Topic 02: A Study on Malaysian Digital Signature Market Demand and Feasibility of Certification Authority Interoperability

A Study on Malaysian Digital Signature Market Demand and Feasibility of Certification Authority Interoperability

Assoc. Prof. Dr. Azni Haslizan Ab Halim

Lead Researcher
Universiti Sains Islam Malaysia

Assoc. Prof. Dr. Farida Hazwani Mohd Ridzuan

Team Member
Universiti Sains Islam Malaysia

Assoc. Prof. Dr. Sakinah Ali Pitchay

Team Member
Universiti Sains Islam Malaysia

Assoc. Prof. Dr. Najwa Hayaati Mohd Alwi

Team Member
Universiti Sains Islam Malaysia

Dr. Maziahtusima Ishak

Team Member
Universiti Sains Islam Malaysia

01 ABSTRACT

The adoption of digital signatures is becoming increasingly important due to its many advantages, including increased security, convenience, and cost savings. Despite these benefits, a significant challenge lies in the lack of crossCertification Authority (CA) interoperability, hindering the seamless use of digital signatures across diverse platforms and services. This study aims to explore the CAs’ views on interoperability across their platforms, the value and implications of such practice, and to establish the potential relationship between interoperability and increased digital signature efficiency and market demand. Interviews with 15 participants, including managers and technical experts from three (3) CAs, gathered insights on the potential relationship between interoperability and increased efficiency and market demand for digital signatures. Subsequently, a systematic literature review (SLR) analysed 57 articles to understand interoperability issues and challenges in various countries. The findings revealed that Malaysian CAs are currently wellequipped to handle the existing demand for digital certificates, actively preparing for anticipated medium-term growth through scalability, automation, and infrastructure enhancements. The study shows a synergistic relationship between increased digital signature efficiency, interoperability, and potential market demand, emphasising the transformative impact of digital signature on productivity. Thus, achieving interoperability among CAs in Malaysia is crucial for advancing Malaysia’s digital economy. It requires collaboration among CAs, the Malaysian Communications and Multimedia Commission (MCMC) as a regulatory body and other stakeholders to address technical, business, and governance challenges. While the National Root CA is a subject of discussion, alternative solutions, such as trust stores, are viable options. With the right infrastructure and policies in place, Malaysia can become a leader in the use of digital signatures and the promotion of cross-CA interoperability, which would benefit both individuals and businesses alike.
Keywords: Digital Signature, Certification Authority, Interoperability

02 introduction

The Digital Signature Act 1997 (DSA 1997) and Digital Signature Regulations 1998 (DSR 1998) provide the licensing framework for providing digital signatures in Malaysia, including the type of services, the qualification requirements, applications, and the respective fees. According to Government of Malaysia (1997) and Kadir (2012), the DSA 1997 defines a digital signature as an electronic method of authentication that uses a mathematical algorithm to validate the authenticity and integrity of a digital document or message. The act also provides for the recognition of digital signatures as legally binding and enforceable in electronic transactions. On the other hand, the DSR 1998 further provides detailed requirements for the creation, verification, and storage of digital signatures. The regulations specify the technical standards that must be used to create and verify digital signatures, including the use of public key cryptography and the X.509 certificate format (Chong, 1998). The acts also provide for the accreditation and regulation of Certification Authority (CA) that issues digital certificates and provide other services related to digital signatures. CAs are required to comply with strict security and operational standards and are subject to regular audits and inspections.

At present, there are four (4) CAs that issue digital certificates in Malaysia licenced by Malaysian Communications and Multimedia Commision (MCMC), namely Pos Digicert Sdn. Bhd.; MSC Trustgate Sdn. Bhd.; Telekom Applied Business Sdn. Bhd.; and Raffcomm Technologies Sdn. Bhd. These CAs provide digital signature services to various clients and organisations in Malaysia including government agencies, financial institutions, healthcare providers, and businesses of various sizes and industries. Currently, a user who has been issued a digital certificate from one (1) CA would not be able to use the same digital certificate on another CA’s platform. This is because each CA has its own unique digital certificate, which is based on its own digital signature and public key (Afshar, 2015). When a user obtains a digital certificate from a CA, the certificate is signed by the CA’s private key and includes the CA’s public key. If the user tries to use their digital certificate on another CA platform, the platform will not be able to verify the certificate’s digital signature, and the certificate will be considered invalid. However, there are efforts underway to promote interoperability among different CAs in Malaysia. This would allow digital certificates issued by one (1) CA to be used on another CA’s platform, as long as both CAs have agreed to the same interoperability standard. This would make it easier for users to use their digital certificates across multiple platforms, and it could help to promote wider adoption of digital signatures.

Problem Statement

The legislative landscape for digital signatures in Malaysia is defined by the DSA 1997 and DSR 1998. This legal framework governs various aspects, including the types of services provided, qualification prerequisites, application processes, and associated fees (Government of Malaysia, 1997). For a digital signature to be recognised as valid, enforceable, and effective in Malaysia, it must undergo certification and validation by licensed CAs. The principal role of a CA is to issue a subscriber’s certificate, confirming the identity to be embedded in the certificate as per the provisions outlined in the DSA 1997.

