Trusted Delivery – trusted data exchange infrastructure for electronic transactions in Vietnam

Publish date:

Trusted Delivery – trusted data exchange infrastructure for electronic transactions in Vietnam
Trusted Delivery for Digital Vietnam

As electronic transactions become the default, the question is no longer just “was it sent?” — but “who sent it, who received it, is the content intact, when did it happen, and is the evidence sufficiently verifiable?” Trusted Delivery transforms the process of sending and receiving digital documents into an evidence chain with identity, digital signatures, timestamps, audit logs, and interoperability across eDelivery systems.

Deployment Architecture: from user portal to evidence and AS4

A modern Trusted Delivery platform should combine user experience, API gateway, identity management, microservices, event streaming, per-service databases, object storage, evidence services, and an AS4/eDelivery gateway.

Reference Architecture Layers

Access Channel Layer
Sender portal, recipient portal, administration portal, API for enterprise systems, mobile applications, and notification integrations.
Security & API Gateway
WSO2 API Manager for API publishing, rate limiting, and policy enforcement; Keycloak for OIDC, roles, scopes, and identity claims.
Trusted Delivery Core
Microservices: request intake, message registration, delivery orchestration, evidence/TCE, trusted directory, notification, audit, and reporting.
Event Backbone
Kafka handles events such as send request accepted, delivery created, evidence generated, AS4 receipt received, and audit event recorded.
Trust & Interoperability
DSS/HSM/TSA for digital signing and timestamping; Domibus or compatible AS4 gateway for eDelivery exchange between systems.
Data & Operations
MariaDB following a per-microservice database model, object storage for payload/evidence data, OpenTelemetry, SIEM, retention policies, and legal hold management.

When should AS4/eDelivery be used?

When the sender and recipient are on the same platform, the system can handle the exchange via a user portal or internal API. When two independent eDelivery systems are involved in the same scenario, AS4/eDelivery serves as the standard communication layer between access points.

Same Platform

User Portal or Internal API

The sender uses the Sender Portal; the recipient uses the Recipient Portal. Evidence is generated within the same trust domain.

Cross-Provider Interoperability

AS4 Access Point

Provider A sends an ERD Dispatch to Provider B via AS4/ebMS3/SOAP/WS-Security. Receipts and evidence are returned to update the delivery status.

Routing

Trusted Directory and PMode

The system looks up participant, endpoint, certificate, capability, and PMode before sending via Domibus or a compatible AS4 gateway.

Real-World Applications in Vietnam

Trusted Delivery is suitable for transactions that require proof of sending, receipt, time of occurrence, content integrity, and accountability of the parties involved — particularly in digital government, finance, insurance, healthcare, education, and large enterprises.

Government Agencies and Public Services

Sending decisions, file-processing notifications, appointment letters, outcome of administrative procedures, or requests for additional documents to citizens and businesses.

  • Proof of notification delivered.
  • Reduced reliance on paper and postal services.
  • Cross-agency data interoperability.

Banking, Insurance, and Finance

Sending contract notifications, terms-and-conditions updates, confirmation requests, debt reminders, insurance dossiers, or important transaction documents.

  • Reduced “not received” disputes.
  • Clear audit trail for compliance purposes.
  • Integration with eKYC, digital signatures, and evidence packages.

Enterprises and Human Resources

Sending employment contracts, decisions, disciplinary notices, termination notifications, addenda, or internal regulations to employees.

  • Recipient acceptance or rejection recorded.
  • Handover evidence preserved.
  • Archived as part of the employee record.

Cross-Provider Certification Service Interoperability

ERDS/eDelivery providers can exchange messages via AS4, using a trusted directory for routing, endpoint authentication, and receipt generation.

  • Four-corner model.
  • AS4 send and receive.
  • Provider capability lookup.
5+evidence types
24/7traceability
AS4standard interoperability
10Y+long-term archival ready

Proposed Implementation Roadmap

Trusted Delivery should not be deployed as an email-sending module. It is a trust platform that must begin with policy, identity, evidence, security, operations, and verifiability.

Define Trust Policy

Identify message types, identity assurance levels, retention groups, evidence types, notification channels, and operational responsibilities.

Build the Trusted Delivery Core

Deploy microservices for request intake, message registration, delivery orchestration, evidence, notifications, audit, and reporting.

Integrate Identity, Digital Signing, and Timestamping

Connect Keycloak, WSO2, HSM/DSS/TSA, object storage, and MariaDB to ensure identity assurance, policy enforcement, and integrity evidence.

Enable AS4 Interoperability

Configure trusted directory, AS4 endpoints, certificates, PMode, and Domibus/AS4 Access Point for cross-provider delivery exchange.

Operate with Compliance Evidence

Set up dashboards, correlation ID tracing, legal record retention, backup/disaster recovery, evidence package export, and incident response procedures.

Trusted Delivery is the next step in digital trust

Digital signatures prove who signed. Trusted Delivery proves how a message was sent, made available, received, rejected, handed over, or expired. When these two capabilities are combined, organisations can operate electronic transactions at a significantly higher level of trust than email or a conventional information portal.

View References

References

Official sources and reference documents used to guide the content of this blog page.

