In business communication with our partners, customers, suppliers and employees, emails have become an indispensable part of our communication. Emails are electronic postcards that can be made readable by unauthorized third parties with comparatively little effort.
Our business relationships, our trust relationships with our employees, and our operational and business secrets are a high asset and must be protected through IT security measures.
Secure e-business processes are based on trustworthy identities in the form of digital certificates.
After careful examination, we have therefore chosen SwissSign as the leading provider of services for trustworthy digital identities. SwissSign is a company of the Swiss Post and offers digital certificates for servers and devices, for individuals, authorities and companies.
SwissSign certificates are already issued in over 50 countries. They are automatically recognized by all major operating systems, browsers and mobile devices, and are integrated into partner solutions.
SwissSign as a certification authority has been included in the EU/eIDAS „Trusted List“ and complies with the EU regulation on electronic identification and trust services for electronic transactions in the internal market (eIDAS).
How it works
With S/MIME, which stands for Secure/Multipurpose Internet Mail Extensions and is the world's established standard for email encryption, based on a hybrid cryptosystem, email communication can be secured relatively easily. All that is needed is a combination of a private and a public key with a certificate. Behind this is a mathematical procedure, or an asymmetric cryptosystem. This is also called the public/private key procedure. The certificate is used by a certification authority to prove a user's identity. An email can thus be signed, encrypted, or signed and encrypted. We primarily use signing.
Signing
By signing via S/MIME, the recipient can be sure that the email actually originates from the sender and that the message has not been manipulated during transmission. A signature generally consists of the sender's certificate including the certificate chain, the signature algorithm, and the encrypted hash value. The hash value represents the content of the email with a unique character string, generated by an algorithm. The email continues to be in plain text, which has the advantage that email programs without S/MIME support can still display the emails. They display the email as usual, with the signature file in p7s format as an attachment. Signed emails are automatically verified by the email application and marked with an icon accordingly (outlined in blue in the image). Clicking the icon displays further details.
If communication partners also sign their emails with S/MIME, these emails will in future, after automatic exchange of certificates, be automatically signed and encrypted.