concepts of advanced electronic signature and qualified electronic signature are explained, the legal difference between them is highlighted. The processes of creating and verifying electronic signatures are demonstrated, and some widespread signature formats (e.g. PKCS#7, XMLDSIG, XAdES, CAdES) are explained. The concept of signature policy is explained.
  • Visit to Microsec
A visit to Microsec premises where students meet a real certification authority. Students also receive a smart card containing public key certificates that can be used for creating qualified electronic signatures.
  • Time stamping
When verifying an electronic signature, we need to know that the signature existed at a certain point of time. If such a trusted point of time is not available, verification becomes ambiguous and signatures can be easily repudiated. Time stamping is perhaps the most straightforward way of obtaining and preserving such time evidence.
  • Long-term archiving of electronic signatures
If the verifiability of an electronic signature needs to be preserved for a long period of time (e.g. for 50 years), special measures must be taken.
  • Encryption and partner authentication using PKI
While the public key infrastructure used for signatures, can also be used for encryption or partner authentication, it requires a fundamentally different approach. Such differences are highlighted. An even deeper insight is provided into web-based authentication using the secure socket layer (SSL) protocol, which constitutes perhaps the most widespread use of PKI.
  • Certificates & roles – attribute certificates
While public key certificates can contain information on the role of the certificate holder, it is beneficial to separate the role from the public key. Attribute certificates provide a standardized solution for this.
  • How can electronic signatures be used? How are they used?
While the legal framework for electronic signatures has been in place for more than ten years, there are relatively few applications yet. Case studies shall be presented on both successful and less successful applications.
The European and the American concepts of electronic signatures (or digital signatures) are fundamentally different; the European PKI is much more heavily regulated both by laws and by technical standards. While students attending the course shall gain a general understanding of the international principles of PKI, they shall also gain insight into the European legal framework and the European electronic signature standards. By completing the course, students shall be able to evaluate if it pays off to use PKI in a certain situation, and if PKI is used, they shall be able to address its issues and design a PKI-enabled system better. If they later choose to work either in Europe or together with European companies, they shall benefit from the course e.g. when setting up e-invoicing for their company. Students shall also learn how to differentiate between various types of certificates, and they shall be able to select the right web server certificate for websites or web stores they shall operate. As the course is on security, it aims to inspire the security-oriented way of thinking, which means ‘thinking with the head of the attacker’ and trying to find the weak points of a system (e.g. a system for signature verification) where it can be ‘hacked’. As PKI relies on cryptography, it is one of those few areas where mathematics can be applied in practice directly. In the practical part of the course, students shall be able to try out what they learned. They shall visit a Hungarian PKI service provider, and shall receive hands-on experience from makers of European PKI.

Learning outcomes

Ez a tantárgy a KKK rendeletben meghatározott, következő kompetenciák fejlesztését szolgálja:

Knowledge

No learning outcomes recorded.

Skills

No learning outcomes recorded.

Attitudes

No learning outcomes recorded.

Autonomy and responsibility

No learning outcomes recorded.

Oktatási módszertan

The course is organized in lectures. Slides for lectures shall be available for students. Students shall receive devices for creating qualified electronic signatures throughout the course, and shall also receive homework they need to solve with their signatures.

Tanulástámogató anyagok

Online források
On cryptography:; Bruce Schneier, Applied Cryptography, second edition, John Wiley & Sons, 1996; On public key certificates:; Peter Gutmann, X.509 Style Guide, 2000; Laws and regulations:; Directive 1999/93/EC of the European Parliament and of the Council of 13 December 1999 on a Community framework for electronic signaturesThe Hungarian Act 2001/35 on electronic signatures (as an example for local e-signature regulation in an EU member state); Standards and specifications:; X.509 – Information technology - Open Systems Interconnection - The Directory: Public-key and attribute certificate frameworksETSI TS 101 903 – XML Advanced Electronic Signatures (XAdES)ETSI TS 101 456 – Policy requirements for certification authorities issuing qualified certificates

Recommended preliminary knowledge for completing the subject

Knowledge type competencies
(azon előzetes ismeretek összessége, amelyek megléte nem kötelező, de a tantárgy eredményes teljesítését nagyban elősegíti)
Interest in IT security is required. No prior knowledge of either law or cryptography is needed. Students are required to have a general knowledge of computers and of Internet use only
Skill type competencies
(azon előzetes képességek és készségek összessége, amelyek megléte nem kötelező, de a tantárgy eredményes teljesítését nagyban elősegíti)
nincs
Recommended (non-compulsory) preliminary competencies
(azon ajánlott (nem kötelező) előzetesen megszerzendő kompetenciák összessége, amelyek jelentősen hozzájárulnak a tantárgy eredményes teljesítéséhez)
Interest in IT security is required. No prior knowledge of either law or cryptography is needed. Students are required to have a general knowledge of computers and of Internet use only
General rules
Requirements: Written exam at the end of the course
Assessment methods
In-term assessments

No detailed assessments provided.

Weight of in-term assessments

No weights provided.

Exam-period assessments

No detailed assessments provided.

Weight of exam elements

No weights provided.

Grade calculation

No grade thresholds provided.

Attendance requirements

No attendance requirements provided.

Rules for retake and resubmission

Not provided.

Short description

Not provided.

Detailed description

Not provided.

Recommended courses
Electronic signatures yield an interdisciplinary field between law and computer science. There is no need to print an electronic document just because we need to sign it. A document can also be signed purely electronically, by encoding it using certain mathematical (cryptographic) methods that can create legally binding ‘electronic signatures’. According to the European legal framework established by Directive 1999/93/EC, the so-called ‘qualified’ electronic signatures are to be considered equivalent with handwritten signatures in all member states of the EU. The course provides an overview of electronic signatures and the public key infrastructure (PKI), the technology behind them. While it approaches the topic from the technical point of view, it also embraces the mathematical, regulatory, legal and economic aspects of electronic signatures. The course gives further insight into the public key infrastructure (PKI) and shows how the same technology is used for other purposes like encryption, partner authentication or secure web access (e.g. secure socket layer, SSL).
Workload to complete the subject

No workload breakdown provided.

Validity of subject requirements
Requirements valid from:
Requirements valid until:
Curriculum placement

No curriculum placements recorded for this subject version.