Asseco, in cooperation with partners and the Ministry of Digitization, supports the development of Polish cyber security
July 4, 2024

Cyber security certification system in Poland - this was the motto of a conference organized by the Ministry of Digitization and technology partners (Asseco, Samsung and Xtension). The meeting discussed how the cybersecurity certification process works and presented its practical aspects, including the biocertiX biometric signature, which is the first Common Criteria-certified solution of its kind in Poland.
In addition to the tremendous benefits to society, advancing digitization also brings numerous threats from cybercriminals. Hence the importance of building a nationwide security ecosystem. Both state bodies and technology companies are involved in the process. One of the measures taken is the ongoing work at the Ministry of Digitization on a draft law on a national cyber security certification system, which will complement the national cyber security system. The legislation will create a framework for issuing cybersecurity certificates recognized throughout the European Union.
Common Criteria - a standard for checking the security of technologies
Already, companies have the opportunity to obtain international Common Criteria certification. In Poland, it is issued by the NASK Certification Unit and confirms that the process of specification, implementation and use of a given solution has been thoroughly evaluated by an accredited auditing unit and received a positive result.
There is no other country in our region that has the ability to certify at such a level. This makes Poland a leader in this area. We are working to expand the current certification system to include more laboratories or certification bodies. I would like to thank all the entities that decided to go through the certification system first, Łukasz Wojewoda, Director of the Cyber Security Department at the Ministry of Digitization, said at the meeting.
Certified biometric signature
In May this year, NASK has certified the biocertiX biometric signature. It is a system for self-signing on a Samsung tablet with a stylus using Xtension software that records and encrypts biometric data. The trustworthiness of the process is ensured by Asseco's qualified trust services: an electronic seal and timestamp, and a hardware key escrow module that protects biometric data. This data is encrypted and associated with a specific signature. It can only be disclosed to a graphology expert by court decision.
Asseco is very active in the cyber security sector. Among other things, we are a provider of qualified trust services that are part of the national cyber security system, said Andrzej Dopierała, President of Asseco Data Systems. Together with our partners Samsung and Xtension, we tackled Common Criteria standards as part of the biocertiX project. This road was not an easy one, we all cut our way through. It was a challenging task, but the success only confirmed that our product provides the maximum level of security for the documents being written, he added.
From a user perspective
biocertiX collects unique biometric data of the signer, such as handwriting characteristics, the force of the stylus on the screen and the speed of the handwriting. Then, through appropriate cryptographic algorithms, it binds this information to the signed content.
From the user's perspective, using a biometric signature is the same as signing documents with a regular pen, but much more secure. In addition, it retains full legal and evidentiary force in the event of litigation, explained during the presentation of the solution Artur Miękina, Director for Business Development at Asseco Data Systems.
biocertiX is not the only Common Criteria-certified solution that Asseco was involved in developing. The company also received it for SimplySign's mobile electronic signature.
Technological partnerships
The meeting, held at the Ministry of Digitization on July 4, was attended by: Paweł Olszewki, Secretary of State, and Łukasz Wojewoda, Director of the Cyber Security Department, as well as Andrzej Dopierała, President of Asseco Data Systems; Conor Pierce, President of Samsung Electronics Polska; Marcin Sikorski, President of Xtension, and Artur Miękina, Director of Asseco Data Systems' Business Development Department. Cooperation between the public administration and the new technology sector is an essential element of an effective and secure digital transformation of the country. What is needed, therefore, is dialogue between these entities and the development of transparent regulations and standards to enable technological development.
For more information, visit: https://paperless.asseco.com/en/offer/biocertix