The adoption of digital signatures is becoming increasingly
important due to its many advantages, including increased
security, convenience, and cost savings. Despite these benefits,
a significant challenge lies in the lack of crossCertification
Authority (CA) interoperability, hindering the seamless use of
digital signatures across diverse platforms and services. This
study aims to explore the CAs’ views on interoperability across
their platforms, the value and implications of such practice,
and to establish the potential relationship between
interoperability and increased digital signature efficiency and
market demand. Interviews with 15 participants, including
managers and technical experts from three (3) CAs, gathered
insights on the potential relationship between interoperability
and increased efficiency and market demand for digital
signatures. Subsequently, a systematic literature review (SLR)
analysed 57 articles to understand interoperability issues and
challenges in various countries. The findings revealed that
Malaysian CAs are currently wellequipped to handle the existing
demand for digital certificates, actively preparing for
anticipated medium-term growth through scalability, automation,
and infrastructure enhancements. The study shows a synergistic
relationship between increased digital signature efficiency,
interoperability, and potential market demand, emphasising the
transformative impact of digital signature on productivity.
Thus, achieving interoperability among CAs in Malaysia is
crucial for advancing Malaysia’s digital economy. It requires
collaboration among CAs, the Malaysian Communications and
Multimedia Commission (MCMC) as a regulatory body and other
stakeholders to address technical, business, and governance
challenges. While the National Root CA is a subject of
discussion, alternative solutions, such as trust stores, are
viable options. With the right infrastructure and policies in
place, Malaysia can become a leader in the use of digital
signatures and the promotion of cross-CA interoperability, which
would benefit both individuals and businesses alike.
Keywords: Digital Signature, Certification Authority,
Interoperability
02 introduction
The Digital Signature Act 1997 (DSA 1997) and Digital Signature
Regulations 1998 (DSR 1998) provide the licensing framework for
providing digital signatures in Malaysia, including the type of
services, the qualification requirements, applications, and the
respective fees. According to Government of Malaysia (1997) and
Kadir (2012), the DSA 1997 defines a digital signature as an
electronic method of authentication that uses a mathematical
algorithm to validate the authenticity and integrity of a
digital document or message. The act also provides for the
recognition of digital signatures as legally binding and
enforceable in electronic transactions. On the other hand, the
DSR 1998 further provides detailed requirements for the
creation, verification, and storage of digital signatures. The
regulations specify the technical standards that must be used to
create and verify digital signatures, including the use of
public key cryptography and the X.509 certificate format (Chong,
1998). The acts also provide for the accreditation and
regulation of Certification Authority (CA) that issues digital
certificates and provide other services related to digital
signatures. CAs are required to comply with strict security and
operational standards and are subject to regular audits and
inspections.
At present, there are four (4) CAs that issue digital
certificates in Malaysia licenced by Malaysian Communications
and Multimedia Commision (MCMC), namely Pos Digicert Sdn. Bhd.;
MSC Trustgate Sdn. Bhd.; Telekom Applied Business Sdn. Bhd.; and
Raffcomm Technologies Sdn. Bhd. These CAs provide digital
signature services to various clients and organisations in
Malaysia including government agencies, financial institutions,
healthcare providers, and businesses of various sizes and
industries. Currently, a user who has been issued a digital
certificate from one (1) CA would not be able to use the same
digital certificate on another CA’s platform. This is because
each CA has its own unique digital certificate, which is based
on its own digital signature and public key (Afshar, 2015). When
a user obtains a digital certificate from a CA, the certificate
is signed by the CA’s private key and includes the CA’s public
key. If the user tries to use their digital certificate on
another CA platform, the platform will not be able to verify the
certificate’s digital signature, and the certificate will be
considered invalid. However, there are efforts underway to
promote interoperability among different CAs in Malaysia. This
would allow digital certificates issued by one (1) CA to be used
on another CA’s platform, as long as both CAs have agreed
to the same interoperability standard. This would make it easier
for users to use their digital certificates across multiple
platforms, and it could help to promote wider adoption of
digital signatures.
Problem Statement
The legislative landscape for digital signatures in Malaysia is
defined by the DSA 1997 and DSR 1998. This legal framework
governs various aspects, including the types of services
provided, qualification prerequisites, application processes,
and associated fees (Government of Malaysia, 1997). For a
digital signature to be recognised as valid, enforceable, and
effective in Malaysia, it must undergo certification and
validation by licensed CAs. The principal role of a CA is to
issue a subscriber’s certificate, confirming the identity to be
embedded in the certificate as per the provisions outlined in
the DSA 1997.
Despite the presence of multiple CAs
in Malaysia, the lack of interoperability among them creates
challenges for users who need to use digital signatures across
different platforms. Currently, a user who obtains a digital
certificate from one (1) CA cannot use the same certificate on
another CA’s platform. This limits the flexibility and ease of
use of digital signatures, which can be a barrier to wider
adoption and usage of digital signatures in Malaysia
(Kamaruzaman et. al., 2010). Therefore, there is a need to
explore the feasibility of establishing interoperability among
different CAs in Malaysia and identify potential strategies and
approaches for achieving this goal. The research will focus on
understanding the current state of interoperability among CAs in
Malaysia, identifying the technical and regulatory barriers to
interoperability, and evaluating best practices and policies
adopted in other countries to promote interoperability. The
research will also investigate the potential benefits of
interoperability, including increased efficiency, enhanced
security, and improved user experience. Ultimately, the goal of
the research is to provide recommendations for promoting
interoperability among different CAs in Malaysia to drive better
adoption and usage of digital signatures.