Despite the presence of multiple CAs in Malaysia, the lack of interoperability among them creates challenges for users who need to use digital signatures across different platforms. Currently, a user who obtains a digital certificate from one (1) CA cannot use the same certificate on another CA’s platform. This limits the flexibility and ease of use of digital signatures, which can be a barrier to wider adoption and usage of digital signatures in Malaysia (Kamaruzaman et. al., 2010). Therefore, there is a need to explore the feasibility of establishing interoperability among different CAs in Malaysia and identify potential strategies and approaches for achieving this goal. The research will focus on understanding the current state of interoperability among CAs in Malaysia, identifying the technical and regulatory barriers to interoperability, and evaluating best practices and policies adopted in other countries to promote interoperability. The research will also investigate the potential benefits of interoperability, including increased efficiency, enhanced security, and improved user experience. Ultimately, the goal of the research is to provide recommendations for promoting interoperability among different CAs in Malaysia to drive better adoption and usage of digital signatures.

Research Objective

The objectives for this research are as follows:

RO1

To identify the capacity of the existing four (4) Certification Authorities (CAs) to meet current and forecasted medium-term demand;

RO2

To establish the relationship between increased digital signature efficiency and interoperability against potentially higher market demand and adoption of digital signatures;

RO3

To explore through literature review the best practices on how interoperability has been promoted for Digital Signatures in other countries for potential adoption for Malaysian CAs in promoting digital signatures;

RO4

To gather input and feedback from CAs on the interoperability among the CAs; and

RO5

To provide recommendations on the best practices, standards adoption, and/or policy or legislative approaches for increasing digital signature efficiency, interoperability, and market demand.

03 literature review

Public Key Infrastructure

A Public Key Infrastructure (PKI) is a system that provides a secure method for exchanging digital information. It is a set of policies, procedures, hardware, software, and roles that are used to create, manage, distribute, use, store, and revoke digital certificates. PKI is used to facilitate the secure electronic transfer of information for a range of network activities such as e-commerce, internet banking, and confidential email (Albargi et. al., 2015).

Utilising asymmetric cryptography forms the basis for the functionality of the PKI. In this system, each user has a pair of keys known as the public key and private key. The public key is used to encrypt data, while the private key is used to decrypt it. The private key is kept secret by the user, while the public key is made available to anyone (Stallings, 2017).

In modern-day digital communication, the PKI stands as a crucial element. It provides a secure and reliable way to exchange information over the Internet. PKI is used in a wide range of applications, including secure email, online banking, e-commerce, and digital signatures. The use of PKI ensures that the information being exchanged is authentic, confidential, and tamper-proof (Singh, 2018). A comparison of PKI definitions among ASEAN countries is shown in Appendix 1.

It is shown that Indonesia (Republic of Indonesia, 2008), Laos (Government of Lao People’s Democratic Republic, 2012), Myanmar (The Union of Myanmar, 2004), and Thailand (Kingdom of Thailand, 2001) do not define PKI, Public Key, and Private Key in their law and act. There are several reasons why these countries do not provide these definitions. Firstly, lack of awareness or understanding of the benefits and challenges of PKI for enhancing the security and trust of electronic transactions and communications. Additionally, the absence of technical expertise or resources hinders the implementation and maintenance of a national PKI system (Singh, 2018). Moreover, insufficient political will or commitment impedes the harmonisation of national laws and regulations with regional or international standards and best practices on PKI. Furthermore, inadequate cooperation or coordination among relevant stakeholders hampers the development and promotion of PKI adoption and development (Albargi et. al., 2015). Lastly, limited demand or incentive from users or customers of PKI services, such as individuals, businesses, and organisations, to utilise digital certificates for their electronic transactions and communications.

Adoption of Digital Signatures

Malaysia has made significant progress in the adoption of digital signatures. The Electronic Commerce Act was implemented in 2006 with the purpose of granting legal acknowledgement to electronic signatures (Government of Malaysia, 2006). The introduction of the DSA 1997 has provided a legal framework for the utilisation of digital signatures in Malaysia, hence further reinforcing this notion (Government of Malaysia, 1997).

The digital signature process involves the actions of signing and verifying. Signing means the sender employs a mathematical method to create a unique digital signature for the message or document using a private key. Signatures are created by combining message content with the sender’s private key (Saripan & Hamin, 2011). On the other hand, verification indicates that the recipient can verify the digital signature using the sender’s public key. The recipient uses the sender’s public key to process the message and digital signature. If the computed signature matches the digital signature, the message is legitimate and hasn’t changed since signing.

MCMC performed a survey in 2019 (MCMC, 2021), which revealed an upward trend in the use of digital signatures among users in Malaysia. According to the survey findings, a significant proportion of firms in Malaysia, specifically 63 per cent, employ digital signatures as a means of conducting their transactions. Similarly, a substantial majority of government organisations, precisely 87 per cent, utilise digital signatures for their internal procedures. The demand for digital certificates has grown significantly, with 19,203,000 digital certificates issued in 2023 as compared to 13,800,000 issued in 2019 (MCMC, 2023). Nevertheless, despite the considerable rate of acceptance, there are certain difficulties that require attention and resolution. A significant obstacle that arises is the absence of interoperability between different CAs.

CA Interoperability

Cross-CA interoperability refers to the ability of different CAs to recognise and accept each other’s digital certificates (Brands, 2000) (Prasad & Kaushik, 2019). This is essential for the seamless use of digital signatures across different platforms and systems (Wazan et. al., 2013). In Malaysia, cross-CA interoperability is still a challenge. Currently, there are four (4) CAs in Malaysia that issue digital certificates. However, they do not recognise each other’s certificates which makes it difficult for users to use their digital certificates across different platforms and systems.

