Network Security and Encryption in Public and Extrajudicial Services

May 18, 20265 min read
"Security""Cryptography""VPN""Networks"

Notary services and extrajudicial registry offices deal daily with national security information, property records, and highly sensitive civil data. The traffic of this information between local registries, state registry centers, and federal agencies must be shielded against active or passive interception.

In this article, I discuss the implementation of secure virtual private networks (VPNs) using IPsec and strict symmetric and asymmetric encryption policies to ensure absolute integrity.

Secure Network Topology

To protect the transmission of digital notary deeds, we designed connections based on: Site-to-Site IPsec VPN Tunnels: Channel encryption using the latest algorithms (AES-256-GCM / SHA-256). Dedicated Next-Generation Firewalls (NGFW): Strict IDS/IPS (Intrusion Detection and Prevention) policies to mitigate lateral movement attempts. * Physical Segmentation: Isolation of public service networks from the rest of internal traffic and databases containing signature and deed records.

Encryption and Digital Signature

For compliance with ICP-Brasil and the LGPD (General Data Protection Law): 1. Digital Certificates (A3 / HSM): All transactional communication is signed using high-density RSA cryptographic keys residing on dedicated hardware. 2. Encryption at Origin (TLS 1.3): Locally encrypting file traffic before transmission, preventing leaks in the event of accidental failure of transit VPNs.

Check the tunnel, not only the drawing

A topology slide does not prove TLS 1.3 or the IPsec tunnel. These do.

openssl s_client -connect registry.example:443 -tls1_3 </dev/null 2>/dev/null \
  | openssl x509 -noout -subject -dates

The site-to-site tunnel, in strongSwan, stays limited to the registry subnets. AES-256-GCM and IKEv2, no legacy cipher.

conn registry-central
  keyexchange=ikev2
  esp=aes256gcm16-sha256
  leftsubnet=10.20.0.0/24
  rightsubnet=10.30.0.0/24

ipsec status has to show the CHILD_SA up before any batch of registry records crosses the link.


Key Lesson

Security in public services is not a static product, but rather a perpetual cycle of audits, vulnerability scans, and continuous human awareness.

Related Articles