Research Objective
The objectives for this research are as follows:
RO1
To identify the capacity of the existing four (4)
Certification Authorities (CAs) to meet current and forecasted
medium-term demand;
RO2
To establish the relationship between increased digital
signature efficiency and interoperability against potentially
higher market demand and adoption of digital signatures;
RO3
To explore through literature review the best practices on how
interoperability has been promoted for Digital Signatures in
other countries for potential adoption for Malaysian CAs in
promoting digital signatures;
RO4
To gather input and feedback from CAs on the interoperability
among the CAs; and
RO5
To provide recommendations on the best practices, standards
adoption, and/or policy or legislative approaches for
increasing digital signature efficiency, interoperability, and
market demand.
03 literature review
Public Key Infrastructure
A Public Key Infrastructure (PKI) is a system that provides a
secure method for exchanging digital information. It is a set of
policies, procedures, hardware, software, and roles that are
used to create, manage, distribute, use, store, and revoke
digital certificates. PKI is used to facilitate the secure
electronic transfer of information for a range of network
activities such as e-commerce, internet banking, and
confidential email (Albargi et. al., 2015).
Utilising
asymmetric cryptography forms the basis for the functionality of
the PKI. In this system, each user has a pair of keys known as
the public key and private key. The public key is used to
encrypt data, while the private key is used to decrypt it. The
private key is kept secret by the user, while the public key is
made available to anyone (Stallings, 2017).
In
modern-day digital communication, the PKI stands as a crucial
element. It provides a secure and reliable way to exchange
information over the Internet. PKI is used in a wide range of
applications, including secure email, online banking,
e-commerce, and digital signatures. The use of PKI ensures that
the information being exchanged is authentic, confidential, and
tamper-proof (Singh, 2018). A comparison of PKI definitions
among ASEAN countries is shown in Appendix 1.
It is
shown that Indonesia (Republic of Indonesia, 2008), Laos
(Government of Lao People’s Democratic Republic, 2012), Myanmar
(The Union of Myanmar, 2004), and Thailand (Kingdom of Thailand,
2001) do not define PKI, Public Key, and Private Key in their
law and act. There are several reasons why these countries do
not provide these definitions. Firstly, lack of awareness or
understanding of the benefits and challenges of PKI for
enhancing the security and trust of electronic transactions and
communications. Additionally, the absence of technical expertise
or resources hinders the implementation and maintenance of a
national PKI system (Singh, 2018). Moreover, insufficient
political will or commitment impedes the harmonisation of
national laws and regulations with regional or international
standards and best practices on PKI. Furthermore, inadequate
cooperation or coordination among relevant stakeholders hampers
the development and promotion of PKI adoption and development
(Albargi et. al., 2015). Lastly, limited demand or incentive
from users or customers of PKI services, such as individuals,
businesses, and organisations, to utilise digital certificates
for their electronic transactions and communications.
Adoption of Digital Signatures
Malaysia has made significant progress in the adoption of
digital signatures. The Electronic Commerce Act was implemented
in 2006 with the purpose of granting legal acknowledgement to
electronic signatures (Government of Malaysia, 2006). The
introduction of the DSA 1997 has provided a legal framework for
the utilisation of digital signatures in Malaysia, hence further
reinforcing this notion (Government of Malaysia, 1997).
The digital signature process involves the actions
of signing and verifying. Signing means the sender employs a
mathematical method to create a unique digital signature for the
message or document using a private key. Signatures are created
by combining message content with the sender’s private key
(Saripan & Hamin, 2011). On the other hand, verification
indicates that the recipient can verify the digital signature
using the sender’s public key. The recipient uses the sender’s
public key to process the message and digital signature. If the
computed signature matches the digital signature, the message is
legitimate and hasn’t changed since signing.
MCMC
performed a survey in 2019 (MCMC, 2021), which revealed an
upward trend in the use of digital signatures among users in
Malaysia. According to the survey findings, a significant
proportion of firms in Malaysia, specifically 63 per cent,
employ digital signatures as a means of conducting their
transactions. Similarly, a substantial majority of government
organisations, precisely 87 per cent, utilise digital signatures
for their internal procedures. The demand for digital
certificates has grown significantly, with 19,203,000 digital
certificates issued in 2023 as compared to 13,800,000 issued in
2019 (MCMC, 2023). Nevertheless, despite the considerable rate
of acceptance, there are certain difficulties that require
attention and resolution. A significant obstacle that arises is
the absence of interoperability between different CAs.
CA Interoperability
Cross-CA interoperability refers to the ability of different CAs
to recognise and accept each other’s digital certificates
(Brands, 2000) (Prasad & Kaushik, 2019). This is essential
for the seamless use of digital signatures across different
platforms and systems (Wazan et. al., 2013). In Malaysia,
cross-CA interoperability is still a challenge. Currently, there
are four (4) CAs in Malaysia that issue digital certificates.
However, they do not recognise each other’s certificates which
makes it difficult for users to use their digital certificates
across different platforms and systems.
CA interoperability challenges are the difficulties or barriers
that arise when different CAs try to exchange or validate
digital certificates across different domains, jurisdictions, or
standards. Interoperability challenges can affect the security,
trust, and efficiency of digital transactions that rely on
digital signatures and certificates (Prima & Sucahyo, 2011)
(Stegemann & Gersch, 2019). There are three (3) common
interoperability challenges identified in this study.