CA interoperability challenges are the difficulties or barriers that arise when different CAs try to exchange or validate digital certificates across different domains, jurisdictions, or standards. Interoperability challenges can affect the security, trust, and efficiency of digital transactions that rely on digital signatures and certificates (Prima & Sucahyo, 2011) (Stegemann & Gersch, 2019). There are three (3) common interoperability challenges identified in this study.

The first challenge is the lack of common standards or frameworks for digital certificates and signatures. Different CAs may use different formats, algorithms, or protocols for issuing and verifying digital certificates and signatures. This can create compatibility issues and increase the complexity and cost of interoperability. Next is the lack of mutual recognition or accreditation among CAs. Different CAs may have different policies, procedures, or criteria for issuing and validating digital certificates and signatures. This can create trust issues and legal uncertainties among CAs and their users.

Lastly, lack of cross-border or cross-domain cooperation among CAs. Different CAs may operate in different geographical or functional domains, such as countries, regions, sectors, or industries. This can create regulatory or technical challenges for interoperability.

04 methodology

This research was systematically divided into two (2) distinct phases, each tailored to the specific aims of the study. This dichotomy allowed for a comprehensive approach to our investigation and ensured a thorough exploration and analysis of the subject matter. The first phase focused on qualitative analysis through openended interviews that directly addressed objectives 1 and 2. The second phase involved a systematic literature review, targeting objectives 3 to 5.

Phase 1: Open-ended Interviews

In the first phase of the study, a qualitative approach was utilised, specifically through open-ended interviews. This method, widely recognised in qualitative research, facilitates a deep and comprehensive understanding of specific topics (Moser & Korstjens, 2018). The focus was on gathering data from four (4) existing CAs, with an emphasis on selecting representatives actively involved in the CA’s operations. These representatives were chosen from both managerial and operational levels, ensuring a varied and insightful perspective on the issues at hand.

Research Design

The objective of this approach is to collect data from CAs by carefully selecting individuals who are directly involved in their operations. The selection of the representative will encompass individuals holding managerial and operational positions, thus facilitating the acquisition of diverse perspectives on the issues at hand. In order to validate the semi-structured interview’s content, the assessment made by various experts from MCMC on different aspects of the interview was considered. Next, the interview data is transcribed and analysed utilising the software tool Atlas.ti. Atlas.ti facilitates the analysis of interview material by organising it thematically and generating summaries of the findings (Ronzani et. al., 2020).

Research Instrument

The interview sessions with three (3) CAs have been conducted via online and face-to-face interview sessions to gather the “collective wisdom” and explore the similarities and divergences across different CAs. There are 29 with 4 sections in the semi-structure interview questions. Section A is the background questions, where the experience of the participants on the topic is mapped, as well as the general impressions about CA’s operation.

In this section, the participants are also asked to explain the process that they have gone through in dealing with the digital signatures to bring the topic into their minds before going deeper into the questions. Section B consists of questions regarding CA’s capacity to handle higher market demand for digital signatures and then Section C consists of questions about the relationship between increased digital signatures efficiency and interoperability against potentially higher market demand. The last section which is Section D consists of questions about CA’s interoperability issues and challenges to answer RO4. The questions are focused on CAs’ opinions or suggestions on how to achieve interoperability including technical challenges, possible solutions, and proposed time frame for a full interoperability of the CA.

The participants were provided with questionnaires in advance of the interview session to facilitate their preparation for accurate responses. The questions asked during the interviews reflected the specific objectives of the study. An interview guide was used to ensure that relevant questions were asked but not used rigidly. Where appropriate, additional questions were asked that were relevant to participants’ situations, especially when new issues emerged during the interviews.

Sampling

Although there are four (4) CAs, only three (3) CAs participated in the interview conducted. Table 1 shows a total of 15 participants from three (3) CAs was considered an appropriate sample size to obtain diverse insights while remaining manageable for detailed analysis. Participants were carefully selected from management and operational positions within CAs to ensure a diverse and representative sample. The selection criteria included experience, decisionmaking capacity, and direct involvement in CA operations to ensure a comprehensive understanding of the subject matter.
Table 1@3x
Table 1: List of 15 Participants Involved in the Study

Data Collection

The interviews were conducted using two (2) methods: face-to-face and online. To ensure a consistent approach across both methods, specific strategies were employed. Verbal consent for participation and audio-record the interview was obtained during the interviews. The researchers emphasised maintaining the anonymity of the participants and the confidentiality of the study findings. Following the interviews, the data collected underwent rigorous thematic analysis. This step was essential for identifying and confirming the key themes relevant to the study’s objectives.

Data Analysis

The interview transcripts, each with an average length of 60 minutes, were meticulously transcribed word-forword, adhering to strict guidelines to ensure thorough accuracy. This detailed transcription process included capturing non-verbal cues and significant pauses, essential for maintaining the integrity of the conversations. The analysis of this interview data was conducted using the Atlas.ti software, which was particularly effective for its thematic coding and organisational capabilities. This software played a crucial role in dissecting the intricate narratives, enabling the extraction of key themes that closely aligned with the central research questions. Triangulation methods were also employed, using multiple data sources and methods to validate and corroborate the findings, enhancing the study’s credibility.

Phase 2: Systematic Literature Review

In the second phase of the study, a systematic literature review was conducted in order to answer our Research Objective 3, which included a comprehensive search of multiple databases (journal articles, international standards, guidelines, policies, and frameworks) using targeted keywords with a focus on digital signatures and CA interoperability. Strict inclusion and exclusion criteria were applied to select only the most relevant and highquality sources. The aim was to uncover and examine best practices for improving the interoperability of digital signatures in different countries in order to assess their applicability and potential adoption in Malaysia.

