S/MIME email certificate, in compliance with FDA email security requirements

The U.S. Food and Drug Administration (FDA) requires partners to use digital certificates to secure communications when submitting or receiving electronic regulatory information.

01 Why does the FDA use digital certificates to secure communications?

In order to maintain data integrity, accuracy, and manage documents in an organized manner, FDA has set up an Electronic Submission Gateway (ESG) for electronic regulatory submissions from receiving agencies, for FDA and its partners to process various documents and submissions through industry standard protocols, FDA Requires the use of S/MIME certificates to manage and maintain the security of email communications and document submissions, securely submitting premarket and postmarket regulatory information for review. FDA ESG complies with Secure Hypertext Transfer Protocol (HTTP) messaging standards and uses digital certificates for secure communications to ensure that all regulatory actions and decisions are effectively documented.

Digital certificates ensure the private and secure submission of electronic documents. A digital certificate binds the owner's name to a pair of electronic keys (public and private) that can be used to encrypt and sign documents. The benefits of signing with a certificate are:

  • Messages cannot be tampered with. That is, data cannot be changed, added, or deleted without the sender's knowledge. Digital signatures of documents provide this assurance.
  • The parties sending the files are who they claim to be. Likewise, when these parties receive a document signed by the sender, they can tell from the document's digital signature that the source of the document is trusted.
  • The sending of the document by the party sending it is undeniable.
  • Parties that have received documents cannot easily claim that they did not receive them.

02 FDA requirements for digital certificates

The public key in the FDA certificate is used to encrypt the document for transmission, and FDA ESG uses the sender's public key to verify the digital signature of the received document, confirming that it is from the specified source. The FDA's requirements for certificates are summarized as follows:

  • Issue a certificate to the owner of the ESG account, the account name is the same as the name of the certificate owner, and the certificate must contain the full name or the correct email address used when registering the ESG account;
  • FDA ESG does not accept certificates with blank "Issuer" or "Subject" fields;
  • The certificate provided should be valid for at least one year from the date of submission to FDA ESG;
  • You can apply for a digital certificate from a third-party certificate authority on the FDA recommendation list;
  • The certificate used for ESG electronic submissions is at least a Class 1 secure email certificate.

03 WoSign provides S/MIME email certificates, in compliance with FDA email security requirements

For food and drug companies that need to complete FDA certification, WoSign CA provides the globally trusted S/MIME email certificate in the FDA recommended list .

WoSign S/MIME email certificate is a basic level (Class 1) email certificate trusted by the world. It follows the S/MIME secure email protocol, realizes email signature and encryption, and has the ability to verify the authenticity of the sending mailbox and protect email content Confidentiality and integrity functions to prevent email security risks such as email information leakage, content tampering, sender identity spoofing, and phishing emails.

Apply for an S/MIME email certificate from WoSign CA, and issue the certificate after verifying the identity of the applicant and the ownership of the mailbox, which meets the FDA email security requirements and helps food and drug companies submit electronic regulatory documents safely. The S/MIME email certificate provided by WoSign CA has the compatibility and versatility of global trust. The main features of the certificate are as follows:

  • The subject of the certificate shows the verified email address and issuer;
  • Supports mainstream S/MIME mail clients such as Outlook, and digital signatures are globally trusted;
  • Adopt RSA2048-bit, SHA256-bit high-strength encryption;
  • The certificate is valid for unlimited times.

Guess you like

Origin blog.csdn.net/lavin1614/article/details/130324600