The first challenge is the lack of common standards or
frameworks for digital certificates and signatures. Different
CAs may use different formats, algorithms, or protocols for
issuing and verifying digital certificates and signatures. This
can create compatibility issues and increase the complexity and
cost of interoperability. Next is the lack of mutual recognition
or accreditation among CAs. Different CAs may have different
policies, procedures, or criteria for issuing and validating
digital certificates and signatures. This can create trust
issues and legal uncertainties among CAs and their users.
Lastly, lack of cross-border or cross-domain cooperation among
CAs. Different CAs may operate in different geographical or
functional domains, such as countries, regions, sectors, or
industries. This can create regulatory or technical challenges
for interoperability.
04 methodology
This research was systematically divided into two (2) distinct
phases, each tailored to the specific aims of the study. This
dichotomy allowed for a comprehensive approach to our
investigation and ensured a thorough exploration and analysis of
the subject matter. The first phase focused on qualitative
analysis through openended interviews that directly addressed
objectives 1 and 2. The second phase involved a systematic
literature review, targeting objectives 3 to 5.
Phase 1: Open-ended Interviews
In the first phase of the study, a qualitative approach was
utilised, specifically through open-ended interviews. This
method, widely recognised in qualitative research, facilitates a
deep and comprehensive understanding of specific topics (Moser
& Korstjens, 2018). The focus was on gathering data from
four (4) existing CAs, with an emphasis on selecting
representatives actively involved in the CA’s operations. These
representatives were chosen from both managerial and operational
levels, ensuring a varied and insightful perspective on the
issues at hand.
Research Design
The objective of this approach is to collect data from CAs by
carefully selecting individuals who are directly involved in
their operations. The selection of the representative will
encompass individuals holding managerial and operational
positions, thus facilitating the acquisition of diverse
perspectives on the issues at hand. In order to validate the
semi-structured interview’s content, the assessment made by
various experts from MCMC on different aspects of the interview
was considered. Next, the interview data is transcribed and
analysed utilising the software tool Atlas.ti. Atlas.ti
facilitates the analysis of interview material by organising it
thematically and generating summaries of the findings (Ronzani
et. al., 2020).
Research Instrument
The interview sessions with three (3) CAs have been conducted
via online and face-to-face interview sessions to gather the
“collective wisdom” and explore the similarities and divergences
across different CAs. There are 29 with 4 sections in the
semi-structure interview questions. Section A is the background
questions, where the experience of the participants on the topic
is mapped, as well as the general impressions about CA’s
operation.
In this section, the participants are
also asked to explain the process that they have gone through in
dealing with the digital signatures to bring the topic into
their minds before going deeper into the questions. Section B
consists of questions regarding CA’s capacity to handle higher
market demand for digital signatures and then Section C consists
of questions about the relationship between increased digital
signatures efficiency and interoperability against potentially
higher market demand. The last section which is Section D
consists of questions about CA’s interoperability issues and
challenges to answer RO4. The questions are focused on CAs’
opinions or suggestions on how to achieve interoperability
including technical challenges, possible solutions, and proposed
time frame for a full interoperability of the CA.
The
participants were provided with questionnaires in advance of the
interview session to facilitate their preparation for accurate
responses. The questions asked during the interviews reflected
the specific objectives of the study. An interview guide was
used to ensure that relevant questions were asked but not used
rigidly. Where appropriate, additional questions were asked that
were relevant to participants’ situations, especially when new
issues emerged during the interviews.
Sampling
Although there are four (4) CAs, only three (3) CAs participated
in the interview conducted. Table 1 shows a total of 15
participants from three (3) CAs was considered an appropriate
sample size to obtain diverse insights while remaining
manageable for detailed analysis. Participants were carefully
selected from management and operational positions within CAs to
ensure a diverse and representative sample. The selection
criteria included experience, decisionmaking capacity, and
direct involvement in CA operations to ensure a comprehensive
understanding of the subject matter.
Table 1: List of 15 Participants Involved in the Study
Data Collection
The interviews were conducted using two (2) methods:
face-to-face and online. To ensure a consistent approach across
both methods, specific strategies were employed. Verbal consent
for participation and audio-record the interview was obtained
during the interviews. The researchers emphasised maintaining
the anonymity of the participants and the confidentiality of the
study findings. Following the interviews, the data collected
underwent rigorous thematic analysis. This step was essential
for identifying and confirming the key themes relevant to the
study’s objectives.
Data Analysis
The interview transcripts, each with an average length of 60
minutes, were meticulously transcribed word-forword, adhering to
strict guidelines to ensure thorough accuracy. This detailed
transcription process included capturing non-verbal cues and
significant pauses, essential for maintaining the integrity of
the conversations. The analysis of this interview data was
conducted using the Atlas.ti software, which was particularly
effective for its thematic coding and organisational
capabilities. This software played a crucial role in dissecting
the intricate narratives, enabling the extraction of key themes
that closely aligned with the central research questions.
Triangulation methods were also employed, using multiple data
sources and methods to validate and corroborate the findings,
enhancing the study’s credibility.
Phase 2: Systematic Literature Review
In the second phase of the study, a systematic literature review
was conducted in order to answer our Research Objective 3, which
included a comprehensive search of multiple databases (journal
articles, international standards, guidelines, policies, and
frameworks) using targeted keywords with a focus on digital
signatures and CA interoperability. Strict inclusion and
exclusion criteria were applied to select only the most relevant
and highquality sources. The aim was to uncover and examine best
practices for improving the interoperability of digital
signatures in different countries in order to assess their
applicability and potential adoption in Malaysia.