Literature resources in this report were collected from multiple digital databases being actively used by researchers including Google Scholar and Google search engine. Initially, 339 articles that focused on digital signatures were retrieved from the search engine. The articles were reduced to 57 articles that fall under the category of CA interoperability.

The technique used in the systematic literature review adopts the Preferred Reporting Items for Systematic Reviews and Meta-Analysis (PRISMA) (Moher et. al., 2009). The review methodology for this work involves four (4) steps that consist of identification, screening, eligibility, and inclusion as depicted in Figure 1.
Asset 1 (1698x1190)
Figure 1: Systematic Literature Review Analysis Flow Diagram
The basis of the identification process makes use of the keywords searching strategy as shown in Table 2 to retrieve articles from the database. Keyword searching strategy guides researchers in searching for the main information used to describe the research topic. Without the right keywords, it might be difficult to find appropriate articles needed for the literature. Using the keywords searching strategy, 339 articles were retrieved.
Table 2@3x
Table 2: Keywords Searching Strategy
Next, the screening process identifies the suitability of literature resources to be included in the survey based on the article selection criteria listed in Table 3. With hundreds of articles found in the database, it is crucial to select significant resources that are useful to the researchers. The type of article, language, and the domain of the article are important criteria in selecting the articles. The criteria specify the research requirements so that researchers will not deviate from their research scope. These criteria will guide researchers in structuring the output of the research from the input obtained from the articles. During the screening process, 187 articles were filtered from the resources.

The eligibility process retrieves the fulltext articles that have been identified in the previous step. From the 187 identified resources, 57 articles were successfully assessed and downloaded that are used in the next stage of the systematic literature review methodology.

Lastly, the inclusion process gathers all of the assessed articles to be included in the study. The systematic literature review methodology would help researchers to conduct their research by finding accurate resources. Without using this methodology, researchers may have to read and review thousands of articles with no clear direction.
Table 3@3x
Table 3: Article Inclusion and Exclusion Criteria

05 finding and analysis

To identify the capacity of the existing four (4) Certification Authorities (CAs) to meet current and forecasted medium-term demand

Based on analysis using Atlas.ti, the capacity of the CA to meet current demand is shown in Figure 2. The overall results show that the Certificate Authority (CA) to are currently equipped to handle the current demand for digital certificates.

Infrastructure which is the foundational element of the CA’s technological backbone plays a crucial role in CA interoperability. A robust and scalable infrastructure is vital for accommodating the increasing demand for digital certificates efficiently. Adequate hardware, network resources, and scalability ensure that the CA can handle the evolving landscape of digital transactions securely.
Asset 2 (1134x784)
Figure 2: The Capacity of the CA to Meet Current Demand
From the analysis, the security measures and mechanisms significantly enhance the CA’s capacity by prioritising the integrity and reliability of its operations. A well implemented PKI not only bolsters the overall security posture but also directly influences the CA’s capacity by streamlining digital certificate issuance and management processes. Concurrently, security mechanisms like firewalls, intrusion detection systems, and endpoint security reinforce the CA’s resilience, indirectly impacting its capacity by mitigating potential disruptions from security threats. This integrated approach ensures that the CA operates with heightened security and efficiency, aligning its capacity with the dynamic demands of the digital landscape.

On the other hand, human resources play a pivotal role in determining the CA’s capacity. Skilled personnel are indispensable for overseeing, monitoring, and administering the CA’s operations effectively. The role of human resources extends beyond operational support to encompass capacity planning, ensuring that the CA is adequately staffed to meet increasing demands while maintaining a high level of security. This comprehensive strategy involves ongoing training and development to keep the workforce abreast of evolving technologies and security best practices, reinforcing the human element as a critical factor in the CA’s capacity.

User adoption cost and regulatory support and policy form additional considerations in the holistic approach to the CA’s capacity. By streamlining user adoption processes, making them cost-effective, and ensuring regulatory compliance, the CA can collectively enhance its ability to meet current demand. An efficient user adoption process can stimulate widespread acceptance of digital certificates, potentially leading to increased demand. Meanwhile, clear regulatory frameworks provide a stable environment within which the CA operates, ensuring that its capacity aligns with legal requirements and industry standards. As CAs take this comprehensive approach, integrating infrastructure, security, human resources, user adoption strategies, and regulatory compliance, they navigate and effectively address the multifaceted challenges of meeting current demand.

While CAs exhibit varying levels of scalability and automation, the majority are taking proactive measures to prepare for the forecasted medium-term increase in demand. Adopting a holistic approach that integrates infrastructure enhancement, process optimisation, training, and collaboration, these CAs aim to ensure the continued issuance of secure and reliable digital certificates to meet the evolving needs of the digital landscape. This strategic alignment positions CAs to effectively address the multifaceted challenges associated with meeting current demand.

