CONTENTS

  • 2 DIP Interfaces
    • 2.1 DIP landscape
    • 2.2 DIP Core Services
      • The Admin Portal is the DIP Manager’s means of administering the DIP, the user portal is for DIP Users
    • 2.3 DIP Connections
    • 2.4 DIP Users
      • 2.4.1 There are primarily three different types of DIP Users:
    • 2.5 Active Market Participant
    • 2.6 Non-active Market Participant
  • 3 DIP Access and participant engagement
    • 3.1 The DIP Portal
    • 3.2 Registration
    • 3.3 PKI Role Governance
    • 3.4 Interfacing with the DIP
  • 4 Public Key Infrastructure
    • 4.1 Overview
    • 4.2 DIP Certificate Authority
    • 4.3 Chain of trust
    • 4.4 Digital Certificate usage
      • complex image of process
      • Digital Certificate Path
    • 4.5 Key management
    • 4.6 Digital Certificate Revocation
  • 5 DIP Security Requirements
    • 5.1 Security requirements
      • The security requirements in the DIP Rules are based on National Cyber Security Centre Cyber Assessment Framework (NCSC CAF) recommendations that organisations adopt a recognised baseline of security controls such as those prescribed in ISO 27001 (or equivalent, e.g., NIST 800- 53), supplemented with a set of enhanced level controls on which DIP Users are reliant to protect the DIP Ecosystem.
    • 5.2 Information Security Management System certification
      • The DIP Manager is responsible for ensuring the DIP is certified against ISO 27001. Certification shall be provided by a UKAS-certified auditing body.
      • DIP Users shall carry out regular risk assessments of their systems and interfaces. Details of how to conduct risk assessments can be found in well-established assessment models, such as ISO 27005 or HMG’s Information Assurance Standards 1 & 2.
    • 5.3 TLS requirements and configuration
    • 5.4 TLS key generation and Certificate Signature Requests
  • 6 Managing Digital Certificates
    • 6.1 DIP Users responsibilities
    • 6.2 DNS Domain creation/verification
    • 6.3 DIP Digital Certificate requirements
    • 6.4 Certificate Subscriber obligations
    • 6.5 Relying Party Obligations
    • 6.6 Certificate Revocation Request
    • 6.7 Digital Certificate renewal
    • 6.8 Private Keys
    • 6.9 Encryption Secrets/Password Guidance
  • 7 DIP Messaging
    • 7.1 DIP Message pattern
    • 7.2 Message Architecture
      • complex image of process
    • 7.3 DIP IDs
    • 7.4 Message/event channels
    • 7.5 MPAN Address Maintenance Service
    • 7.6 Message structure
      • complex image of process
    • 7.7 Message routing
    • 7.8 Message/event obfuscation
    • 7.9 Message Compression Handling
    • 7.10 Message De-compression Handling
    • 7.11 Message configuration requirements
    • 7.12 Message Egress
    • 7.13 Message Ingress
    • 7.14 Capacity Management
    • 7.15 Message Security
    • 7.16 Message Alarms
  • 8 Message choreography
    • 8.1 Message choreography
    • 8.2 Simple Message Exchange
    • 8.3 Level 1 validation - DIP Synchronous rejection
    • 8.4 Level 2 validation – DIP asynchronous rejection
    • 8.5 Level 3 response - Recipient Synchronous Error (with retry)
    • 8.6 Level 3 validation - Recipient Synchronous Response (no-retry)
    • 8.7 Level 4 validation - Recipient validation response (asynchronous)
    • 8.8 Consumption Replay
    • 8.9 Recipient timeout and ‘Dead-Letter Queue’ handling
    • 8.10 Error Handling & Message Distribution Patterns
    • 8.11 Batch Message Handling
    • 8.12 Workflow message handling
  • 9 Use of APIs and Webhooks
    • 9.1 Send Messages API
    • 9.2 Send message DIP Processing (Level 1 Validation)
    • 9.3 Receive Message Webhooks
    • 9.4 Receive Message Call back Request structure
    • 9.5 Recipient responsibilities
    • 9.6 Replay events
    • 9.7 Message return codes and response body
    • 9.8 DIP API Actions
    • 9.9 API Version Control
    • 9.10 Message channel versioning
    • 9.11 Multi-version support – API and message channels
    • 9.12 API Keys
    • 9.13 API Key rotation
    • 9.14 API Key(s) and DCPs
  • 10 Signatures
    • 10.1 Digital signatures
    • 10.2 Digital signature formats
    • 10.3 Message signing
    • 10.4 Verifying signatures
    • 10.5 Signature key generation and Certificate Signing Requests
  • 11 DIP capabilities
    • 11.1 Number of channels and DIP Users
    • 11.2 Transactional volumes
    • 11.3 Message Latency
    • 11.4 System availability
  • Amendment Record

DSD002 Annex 2 - Detailed DIP Operational Requirements V1.0

Effective From Date:01/10/2024
Status:SUPERSEDED
Other versions
Download