Literature
resources in this report were collected from multiple digital
databases being actively used by researchers including Google
Scholar and Google search engine. Initially, 339 articles that
focused on digital signatures were retrieved from the search
engine. The articles were reduced to 57 articles that fall under
the category of CA interoperability.
The technique
used in the systematic literature review adopts the Preferred
Reporting Items for Systematic Reviews and Meta-Analysis
(PRISMA) (Moher et. al., 2009). The review methodology for this
work involves four (4) steps that consist of identification,
screening, eligibility, and inclusion as depicted in Figure
1.
Figure 1: Systematic Literature Review Analysis Flow Diagram
The basis of the identification process makes use of the
keywords searching strategy as shown in Table 2 to retrieve
articles from the database. Keyword searching strategy guides
researchers in searching for the main information used to
describe the research topic. Without the right keywords, it
might be difficult to find appropriate articles needed for the
literature. Using the keywords searching strategy, 339 articles
were retrieved.
Table 2: Keywords Searching Strategy
Next, the screening process identifies the suitability of
literature resources to be included in the survey based on the
article selection criteria listed in Table 3. With hundreds of
articles found in the database, it is crucial to select
significant resources that are useful to the researchers. The
type of article, language, and the domain of the article are
important criteria in selecting the articles. The criteria
specify the research requirements so that researchers will not
deviate from their research scope. These criteria will guide
researchers in structuring the output of the research from the
input obtained from the articles. During the screening process,
187 articles were filtered from the resources.
The
eligibility process retrieves the fulltext articles that have
been identified in the previous step. From the 187 identified
resources, 57 articles were successfully assessed and downloaded
that are used in the next stage of the systematic literature
review methodology.
Lastly, the inclusion process
gathers all of the assessed articles to be included in the
study. The systematic literature review methodology would help
researchers to conduct their research by finding accurate
resources. Without using this methodology, researchers may have
to read and review thousands of articles with no clear
direction.
Table 3: Article Inclusion and Exclusion Criteria
05 finding and analysis
To identify the capacity of the existing four (4) Certification
Authorities (CAs) to meet current and forecasted medium-term
demand
Based on analysis using Atlas.ti, the capacity of the CA to meet
current demand is shown in Figure 2. The overall results show
that the Certificate Authority (CA) to are currently equipped to
handle the current demand for digital certificates.
Infrastructure
which is the foundational element of the CA’s technological
backbone plays a crucial role in CA interoperability. A robust
and scalable infrastructure is vital for accommodating the
increasing demand for digital certificates efficiently. Adequate
hardware, network resources, and scalability ensure that the CA
can handle the evolving landscape of digital transactions
securely.
Figure 2: The Capacity of the CA to Meet Current Demand
From the analysis, the security measures and mechanisms
significantly enhance the CA’s capacity by prioritising the
integrity and reliability of its operations. A well implemented
PKI not only bolsters the overall security posture but also
directly influences the CA’s capacity by streamlining digital
certificate issuance and management processes. Concurrently,
security mechanisms like firewalls, intrusion detection systems,
and endpoint security reinforce the CA’s resilience, indirectly
impacting its capacity by mitigating potential disruptions from
security threats. This integrated approach ensures that the CA
operates with heightened security and efficiency, aligning its
capacity with the dynamic demands of the digital landscape.
On the other hand, human resources play a pivotal role in
determining the CA’s capacity. Skilled personnel are
indispensable for overseeing, monitoring, and administering the
CA’s operations effectively. The role of human resources extends
beyond operational support to encompass capacity planning,
ensuring that the CA is adequately staffed to meet increasing
demands while maintaining a high level of security. This
comprehensive strategy involves ongoing training and development
to keep the workforce abreast of evolving technologies and
security best practices, reinforcing the human element as a
critical factor in the CA’s capacity.
User adoption cost and regulatory support and policy form
additional considerations in the holistic approach to the CA’s
capacity. By streamlining user adoption processes, making them
cost-effective, and ensuring regulatory compliance, the CA can
collectively enhance its ability to meet current demand. An
efficient user adoption process can stimulate widespread
acceptance of digital certificates, potentially leading to
increased demand. Meanwhile, clear regulatory frameworks provide
a stable environment within which the CA operates, ensuring that
its capacity aligns with legal requirements and industry
standards. As CAs take this comprehensive approach, integrating
infrastructure, security, human resources, user adoption
strategies, and regulatory compliance, they navigate and
effectively address the multifaceted challenges of meeting
current demand.
While CAs exhibit varying levels of scalability and automation,
the majority are taking proactive measures to prepare for the
forecasted medium-term increase in demand. Adopting a holistic
approach that integrates infrastructure enhancement, process
optimisation, training, and collaboration, these CAs aim to
ensure the continued issuance of secure and reliable digital
certificates to meet the evolving needs of the digital
landscape. This strategic alignment positions CAs to effectively
address the multifaceted challenges associated with meeting
current demand.
To establish the relationship between increased digital
signature efficiency and interoperability against potentially
higher market demand and adoption of digital signatures
From the analysis, it is expected that the increased in digital
efficiency and interoperability lead to higher market demand.
The relationship between increased digital signature efficiency,
interoperability, and potential market demand and adoption of
digital signature is synergistic as shown in Figure 3.
Figure 3: The Relationship Between Increased Digital Signature
Efficiency and Interoperability Against Potentially Higher
Market Demand and Adoption of Digital Signature
It is also proven true that there is a consensus that digital
signatures significantly improve efficiency and productivity in
various tasks and workflows. They eliminate the need for
physical signing, printing, and scanning of documents, enabling
users to sign and approve documents from anywhere with an
internet connection (Earl & Kimport, 2011) (Gupta et. al.,
2004). Digital signatures also facilitate the enforcement of
standard operating procedures (SOPs) by allowing for predefined
signing sequences and timestamps, ensuring compliance with
regulations.
