41
course, to the validity or value of the information in a document. Both
studies and common sense indicate, however, that the full potential of ecommerce will not develop until there is a sufficiently trusted means of
communicating and authenticating communications—of performing
functions similar to those of signatures. In an electronic environment,
the original of a message cannot be distinguished from a copy; there is
no handwritten signature; it is not on paper; and it can be manipulated or
altered without being easily discernable—indeed, it can be altered
without the direct intervention of a human. There is considerable scope
for fraud or error. The purpose of electronic signatures is to offer some
technical means by which the characteristics of a signature can be
duplicated in an electronic environment.
6.3.2
Depending on the importance of the document, electronic signatures
may be a necessary and inherent part of the communication under ecommerce or electronic transactions statutes. Phrases such as “secure
electronic signatures” may not only satisfy provisions relating to
signatures, but also with legislative language dealing with witnesses,
notarisation, and statements made under oath. They may also be used to
deal with requirements for “original” documents.
6.3.3
Cryptography can also provide technical solutions for protection of
intellectual property in digital form. For example, a digital signature in
conjunction with a verifiable time stamp can give authors some control
over their work by tying an electronic document to a particular issuer
and ensuring that it cannot be altered without detection. This technology
can also be used to ensure the integrity of electronic archives, an
increasingly important issue.
6.3.4
Virtually all OECD countries have some form of legislative or
regulatory framework in place to provide for the legal effect of
electronic signatures. While details differ, there is a consistent approach.
All are theoretically technology neutral, although in some cases where a
high degree of certainty was required, policies specified the use of
technology that was asymmetric cryptography-based.
6.3.5 Digital signatures are an important application of public key
cryptography, which must be considered in conjunction with policy
development on cryptography, discussed above.35 Other authentication
models are possible, including biometric devices, use of personal
identification numbers (PINS) or “passwords,” digitised versions of
35
Using cryptography for digital signatures should not be confused with the creation of
confidential messages, which may be limited in some circumstances (or using some
methodologies) for reasons of national security or defence. Digital signatures using
cryptography may be appended to non-encrypted messages.