  1. Government Electronic Information Portal, Law No. 20/2023/QH15 — Electronic Transaction Law: https://vanban.chinhphu.vn/?docid=208421&pageid=27160
  2. Government Electronic Information Portal, Decree No. 48/2024/ND-CP amending Decree 130/2018/ND-CP on digital signatures and digital signature certification services: https://chinhphu.vn/?docid=210212&pageid=27160
  3. Government Electronic Information Portal, Consolidated Document 06/VBHN-BTTTT on digital signatures and digital signature certification services: https://chinhphu.vn/?classid=0&docid=210792&pageid=27160
  4. Government Electronic Information Portal, Decree No. 194/2025/ND-CP on national databases, connectivity and data sharing, and open data for electronic transactions of state agencies: https://chinhphu.vn/?docid=214448&pageid=27160
  5. Mobile-ID website and blog — reference materials on digital trust, PKI, digital signing, and government digital transformation.

Community Discussion

Comments

Related Posts

Trusted IoT Connectivity & Tracking - a trusted IoT architecture for logistics, cold chain, and enterprise operations

Trusted IoT Connectivity & Tracking – a trusted IoT architecture for logistics, cold chain, and enterprise operations

Technical Blog v2 | In-depth Technical Style | Mobile-ID-standard Layout When logistics, cold-chain and container tracking enter real operational environments, customer requirements go beyond “the device can send data.” What…

GoPaperless CLMIAM – an integrated agentic AI platform for enterprise agreement and workflow operations

GoPaperless CLM/IAM – an integrated agentic AI platform for enterprise agreement and workflow operations

Technical Perspective · Next-Generation GoPaperless GoPaperless can evolve from a document workflow and digital signing portal into a Trusted Enterprise Work Platform — managing the full lifecycle of records, contracts,…

Quantera AI WorkSphere – on-premise AI agents for secure enterprise productivity and workflow management

Quantera AI WorkSphere – on-premise AI agents for secure enterprise productivity and workflow management

On-premise agentic AI productivity appliance Quantera AI WorkSphere is a secure on-premise agentic AI appliance engineered for enterprises that require governed document ingestion, AI-assisted drafting, department-level agent workflows, read-only system…

Quantera Platform - decentralized digital identity and EUDI-standard digital signature

Quantera Platform – decentralized digital identity and EUDI-standard digital signature

Technical Blog • Quantera Platform Quantera is positioned as a Digital Trust Infrastructure platform for enterprises, governments, and digital service ecosystems: where users control their identity, issuing organisations provide verifiable…

Trusted PalmPay - a palm-based biometric payment platform for Vietnamese banks

Trusted PalmPay – a palm-based biometric payment platform for Vietnamese banks

Mobile-ID Perspective · Vietnam Market · Trusted PalmPay Trusted PalmPay: building bank-grade biometric payment infrastructure with Mobile-ID This article analyses Trusted PalmPay from a product and technical architecture perspective —…

Trusted Billing - automate the Entire Invoice, Payment and Reconciliation Lifecycle for Your Business

Trusted Billing – automate the Entire Invoice, Payment and Reconciliation Lifecycle for Your Business

Mobile-ID Trusted Billing Billing-as-a-Service • Open Banking • e-Invoice • Automated Reconciliation A unified platform for billing, fee collection, and reconciliation Trusted Billing is Mobile-ID’s SaaS billing platform that brings…

Quantum Safe Card Architecture on Java Card – from Secure Chip to Enterprise Application Integration

Quantum Safe Card Architecture on Java Card – from Secure Chip to Enterprise Application Integration

In-Depth Technical Analysis A technical deep-dive into building a post-quantum digital signing product on smart cards — focusing on the secure chip, applet model, APDU protocol, CSP/KSP and CryptoTokenKit layers…

GoPaperless evolves into CLMIAM—from a digital signing portal to a full agreement lifecycle management platform.

GoPaperless evolves into CLM/IAM—from a digital signing portal to a full agreement lifecycle management platform.

Agreement Lifecycle Platform Overview In many organizations, digital signatures only address the final “checkpoint” of a document. Greater value lies in controlling the entire journey of an agreement — from…

FacialSense – advanced facial authentication spoof detection aligned with ISOIEC 30107-3

FacialSense – advanced facial authentication spoof detection aligned with ISO/IEC 30107-3

Biometric Identity & Presence FacialSense is introduced as a biometric platform designed to support multiple real-world use cases, including attendance tracking, presence management, visitor management, education, healthcare, hospitality, and mobile…

Post-quantum remote signing for long-term digital trust

Post-quantum remote signing for long-term digital trust

Quantum-Safe Remote Signing Ecosystem Mobile-ID positions a Quantum-Safe Remote Signing ecosystem for contracts, digital dossiers, enterprise eSeals, and evidentiary records—designed for organizations that require legal validity, auditability, and long-term retention.…

This website uses cookies

By clicking "Accept all", you agree to the storing of cookies on your device to enhance site navigation, analyze site usage, and assist in our marketing efforts.

Custom cookie preferences

These cookies are required for the website to function properly. They do not collect data for advertising purposes and cannot be disabled, as this would break the site's basic functionality.

Always active

These cookies remember your choices and settings to provide a more personalized experience, such as your selected language, dark/light theme, font size, region, or other customizations.

These cookies help us understand how visitors interact with the site. All data is fully anonymized and used solely to improve site performance, loading speed, and content quality—no personal identification.

These cookies enable us to show you more relevant ads on our site and across other platforms. They anonymously track your browsing behavior and prevent the same ad from appearing repeatedly.