The analysis also shows there are
efforts to promote the adoption of digital signature technology,
such as workshops, roadshows, and awareness campaigns. There is
a focus on approaching targeted organisations and individuals to
demonstrate the benefits and use cases of digital signatures.
Trust in digital signature technology is crucial for its
adoption. The interviews mention various efforts to inform users
about the benefits and limitations of digital signatures. These
efforts include social media promotion, workshops, direct
pitches to organisations, and proof of concept demonstrations.
Compliance with international standards, such as WebTrust
certification, is highlighted as a way to ensure trust in
digital signature technology (Patton & Jøsang, 2004).
Digital signatures are perceived as highly useful and
productive, leading to increased efficiency in various tasks,
which can drive market demand and adoption. When the market
demand for digital transactions rises, efficient and
interoperable digital signatures become essential for meeting
user expectations, regulatory requirements, and seamless
integration with digital workflows.
Thus, the
relationship between increased digital signature efficiency and
interoperability is crucial for driving higher market demand and
adoption of digital signatures. Efficient digital signature
processes, coupled with interoperability between different
providers and platforms, can enhance user experiences and
productivity, ultimately leading to greater trust and adoption
of this technology. Efforts to promote digital signatures and
build trust among users play a pivotal role in driving adoption
within both government and private sectors.
To explore through literature review the best practices on how
interoperability has been promoted for Digital Signatures in
other countries for potential adoption for Malaysian CAs in
promoting digital signatures
Efforts to enhance CA interoperability are crucial for building
a secure and connected digital ecosystem. This becomes
particularly relevant as organisations and individuals
increasingly rely on digital signatures, secure email
communication, and other PKI-based services in their daily
operations (Paulus et. al., 2004). Standards organisations and
industry collaborations play a significant role in driving
interoperability initiatives within the PKI space.
This study analyses CA interoperability models to
identify the best model to be proposed to the government of
Malaysia. The risk analysis was done based on the CAs
interoperability models as shown in Table 4.
Table 4: Risk Analysis on CA Interoperability Models
From the risk analysis in Table 4, the best model can be
suggested for Malaysian CA interoperability is the Bridge model.
Choosing the Bridge CA model for CA interoperability in Malaysia
has several justifiable reasons. Firstly, this model involves
moderate costs, offering a balance between affordability and the
structured interoperability framework it provides. The medium to
high scalability of the Bridge CA model is beneficial for
accommodating a potentially large and growing ecosystem, which
is particularly important for a national CA infrastructure
(Wazan et. al., 2013). In terms of security, the Bridge CA model
carries moderate risks compared to a single root CA. In the
event of a breach, participants in the network can still operate
independently, minimising potential impacts (World Bank, 2007)
(Danquah & Kwabena-Adade, 2020). The structured trust model
of the Bridge CA simplifies the establishment of trust
relationships, contributing to predictability and reliability
within the interoperability framework.
Administratively,
the Bridge CA model is more manageable than a full mesh model,
making it easier to coordinate and enforce rules (Kakei et. al.
2020). The direct trust relationships inherent in this model
enhance simplicity and clarity in the interoperability
framework. Additionally, the Bridge CA model offers flexibility
in implementation, allowing Malaysia to customise its
interoperability framework based on specific technical and
regulatory requirements while maintaining a centralised point of
trust (Arseni et. al., 2021).
There is a clear trend
in the current CA interoperability discussions to move towards
the Bridge CA model as depicted in Appendix 2. The Bridge CA may
be sitting above the Root CA/Hierarchy, Cross-Certification
(Mesh), Cross Recognition, Certificate Trust List models, or
even a combination of all of these. It would appear that the
main advantage of Bridge CA is the provision of a stable third
party to coordinate and promote CA interoperability by whatever
means necessary.
In the absence of a Bridge CA,
interoperability may fall between the cracks. Individual
governments, accreditation agencies and CAs do not have
sufficient motivation, skills, or resources to deliver and
maintain interoperability (Yang et. al., 2019). In addition, the
creation of a bridge allows interoperability to be achieved
through staged testing and upgrades since perfect
interoperability does not need to be achieved at once (Ford et.
al., 2007).
The potential adoption of the Bridge CA
model emerges as a strategic necessity for the government of
Malaysia in bolstering its CA interoperability framework. The
identified advantages, such as providing stable third-party
coordination, promotion of interoperability through various
means, and the facilitation of staged testing and upgrades,
position the Bridge CA as a pivotal component in ensuring the
seamless integration of PKI-based services (Hardin et. al,
2015). The evolving landscape of digital transactions and
communications necessitates a robust and adaptive approach, and
the Bridge CA model aligns with the current trends in CA
interoperability discussions. By embracing this model, Malaysia
can not only address the potential pitfalls of interoperability
lapses but also promote a standardised and secure digital
ecosystem that aligns with global best practices.
To gather input and feedback from CAs on the interoperability
among the CAs.
