development of Internet commerce. In the last several years, states have begun regulating electronic authentication with a variety of approaches. This patchwork of state laws has created conflicts and confusion in the marketplace. The industry needs uniform legislation which provides legal recognition of specific electronic authentication methods using digital signature and “hashing” function technology. A digital signature allows a secure message to be sent over a computer network, Actually, the digital signature is based on a complex mathematical formula allowing authorization, confidentiality and non-repudiation. The technical processes that compose a digital signature include public key encryption and a “hash” function.
Public key cryptography allows information encrypted by one key from a given pair only to be decrypted by the other key of the same pair. Users of this system maintain secrecy of their private key but make their public key freely available. In this way, the private key holder can send a message to anyone on the Internet, and, since her public key can decrypt the message, the recipient knows it must have come from the private key holder. Conversely, anyone sending a message with her public key knows that only the private key holder can read the encrypted text.
Seifert Systems Invests in Energy Efficiency to Strengthen Operations
For manufacturers, energy is more than just another operating expense. It plays a critical role…
Learn More
A “hash” function creates a number which represents a document’s electronic data. Changes to that document, however minor, result in a completely different hashing number.
This number is called the message digest. The digest, which is sent along with the message, allows the recipient to determine whether the document has been tampered with by comparing the sent digest with a digest created by the recipient using the same hashing software.
Public key cryptography requires that a certification authority attest to the identity of a person associated with a given public key. When the subscriber signs a record user her private key, a certificate issued by the certification authority is sent with the message. Maintaining the integrity of public key encryption requires two conditions: The subscriber’s private key must remain secure; and, the certificate authority must be a trusted third party to the transaction.
Because state laws differ in how “digital signatures” are defined, potential difficulties exist in achieving a uniform set of laws. For example, Utah law defines digital signature narrowly as “a transformation of a message using an asymmetric cryptosystem.” On the other hand, Rhode Island defines the term expansively as an “electronic identifier, created by computer, and intended by the party using it to have the same force and effect as the use of a manual signature.”
Efforts to establish uniform digital signature laws are now under way. The National Conference on Uniform State Laws recently finished its Uniform Electronic Transactions Act (UETA). UETA addresses the use and legal recognition of electronic records and electronic signatures, the effect of varying certain provisions by contract, admissibility in evidence and operation of electronic agents. The Act defines electronic signatures broadly which prevents it from becoming obsolete as cryptographic technology advances. However, UETA may be so general that little uniformity is achieved for the use of secure computer-based signatures. Moreover, it may take several years for UETA to be adopted by legislatures of each state.
As an alternative to uniform state legislation, Congress has considered federal legislation to provide recognition for electronic authentication. This development could realize national uniformity by the advantage of preempting conflicting state laws. Recent attempts to enact such legislation have been defeated by interest groups, however, as either “industry -centric,” creating overly bureaucratic certifying authorities or as premature.
As the transmission of private information and commercial transactions over the Internet increases rapidly, the need for security is critical. Digital signature technology is gaining as a substitute for traditional signatures by providing necessary verification and authenticity safeguards.
However, technology alone is insufficient for e-commerce to succeed. Commerce needs uniform rules and practices for computer-based transactions. Digital signatures are an important technology, but uniform rules are needed to govern their use.
Kevin J McNeely is an attorney a/ Partridge Snow & Hahn, LLP and may be reached for comment concerning technology law at kjm@psh.com,












