Network Security and Encryption in Public and Extrajudicial Services
Notary services and extrajudicial registry offices deal daily with national security information, property records, and highly sensitive civil data. The traffic of this information between local registries, state registry centers, and federal agencies must be shielded against active or passive interception.
In this article, I discuss the implementation of secure virtual private networks (VPNs) using IPsec and strict symmetric and asymmetric encryption policies to ensure absolute integrity.
Secure Network Topology
To protect the transmission of digital notary deeds, we designed connections based on: Site-to-Site IPsec VPN Tunnels: Channel encryption using the latest algorithms (AES-256-GCM / SHA-256). Dedicated Next-Generation Firewalls (NGFW): Strict IDS/IPS (Intrusion Detection and Prevention) policies to mitigate lateral movement attempts. * Physical Segmentation: Isolation of public service networks from the rest of internal traffic and databases containing signature and deed records.Encryption and Digital Signature
For compliance with ICP-Brasil and the LGPD (General Data Protection Law): 1. Digital Certificates (A3 / HSM): All transactional communication is signed using high-density RSA cryptographic keys residing on dedicated hardware. 2. Encryption at Origin (TLS 1.3): Locally encrypting file traffic before transmission, preventing leaks in the event of accidental failure of transit VPNs.Check the tunnel, not only the drawing
A topology slide does not prove TLS 1.3 or the IPsec tunnel. These do.
openssl s_client -connect registry.example:443 -tls1_3 </dev/null 2>/dev/null \
| openssl x509 -noout -subject -dates
The site-to-site tunnel, in strongSwan, stays limited to the registry subnets. AES-256-GCM and IKEv2, no legacy cipher.
conn registry-central
keyexchange=ikev2
esp=aes256gcm16-sha256
leftsubnet=10.20.0.0/24
rightsubnet=10.30.0.0/24
ipsec status has to show the CHILD_SA up before any batch of registry records crosses the link.
Key Lesson
Security in public services is not a static product, but rather a perpetual cycle of audits, vulnerability scans, and continuous human awareness.Related Articles
Multi-cloud for Banks: Separating the Core, Data, and the Audit Trail
Multi-cloud architecture for banks: a locked region, a core isolated from the lab, and an audit trail nobody can delete. SCP, CloudTrail, and Object Lock commands.
SAP Business One with SAP HANA on AWS: Architecture and Day-to-Day Operations
How to run SAP Business One on SAP HANA on AWS: instance, data and log volumes, port 30015, and backup. Power BI reads the replica, not production HANA.