Based on the findings of the interview with the CA, achieving
interoperability among CAs in Malaysia is seen as a complex but
possible goal. The CAs highlighted four (4) issues and
challenges they faced to achieved interoperability. Below are
details of the discussion for each identified challenges and
issues related to interoperability.
a. Lack of Standardisation in Software
Despite the existence of a standard format like X.509, subtle
deviations in implementation can impede seamless communication
between different digital signature systems. Standardising
certificate formats becomes imperative to ensure a consistent
and universally accepted structure, facilitating smoother
interoperability. The absence of standardised software
implementations across different vendors contributes to
interoperability challenges (Jardim-Goncalves et. al., 2006). As
CAs employ their own proprietary software for digital
signatures, disparities in implementation may arise, leading to
compatibility issues. Addressing this challenge involves
advocating for standardised software practices within the
industry to enhance the coherence of digital signature systems.
The result in this study highlights the importance of
standardising software to alleviate interoperability issues.
b. Security Issues
Security and privacy issues arise when different systems
interoperate, increasing potential risks. Companies may
implement varying security measures based on their specific
needs and requirements. This can result in inconsistencies
across the organisation, making maintaining a uniform level of
protection challenging. In addition, integrating the systems or
applications for interoperability purposes can be complex when
they have different security protocols (Kouroubali &
Katehakis, 2019). Incompatibility between security measures may
create vulnerabilities or points of weakness that attackers can
exploit. The variations in authentication techniques might
influence the overall usability and accessibility of the
system.
c. Business Considerations
Interoperability may face resistance from CAs if perceived as
conflicting with their business interests. The interviews
underscore the importance of assessing the business implications
of interoperability. CAs may question the benefits and alignment
with their overarching business strategies, emphasising the need
for a delicate balance between technological advancements and
business considerations. Business considerations affecting
interoperability has intersection between technology and
business strategy (Agostinho et. al., 2016). It is suggested
that a nuanced evaluation of the benefits and alignment with
overarching business strategies is crucial for CAs facing
interoperability decisions. Therefore, this study proposes that
evaluating the perceived benefits and alignment with business
strategies is crucial.
d. Business Operation
The issue of the integrity and security of business operations
is of paramount importance. The continuity of business
operations will be disrupted because of technological obstacles
associated with interoperability (Nepelski, 2019). These
challenges mostly pertain to the compatibility concerns arising
from digital signature formats and certificate management,
particularly in modifying signed documents. This issue is also
interconnected with Business Considerations. The possible impact
on the company encompasses various variables, including the loss
of control and heightened competition.
To provide recommendations on the best practices, standards
adoption, and/or policy or legislative approaches for increasing
digital signature efficiency, interoperability, and market
demand
The Malaysia acts that specify electronic and digital signatures
are highlighted in three (3) documents. Firstly, the DSA 1997
that focuses on the legal recognition of digital signatures and
their use in electronic transactions (Kadir, 2012). The act also
provides legal recognition to digital signatures and digital
certificates. In addition, it establishes the regulatory
framework for CAs.
Secondly, the DSR 1998 which is a
set of rules made under the DSA 1997. The regulations cover
various aspects of licensing, certification, and auditing of
digital signature authorities and repositories in Malaysia
(Government of Malaysia, 1998). The regulations also specify the
approved digital signature schemes and the requirements for key
management and storage.
The Electronic Commerce Act
2006 on the other hand addresses various aspects of electronic
commerce, including electronic contracts and the liability of
network service providers (Government of Malaysia, 2006). The
act recognises electronic messages and electronic contracts, as
well as addresses the liability of network service providers for
third-party content.
This study analyses the
governing legislation of ASEAN countries to observe Malaysian
acts against other international best practices and standards.
In order to maintain the relevance and effectiveness of the
above acts, it is crucial to recommend improvement. There are
eight (8) recommendations for improvement as shown in Table
5.
Table 4: Risk Analysis on CA Interoperability Models
The DSA 1997, DSR 1998, and the Electronic Commerce Act 2006
have played pivotal roles in shaping Malaysia’s approach to
electronic transactions. However, recognising the constant
evolution of technology, it becomes imperative to proactively
recommend enhancements to these acts. The eight (8) identified
recommendations, ranging from bolstering cybersecurity measures
to fostering innovation, collectively form a roadmap for the
necessary modernisation of these long-standing legislations. By
embracing these improvements, Malaysia not only aligns itself
with international standards but also ensures the continued
trust and efficiency of electronic transactions within its
borders.
06 recommendations
Based on the findings of this study, a Certification Authority
Interoperability Framework in Figure 4 is recommended to MCMC to
bolster CA interoperability in Malaysia and ensure a robust and
secure digital infrastructure to be adopted at the national
level. This CA interoperability framework design is critical to
enhance the seamless functioning of digital security
infrastructures.
Figure 4: A Proposed Certification Authority Interoperability
Framework
The proposed Certification Authority Interoperability Framework
presents a comprehensive structure with key components that are
instrumental in fostering effective CA interoperability. To
fortify this framework, it is recommended to prioritise the PKI
Trust Model across all components. This alignment with industry
standards ensures a consistent and secure foundation for
interoperability, fostering trust in the digital environment. A
key focus should be on establishing a robust infrastructure and
security measures as foundational elements. Encouraging CA to
adopt state-ofthe-art security measures is essential to
facilitate seamless interoperability without compromising data
integrity and confidentiality (Lampathaki, 2011). Additionally,
standardising protocols within the framework is crucial,
ensuring that PKI applications adhere to common technical
standards. This standardisation simplifies communication and
data exchange between different CAs and PKI applications,
promoting a cohesive and interoperable digital landscape.