To establish the relationship between increased digital signature efficiency and interoperability against potentially higher market demand and adoption of digital signatures

From the analysis, it is expected that the increased in digital efficiency and interoperability lead to higher market demand. The relationship between increased digital signature efficiency, interoperability, and potential market demand and adoption of digital signature is synergistic as shown in Figure 3.
Asset 3 (1477x865)
Figure 3: The Relationship Between Increased Digital Signature Efficiency and Interoperability Against Potentially Higher Market Demand and Adoption of Digital Signature
It is also proven true that there is a consensus that digital signatures significantly improve efficiency and productivity in various tasks and workflows. They eliminate the need for physical signing, printing, and scanning of documents, enabling users to sign and approve documents from anywhere with an internet connection (Earl & Kimport, 2011) (Gupta et. al., 2004). Digital signatures also facilitate the enforcement of standard operating procedures (SOPs) by allowing for predefined signing sequences and timestamps, ensuring compliance with regulations.

The analysis also shows there are efforts to promote the adoption of digital signature technology, such as workshops, roadshows, and awareness campaigns. There is a focus on approaching targeted organisations and individuals to demonstrate the benefits and use cases of digital signatures. Trust in digital signature technology is crucial for its adoption. The interviews mention various efforts to inform users about the benefits and limitations of digital signatures. These efforts include social media promotion, workshops, direct pitches to organisations, and proof of concept demonstrations. Compliance with international standards, such as WebTrust certification, is highlighted as a way to ensure trust in digital signature technology (Patton & Jøsang, 2004). Digital signatures are perceived as highly useful and productive, leading to increased efficiency in various tasks, which can drive market demand and adoption. When the market demand for digital transactions rises, efficient and interoperable digital signatures become essential for meeting user expectations, regulatory requirements, and seamless integration with digital workflows.

Thus, the relationship between increased digital signature efficiency and interoperability is crucial for driving higher market demand and adoption of digital signatures. Efficient digital signature processes, coupled with interoperability between different providers and platforms, can enhance user experiences and productivity, ultimately leading to greater trust and adoption of this technology. Efforts to promote digital signatures and build trust among users play a pivotal role in driving adoption within both government and private sectors.

To explore through literature review the best practices on how interoperability has been promoted for Digital Signatures in other countries for potential adoption for Malaysian CAs in promoting digital signatures

Efforts to enhance CA interoperability are crucial for building a secure and connected digital ecosystem. This becomes particularly relevant as organisations and individuals increasingly rely on digital signatures, secure email communication, and other PKI-based services in their daily operations (Paulus et. al., 2004). Standards organisations and industry collaborations play a significant role in driving interoperability initiatives within the PKI space.

This study analyses CA interoperability models to identify the best model to be proposed to the government of Malaysia. The risk analysis was done based on the CAs interoperability models as shown in Table 4.
Table 4@3x
Table 4: Risk Analysis on CA Interoperability Models
From the risk analysis in Table 4, the best model can be suggested for Malaysian CA interoperability is the Bridge model. Choosing the Bridge CA model for CA interoperability in Malaysia has several justifiable reasons. Firstly, this model involves moderate costs, offering a balance between affordability and the structured interoperability framework it provides. The medium to high scalability of the Bridge CA model is beneficial for accommodating a potentially large and growing ecosystem, which is particularly important for a national CA infrastructure (Wazan et. al., 2013). In terms of security, the Bridge CA model carries moderate risks compared to a single root CA. In the event of a breach, participants in the network can still operate independently, minimising potential impacts (World Bank, 2007) (Danquah & Kwabena-Adade, 2020). The structured trust model of the Bridge CA simplifies the establishment of trust relationships, contributing to predictability and reliability within the interoperability framework.

Administratively, the Bridge CA model is more manageable than a full mesh model, making it easier to coordinate and enforce rules (Kakei et. al. 2020). The direct trust relationships inherent in this model enhance simplicity and clarity in the interoperability framework. Additionally, the Bridge CA model offers flexibility in implementation, allowing Malaysia to customise its interoperability framework based on specific technical and regulatory requirements while maintaining a centralised point of trust (Arseni et. al., 2021).

There is a clear trend in the current CA interoperability discussions to move towards the Bridge CA model as depicted in Appendix 2. The Bridge CA may be sitting above the Root CA/Hierarchy, Cross-Certification (Mesh), Cross Recognition, Certificate Trust List models, or even a combination of all of these. It would appear that the main advantage of Bridge CA is the provision of a stable third party to coordinate and promote CA interoperability by whatever means necessary.

In the absence of a Bridge CA, interoperability may fall between the cracks. Individual governments, accreditation agencies and CAs do not have sufficient motivation, skills, or resources to deliver and maintain interoperability (Yang et. al., 2019). In addition, the creation of a bridge allows interoperability to be achieved through staged testing and upgrades since perfect interoperability does not need to be achieved at once (Ford et. al., 2007).

The potential adoption of the Bridge CA model emerges as a strategic necessity for the government of Malaysia in bolstering its CA interoperability framework. The identified advantages, such as providing stable third-party coordination, promotion of interoperability through various means, and the facilitation of staged testing and upgrades, position the Bridge CA as a pivotal component in ensuring the seamless integration of PKI-based services (Hardin et. al, 2015). The evolving landscape of digital transactions and communications necessitates a robust and adaptive approach, and the Bridge CA model aligns with the current trends in CA interoperability discussions. By embracing this model, Malaysia can not only address the potential pitfalls of interoperability lapses but also promote a standardised and secure digital ecosystem that aligns with global best practices.

To gather input and feedback from CAs on the interoperability among the CAs.