In
the next layer of framework, lies human resources, which play a
pivotal role in the success of interoperable CA systems. To
address this, it is recommended to invest in capacity-building
initiatives for personnel involved in PKI management. Equipping
them with the necessary skills ensures efficient implementation
and maintenance of interoperable systems. Furthermore, a
user-centric approach in the design of PKI applications is
paramount, prioritising user experience and accessibility to
encourage widespread adoption and utilisation by individuals and
organisations (Perlman & Kaufman, 2008).
In
conjunction, aligning the framework with government regulations
and laws is vital as the pillar underpinning the other
components. Collaboration with regulatory bodies ensures that
policies governing PKI and CA operations are updated to
accommodate interoperability requirements, fostering a
regulatory environment conducive to secure and standardised
digital transactions (Basu, 2004) (Tai & Ou, 2003).
Simultaneously, education and promotion initiatives are
recommended to raise awareness about the benefits of
interoperable CAs and PKI systems. Engaging stakeholders through
campaigns and training programmes contributes to building
understanding and trust in the security and reliability of
interoperable digital signatures.
Collectively,
these recommendations fortify the proposed Certification
Authority Interoperability Framework, positioning it to meet the
dynamic demands of a secure and interoperable digital ecosystem
in the ever-evolving landscape of cybersecurity and
technological advancements.
07 conclusion
In conclusion, this study has provided valuable insights into
the dynamic landscape of digital signatures in Malaysia. The
findings underscore the growing importance of digital signatures
in various sectors, driven by the increasing reliance on digital
transactions and the need for secure and efficient
authentication processes. The Malaysian digital signature market
exhibits promising potential for growth, as businesses and
individuals recognise the benefits of enhanced security, reduced
paperwork, and streamlined processes.
Furthermore,
the examination of the feasibility of CA interoperability has
revealed crucial considerations for establishing a more
connected and interoperable digital signature infrastructure.
The interoperability of CAs is essential for fostering a
seamless and trustworthy digital environment, promoting
crossplatform compatibility, and ensuring the widespread
acceptance of digital signatures.
As the digital
landscape continues to evolve, the study highlights the
importance of collaboration among stakeholders, including
government bodies, businesses, and technology providers, to
establish standardised practices and promote interoperability.
The implementation of interoperable CAs can contribute
significantly to the growth and maturity of the Malaysian
digital signature market, fostering trust and confidence among
users.
The insights gained from this study provide a
foundation for future initiatives aimed at promoting the
widespread adoption of digital signatures in Malaysia. By
addressing the identified challenges and leveraging the
opportunities presented, stakeholders can collectively
contribute to the development of a robust and interoperable
digital signature ecosystem, ultimately shaping a more secure
and efficient digital future for Malaysia.
08 references
Kadir, R. (2012). Malaysian DSA 1997: A Review of Some
Unresolved Issues. Asian Social Science, 8(12), 221.
Chong, J. (1998). A primer on digital signatures and Malaysia’s
digital signatures act 1997. Computer Law & Security Review,
14(5), 322-333.
Afshar, R. (2015). Digital Certificates (Public Key
Infrastructure). Indiana State University, Terre Haute.
Kamaruzaman, K. N., Handrich, Y. M., & Sullivan, F. (2010).
E commerce adoption in Malaysia: Trends, issues and
opportunities. ICT strategic review, 11.
Albarqi, A., Alzaid, E., Ghamdi, F., Asiri, S. and Kar, J.
(2015) Public Key Infrastructure: A Survey. Journal of
Information Security, 6, 31-37.
Stallings, W. (2017). The Principles and Practice of
Cryptography and Network Security 7th Edition. Pearson
Education, 20(1), 7.
Singh, S. (2018). Public Key Infrastructure (PKI) and its
Applications. International Journal of Computer Sciences and
Engineering, 6(5), 1-5.
Republic of Indonesia. Electronic Information and Transactions
Law. (2008). https://www. icnl.org/wp
content/uploads/Indonesia_elec.pdf.
The Union of Myanmar. Electronic Transaction Law. (2004).
https://www. myanmartradeportal.gov.mm/ uploads/legals/2018/12/ Electronic%20Transactions%20Law%202004(English).pdf.
Government of Malaysia. Electronic Commerce Act. (2006).
https://aseanconsumer.org/
file/post_image/Act%20658%20-%20Electronic%20Commerce%20Act%202006.pdf.
Government of Malaysia. Digital Signature Act. (1997).
https://www.mcmc.gov.my/skmmgovmy/ media/General/pdf/Act-562.pdf.
Saripan, H., & Hamin, Z. (2011). The application of the
digital signature law in securing internet banking: Some
preliminary evidence from Malaysia. Procedia Computer Science,
3, 248-253.
Brands, S. (2000). Rethinking public key infrastructures and
digital certificates: building in privacy. Mit Press.
Prasad, A., & Kaushik, K. (2019). Digital signatures. In
Emerging security algorithms and techniques (pp. 249-272).
Taylor & Francis.
Wazan, A. S., Laborde, R., Barrere, F., Benzekri, A., &
Chadwick, D. W. (2013). PKI interoperability: Still an issue? A
solution in the X. 509 realm. In Information Assurance and
Security Education and Training: 8th IFIP WG 11.8 World
Conference on Information Security Education, WISE 8, Auckland,
New Zealand, July 8-10, 2013, Proceedings, WISE 7, Lucerne
Switzerland, June 9-10, 2011, and WISE 6, Bento Gonçalves, RS,
Brazil, July 27-31, 2009, Revised Selected Papers 8 (pp. 68-82).
Springer Berlin Heidelberg.
Prima, E., & Sucahyo, Y. G. (2011, December). Digital
certificate based security system for electronic government:
Case study of PKI implementation for securing electronic
government procurement in Indonesia. In Proc. IADIS
International Conference on Internet Technologies & Society
(ITS) 2011 (pp. 109-120).
Stegemann, L., & Gersch, M. (2019). Interoperability -
Technical or Economic Challenge?. it-Information Technology,
61(5-6), 243-252.
Moser, A., & Korstjens, I. (2018). Series: Practical
guidance to qualitative research. Part 3: Sampling, data
collection and analysis. European journal of general practice,
24(1), 9-18.
Ronzani, C. M., da Costa, P. R., da Silva, L. F., Pigola, A.,
& de Paiva, E. M. (2020). Qualitative methods of analysis:
an example of Atlas. TITM Software usage. Revista Gestão &
Tecnologia, 20(4), 284-311.
Moher David, Liberati Alessandro, Tetzlaff Jennifer, Altman
Douglas G., The PRISMA Group. 2009. Preferred Reporting Items
for Systematic Reviews and Meta-Analyses: The PRISMA Statement.
PLoS Med 6(7), 1–6.
Earl, J., & Kimport, K. Digitally enabled social change:
Activism in the internet age. Mit Press, (2011).
Gupta, A., Tung, Y. A., & Marsden, J. R. Digital signature:
use and modification to achieve success in next generational
e-business processes. Information & Management, 41(5),
561-575, (2004).
Patton, M. A., & Jøsang, A. Technologies for trust in
electronic commerce. Electronic Commerce Research, 4, 9-21,
(2004).
Paulus, S., Pohlmann, N., Reimer, H., Jeun, I., Lee, J., &
Park, S. (2004). Asia PKI Interoperability Guideline. In ISSE
2004 - Securing Electronic Business Processes: Highlights of the
Information Security Solutions Europe 2004 Conference (pp. 309
320). Springer.
World Bank (2007). e-Signature and PKI Frameworks: International
Benchmarks. Final Report.
https://documents1.worldbank.org/curated/ pt/438441468028444821/pdf/ 694710ESW0P10300000Inception0Report.pdf
Danquah, P., & Kwabena-Adade, H. (2020). Public Key
Infrastructure: An Enhanced Validation Framework. Journal of
Information Security, 11(4), 241-260.
Kakei, S., Shiraishi, Y., Mohri, M., Nakamura, T., Hashimoto,
M., & Saito, S. (2020). Cross-Certification Towards
Distributed Authentication Infrastructure: A Case of Hyperledger
Fabric. IEEE Access, 8, 135742-135757.
Arseni, Ș. C., Avram, D., Medvei, M., Togan, M., & Dima, A.
(2021). Securing the C-ITS: A PKI Perspective.
Yang, C., Chou, T. C., & Chen, Y. H. (2019). Bridging
digital boundary in healthcare systems—An interoperability
enactment perspective. Computer Standards & Interfaces, 62,
43-52.
Ford, T. C., Colombi, J. M., Graham, S. R., & Jacques, D. R.
(2007). A survey on interoperability measurement. Gateways, 2,
3.
Hardin, D., Stephan, E. G., Wang, W., Corbin, C. D., &
Widergren, S. E. (2015). Buildings interoperability landscape
(No. PNNL-25124). Pacific Northwest National Lab (PNNL),
Richland, WA (United States).
Jardim-Goncalves, R., Grilo, A., & Steiger-Garcao, A.
(2006). Challenging the interoperability between computers in
industry with MDA and SOA. Computers in industry, 57(8-9),
679-689.
Kouroubali, A., & Katehakis, D. G. (2019). The new European
interoperability framework as a facilitator of digital
transformation for citizen empowerment. Journal of biomedical
informatics, 94, 103166.
Agostinho, C., Ducq, Y., Zacharewicz, G., Sarraipa, J.,
Lampathaki, F., Poler, R., & Jardim- Goncalves, R. (2016).
Towards a sustainable interoperability in networked enterprise
information systems: Trends of knowledge and model-driven
technology. Computers in industry, 79, 64-76.
Nepelski, D. (2019). How to facilitate digital innovation in
Europe. Intereconomics, 54(1), 47-52.
Government of Malaysia. Digital Signature Regulations. (1998).
https://www.posdigicert.com.my/public/uploads/files/ Digital_Signature_Regulations_1998.pdf.
Lampathaki, F., Tsiakaliaris, C., Stasis, A., &
Charalabidis, Y. (2011). National interoperability frameworks:
The way forward. In Interoperability in digital public services
and administration: Bridging e-government and e business (pp.
1-24). IGI Global.
Perlman, R., & Kaufman, C. (2008, March). User-centric PKI.
In Proceedings of the 7th Symposium on Identity and Trust on the
Internet (pp. 59-71).
Basu, S. (2004). E‐government and developing countries: an
overview. International Review of Law, Computers &
Technology, 18(1), 109-132
Tai, G. C., & Ou, C. M. (2003, October). The development of
PKI interoperability in Taiwan. In IEEE 37th Annual 2003
International Carnahan Conference on Security Technology, 2003.
Proceedings. (pp. 405-409). IEEE.
09 appendix
up next:
Digital Healthcare Adoption by Malaysian Senior Citizens: Its
Challenges, Needs, and Future Action
by Ts. Dr. Chang Jing Jing, Dr. Seow Ai Na, Dr.
Nurul Afidah binti Mohamad Yusof, Dr. Abdullah
Sallehhuddin bin Abdullah Salim, Dr. Syarah Syahira binti
Mohd Yusoff and Dr. Nani Draman