Based on the findings of the interview with the CA, achieving interoperability among CAs in Malaysia is seen as a complex but possible goal. The CAs highlighted four (4) issues and challenges they faced to achieved interoperability. Below are details of the discussion for each identified challenges and issues related to interoperability.

a. Lack of Standardisation in Software

Despite the existence of a standard format like X.509, subtle deviations in implementation can impede seamless communication between different digital signature systems. Standardising certificate formats becomes imperative to ensure a consistent and universally accepted structure, facilitating smoother interoperability. The absence of standardised software implementations across different vendors contributes to interoperability challenges (Jardim-Goncalves et. al., 2006). As CAs employ their own proprietary software for digital signatures, disparities in implementation may arise, leading to compatibility issues. Addressing this challenge involves advocating for standardised software practices within the industry to enhance the coherence of digital signature systems. The result in this study highlights the importance of standardising software to alleviate interoperability issues.

b. Security Issues

Security and privacy issues arise when different systems interoperate, increasing potential risks. Companies may implement varying security measures based on their specific needs and requirements. This can result in inconsistencies across the organisation, making maintaining a uniform level of protection challenging. In addition, integrating the systems or applications for interoperability purposes can be complex when they have different security protocols (Kouroubali & Katehakis, 2019). Incompatibility between security measures may create vulnerabilities or points of weakness that attackers can exploit. The variations in authentication techniques might influence the overall usability and accessibility of the system.

c. Business Considerations

Interoperability may face resistance from CAs if perceived as conflicting with their business interests. The interviews underscore the importance of assessing the business implications of interoperability. CAs may question the benefits and alignment with their overarching business strategies, emphasising the need for a delicate balance between technological advancements and business considerations. Business considerations affecting interoperability has intersection between technology and business strategy (Agostinho et. al., 2016). It is suggested that a nuanced evaluation of the benefits and alignment with overarching business strategies is crucial for CAs facing interoperability decisions. Therefore, this study proposes that evaluating the perceived benefits and alignment with business strategies is crucial.

d. Business Operation

The issue of the integrity and security of business operations is of paramount importance. The continuity of business operations will be disrupted because of technological obstacles associated with interoperability (Nepelski, 2019). These challenges mostly pertain to the compatibility concerns arising from digital signature formats and certificate management, particularly in modifying signed documents. This issue is also interconnected with Business Considerations. The possible impact on the company encompasses various variables, including the loss of control and heightened competition.

To provide recommendations on the best practices, standards adoption, and/or policy or legislative approaches for increasing digital signature efficiency, interoperability, and market demand

The Malaysia acts that specify electronic and digital signatures are highlighted in three (3) documents. Firstly, the DSA 1997 that focuses on the legal recognition of digital signatures and their use in electronic transactions (Kadir, 2012). The act also provides legal recognition to digital signatures and digital certificates. In addition, it establishes the regulatory framework for CAs.

Secondly, the DSR 1998 which is a set of rules made under the DSA 1997. The regulations cover various aspects of licensing, certification, and auditing of digital signature authorities and repositories in Malaysia (Government of Malaysia, 1998). The regulations also specify the approved digital signature schemes and the requirements for key management and storage.

The Electronic Commerce Act 2006 on the other hand addresses various aspects of electronic commerce, including electronic contracts and the liability of network service providers (Government of Malaysia, 2006). The act recognises electronic messages and electronic contracts, as well as addresses the liability of network service providers for third-party content.

This study analyses the governing legislation of ASEAN countries to observe Malaysian acts against other international best practices and standards. In order to maintain the relevance and effectiveness of the above acts, it is crucial to recommend improvement. There are eight (8) recommendations for improvement as shown in Table 5.
Table 5@3x
Table 4: Risk Analysis on CA Interoperability Models
The DSA 1997, DSR 1998, and the Electronic Commerce Act 2006 have played pivotal roles in shaping Malaysia’s approach to electronic transactions. However, recognising the constant evolution of technology, it becomes imperative to proactively recommend enhancements to these acts. The eight (8) identified recommendations, ranging from bolstering cybersecurity measures to fostering innovation, collectively form a roadmap for the necessary modernisation of these long-standing legislations. By embracing these improvements, Malaysia not only aligns itself with international standards but also ensures the continued trust and efficiency of electronic transactions within its borders.

06 recommendations

Based on the findings of this study, a Certification Authority Interoperability Framework in Figure 4 is recommended to MCMC to bolster CA interoperability in Malaysia and ensure a robust and secure digital infrastructure to be adopted at the national level. This CA interoperability framework design is critical to enhance the seamless functioning of digital security infrastructures.
Asset 4 (1872x1142)
Figure 4: A Proposed Certification Authority Interoperability Framework
The proposed Certification Authority Interoperability Framework presents a comprehensive structure with key components that are instrumental in fostering effective CA interoperability. To fortify this framework, it is recommended to prioritise the PKI Trust Model across all components. This alignment with industry standards ensures a consistent and secure foundation for interoperability, fostering trust in the digital environment. A key focus should be on establishing a robust infrastructure and security measures as foundational elements. Encouraging CA to adopt state-ofthe-art security measures is essential to facilitate seamless interoperability without compromising data integrity and confidentiality (Lampathaki, 2011). Additionally, standardising protocols within the framework is crucial, ensuring that PKI applications adhere to common technical standards. This standardisation simplifies communication and data exchange between different CAs and PKI applications, promoting a cohesive and interoperable digital landscape.

In the next layer of framework, lies human resources, which play a pivotal role in the success of interoperable CA systems. To address this, it is recommended to invest in capacity-building initiatives for personnel involved in PKI management. Equipping them with the necessary skills ensures efficient implementation and maintenance of interoperable systems. Furthermore, a user-centric approach in the design of PKI applications is paramount, prioritising user experience and accessibility to encourage widespread adoption and utilisation by individuals and organisations (Perlman & Kaufman, 2008).

In conjunction, aligning the framework with government regulations and laws is vital as the pillar underpinning the other components. Collaboration with regulatory bodies ensures that policies governing PKI and CA operations are updated to accommodate interoperability requirements, fostering a regulatory environment conducive to secure and standardised digital transactions (Basu, 2004) (Tai & Ou, 2003). Simultaneously, education and promotion initiatives are recommended to raise awareness about the benefits of interoperable CAs and PKI systems. Engaging stakeholders through campaigns and training programmes contributes to building understanding and trust in the security and reliability of interoperable digital signatures.

Collectively, these recommendations fortify the proposed Certification Authority Interoperability Framework, positioning it to meet the dynamic demands of a secure and interoperable digital ecosystem in the ever-evolving landscape of cybersecurity and technological advancements.

07 conclusion

In conclusion, this study has provided valuable insights into the dynamic landscape of digital signatures in Malaysia. The findings underscore the growing importance of digital signatures in various sectors, driven by the increasing reliance on digital transactions and the need for secure and efficient authentication processes. The Malaysian digital signature market exhibits promising potential for growth, as businesses and individuals recognise the benefits of enhanced security, reduced paperwork, and streamlined processes.

Furthermore, the examination of the feasibility of CA interoperability has revealed crucial considerations for establishing a more connected and interoperable digital signature infrastructure. The interoperability of CAs is essential for fostering a seamless and trustworthy digital environment, promoting crossplatform compatibility, and ensuring the widespread acceptance of digital signatures.

As the digital landscape continues to evolve, the study highlights the importance of collaboration among stakeholders, including government bodies, businesses, and technology providers, to establish standardised practices and promote interoperability. The implementation of interoperable CAs can contribute significantly to the growth and maturity of the Malaysian digital signature market, fostering trust and confidence among users.

The insights gained from this study provide a foundation for future initiatives aimed at promoting the widespread adoption of digital signatures in Malaysia. By addressing the identified challenges and leveraging the opportunities presented, stakeholders can collectively contribute to the development of a robust and interoperable digital signature ecosystem, ultimately shaping a more secure and efficient digital future for Malaysia.

08 references

Kadir, R. (2012). Malaysian DSA 1997: A Review of Some Unresolved Issues. Asian Social Science, 8(12), 221.
Chong, J. (1998). A primer on digital signatures and Malaysia’s digital signatures act 1997. Computer Law & Security Review, 14(5), 322-333.
Afshar, R. (2015). Digital Certificates (Public Key Infrastructure). Indiana State University, Terre Haute.
Kamaruzaman, K. N., Handrich, Y. M., & Sullivan, F. (2010). E commerce adoption in Malaysia: Trends, issues and opportunities. ICT strategic review, 11.
Albarqi, A., Alzaid, E., Ghamdi, F., Asiri, S. and Kar, J. (2015) Public Key Infrastructure: A Survey. Journal of Information Security, 6, 31-37.
Stallings, W. (2017). The Principles and Practice of Cryptography and Network Security 7th Edition. Pearson Education, 20(1), 7.
Singh, S. (2018). Public Key Infrastructure (PKI) and its Applications. International Journal of Computer Sciences and Engineering, 6(5), 1-5.
Republic of Indonesia. Electronic Information and Transactions Law. (2008). https://www. icnl.org/wp content/uploads/Indonesia_elec.pdf.
Government of Lao People’s Democratic Republic. Law on Electronic Signature. (2012). http://www.laotradeportal.gov.la/kcfinder/upload/files/Electronic%20Transaction%20Law%20Eng.pdf
The Union of Myanmar. Electronic Transaction Law. (2004). https://www. myanmartradeportal.gov.mm/
uploads/legals/2018/12/
Electronic%20Transactions%20Law%202004(English).pdf.
Government of Malaysia. Electronic Commerce Act. (2006). https://aseanconsumer.org/ file/post_image/Act%20658%20-%20Electronic%20Commerce%20Act%202006.pdf.
Government of Malaysia. Digital Signature Act. (1997). https://www.mcmc.gov.my/skmmgovmy/
media/General/pdf/Act-562.pdf.
Saripan, H., & Hamin, Z. (2011). The application of the digital signature law in securing internet banking: Some preliminary evidence from Malaysia. Procedia Computer Science, 3, 248-253.
Brands, S. (2000). Rethinking public key infrastructures and digital certificates: building in privacy. Mit Press.
Prasad, A., & Kaushik, K. (2019). Digital signatures. In Emerging security algorithms and techniques (pp. 249-272). Taylor & Francis.
Wazan, A. S., Laborde, R., Barrere, F., Benzekri, A., & Chadwick, D. W. (2013). PKI interoperability: Still an issue? A solution in the X. 509 realm. In Information Assurance and Security Education and Training: 8th IFIP WG 11.8 World Conference on Information Security Education, WISE 8, Auckland, New Zealand, July 8-10, 2013, Proceedings, WISE 7, Lucerne Switzerland, June 9-10, 2011, and WISE 6, Bento Gonçalves, RS, Brazil, July 27-31, 2009, Revised Selected Papers 8 (pp. 68-82). Springer Berlin Heidelberg.
Prima, E., & Sucahyo, Y. G. (2011, December). Digital certificate based security system for electronic government: Case study of PKI implementation for securing electronic government procurement in Indonesia. In Proc. IADIS International Conference on Internet Technologies & Society (ITS) 2011 (pp. 109-120).
Stegemann, L., & Gersch, M. (2019). Interoperability - Technical or Economic Challenge?. it-Information Technology, 61(5-6), 243-252.
Moser, A., & Korstjens, I. (2018). Series: Practical guidance to qualitative research. Part 3: Sampling, data collection and analysis. European journal of general practice, 24(1), 9-18.
Ronzani, C. M., da Costa, P. R., da Silva, L. F., Pigola, A., & de Paiva, E. M. (2020). Qualitative methods of analysis: an example of Atlas. TITM Software usage. Revista Gestão & Tecnologia, 20(4), 284-311.
Moher David, Liberati Alessandro, Tetzlaff Jennifer, Altman Douglas G., The PRISMA Group. 2009. Preferred Reporting Items for Systematic Reviews and Meta-Analyses: The PRISMA Statement. PLoS Med 6(7), 1–6.
Earl, J., & Kimport, K. Digitally enabled social change: Activism in the internet age. Mit Press, (2011).
Gupta, A., Tung, Y. A., & Marsden, J. R. Digital signature: use and modification to achieve success in next generational e-business processes. Information & Management, 41(5), 561-575, (2004).
Patton, M. A., & Jøsang, A. Technologies for trust in electronic commerce. Electronic Commerce Research, 4, 9-21, (2004).
Paulus, S., Pohlmann, N., Reimer, H., Jeun, I., Lee, J., & Park, S. (2004). Asia PKI Interoperability Guideline. In ISSE 2004 - Securing Electronic Business Processes: Highlights of the Information Security Solutions Europe 2004 Conference (pp. 309 320). Springer.
World Bank (2007). e-Signature and PKI Frameworks: International Benchmarks. Final Report. https://documents1.worldbank.org/curated/
pt/438441468028444821/pdf/
694710ESW0P10300000Inception0Report.pdf
Danquah, P., & Kwabena-Adade, H. (2020). Public Key Infrastructure: An Enhanced Validation Framework. Journal of Information Security, 11(4), 241-260.
Kakei, S., Shiraishi, Y., Mohri, M., Nakamura, T., Hashimoto, M., & Saito, S. (2020). Cross-Certification Towards Distributed Authentication Infrastructure: A Case of Hyperledger Fabric. IEEE Access, 8, 135742-135757.
Arseni, Ș. C., Avram, D., Medvei, M., Togan, M., & Dima, A. (2021). Securing the C-ITS: A PKI Perspective.
Yang, C., Chou, T. C., & Chen, Y. H. (2019). Bridging digital boundary in healthcare systems—An interoperability enactment perspective. Computer Standards & Interfaces, 62, 43-52.
Ford, T. C., Colombi, J. M., Graham, S. R., & Jacques, D. R. (2007). A survey on interoperability measurement. Gateways, 2, 3.
Hardin, D., Stephan, E. G., Wang, W., Corbin, C. D., & Widergren, S. E. (2015). Buildings interoperability landscape (No. PNNL-25124). Pacific Northwest National Lab (PNNL), Richland, WA (United States).
Jardim-Goncalves, R., Grilo, A., & Steiger-Garcao, A. (2006). Challenging the interoperability between computers in industry with MDA and SOA. Computers in industry, 57(8-9), 679-689.
Kouroubali, A., & Katehakis, D. G. (2019). The new European interoperability framework as a facilitator of digital transformation for citizen empowerment. Journal of biomedical informatics, 94, 103166.
Agostinho, C., Ducq, Y., Zacharewicz, G., Sarraipa, J., Lampathaki, F., Poler, R., & Jardim- Goncalves, R. (2016). Towards a sustainable interoperability in networked enterprise information systems: Trends of knowledge and model-driven technology. Computers in industry, 79, 64-76.
Nepelski, D. (2019). How to facilitate digital innovation in Europe. Intereconomics, 54(1), 47-52.
Government of Malaysia. Digital Signature Regulations. (1998). https://www.posdigicert.com.my/public/uploads/files/
Digital_Signature_Regulations_1998.pdf.
Lampathaki, F., Tsiakaliaris, C., Stasis, A., & Charalabidis, Y. (2011). National interoperability frameworks: The way forward. In Interoperability in digital public services and administration: Bridging e-government and e business (pp. 1-24). IGI Global.
Perlman, R., & Kaufman, C. (2008, March). User-centric PKI. In Proceedings of the 7th Symposium on Identity and Trust on the Internet (pp. 59-71).
Basu, S. (2004). E‐government and developing countries: an overview. International Review of Law, Computers & Technology, 18(1), 109-132
Tai, G. C., & Ou, C. M. (2003, October). The development of PKI interoperability in Taiwan. In IEEE 37th Annual 2003 International Carnahan Conference on Security Technology, 2003. Proceedings. (pp. 405-409). IEEE.

09 appendix

Table 6@3x Table 7@3x Table 8@3x Table 9@3x

up next:

Digital Healthcare Adoption by Malaysian Senior Citizens: Its Challenges, Needs, and Future Action

by Ts. Dr. Chang Jing Jing, Dr. Seow Ai Na, Dr. Nurul Afidah binti Mohamad Yusof, Dr. Abdullah Sallehhuddin bin Abdullah Salim, Dr. Syarah Syahira binti Mohd Yusoff and Dr. Nani Draman
Read manuscript
download arrow-left arrow-right