Showing posts with label Security. Show all posts
Showing posts with label Security. Show all posts

2007/12/05

HIPAA Electronic Signatures

Introduction to HIPAA Electronic Signatures

An electronic signature under HIPAA means the attribute affixed to an electronic document to bind it to a particular party. HIPAA electronic signature secures the user authentication (proof of claimed identity) at the time the signature is generated; creates the logical manifestation of signature (including the possibility for multiple parties to sign a document and have the order of application recognized and proven); supplies additional information such as time stamp and signature purpose specific to that user; and ensures the integrity of the signed document to enable transportability of data, interoperability, independent verifiability, and continuity of signature capability. Verifying HIPAA electronic signature on a document verifies the integrity of the document and associated attributes and verifies the identity of the signer.

Requirements to HIPAA Electronic Signatures

Electronic signature. If electronic signature is employed, the following three implementation features must be implemented: Message integrity, Non-repudiation, User authentication. Other implementation features of HIPAA electronic signature are optional. No specific technology is mandated by HIPAA, and it also appears to be technology neutral.

HIPAA Electronic Signatures Implementation

Ability to add attributes.
Continuity of signature capability.
Counter signatures.
Independent verifiability.
Interoperability.
Message integrity.
Multiple Signatures.
Non-repudiation.
Transportability.
User authentication.

Infopath Digital Signature

Briefly about digital signatures

You can enable digital signatures when designing a form so that users can add digital signature when filling it out. This digital signature proves that the form originated from the signer and has not been changed. Also the signature can include some comments from the author. After signing, the data in the form cannot be changed without cancellation digital signature.

When adding a digital signature, the user must use a digital certificate. Digital certificate is an attachment for a file, macro project, or e-mail message that assures authenticity, provides secure encryption, or supplies a verifiable signature. Digital certificates, which you can get through commercial certification authorities or from your internal security administrator, establish the authenticity of the signature.

About InfoPath digital signatures

In addition to enabling digital signatures so that users can sign your form, you can add a digital signature to your form template which authenticates you as the author of the form template in the same way that a digital signature on a form authenticates the user who filled out the form. Form template in InfoPath is a file or set of files that defines the data structure, appearance, and behavior of a form. For example, form templates that have been distributed to users in an e-mail message can be updated more effectively if they have been supplied with a digital signature.
When you put a digital signature in a form, InfoPath uses only those certificates that have a private key and a Digital Signature or Both value for the Key Usage attribute. Also the purpose of the certificate must be set as Client Authentication or Code Signing. If you are using a certificate to add digital signature to a form template, the certificate must be set as Code Signing. These limitations are applied because InfoPath uses XML Signatures to digitally sign forms.
  • Because a digital certificate you create is not issued by a formal certification authority, forms signed using a certificate you created are referred to as self-signed forms. These certificates are considered unauthenticated and will generate a security warning if the form's security level is set to Domain. InfoPath trusts self-signed certificates only on computers that have access to the private key for that certificate. In most cases, this means that InfoPath trusts self-signed certificates only on the computer that created the certificate, unless the private key is shared with other computers.
  • The information in this topic may not apply if you are working with a form designed using Microsoft Office InfoPath 2003 without the service pack installed.

Legal Digital Signatures

Digital signatures (unlike electronic signatures) are more often used as a method of showing affirmative purpose. The troubles with digital signatures do not ensue from agreement to terms, but rather from the security and confidentiality of the digital signatures. Virtually, digital signatures are encrypted electronic signatures that a third party (certification authorities) authenticates as original. Unlike the more general electronic signature, a digital signature must be unique and rigorously under the sole custody of the party using it. Unlike electronic signatures, where a typed name, a company name or even a logo can all bind the party to be charged by its mere presence, digital signatures offer the agreeing party greater levels of security and efficiency. The general types of signatures will not be enforceable as a digital signature. Because of the authentication requirements, digital signature should be recommended that clients rely on the use of digital signatures for any high-profile or high liability electronic contract.

Digital signature use will only increase in use in the future, as parties to all transactions will seek a heightened level of information security without the fear of accidentally agreeing to unfavorable terms. While there is an inherent fear of paperless transactions, especially with more traditional attorneys and companies, the use of digital signatures makes commerce faster, more secure and more effective and should be recommended to clients when appropriate. The use of digital signatures is even more effective when dealing in international trade, making it no longer necessary to fly overseas in order to demonstrate intent to sign a contract.

While understanding and diligent advising clients to the use of different forms of signatures for electronic commerce is significant, it is also very important to understand that we are still in the early years of a technological revolution, and that part of being an effective advocate is keeping up to date on advancements in the law. Electronic and digital signatures are only the beginning. Progress in technology will soon allow for the widespread use of biometric identification as a method of showing purpose of contract. Rules of contract law will continue to evolve with technology and while the application of contract principles and the Statute of Frauds will not substantially change, their interpretation and use surely will.

Read about Legal Electronic Signatures.

Legal Electronic Signatures

The Uniform Electronic Transactions Act (UETA) defines electronic signature as “an electronic sound, symbol, or process attached to or associated with, an electronic record and executed or adopted by a person with the intent to sign the record.” UETA, §2. Often referred to as ‘click-wrap’ agreements, these forms of electronic signatures are given a broad presumption of enforceability through acts such as UETA and the Electronic Signatures in Global and National Commerce Act (ESGNCA/ “E-Sign”). These acts make it clear that binding contracts may be created by the exchange of email or by simply clicking “yes” on those click-on licensing agreements that we have all accepted with all types of internet transactions. Like the UETA, the ESGNCA does require that consumers affirmatively consent to the click agreements and that the vendor must provide the consumer with a clear and conspicuous statement regarding the effect of agreeing to click, but parole evidence is rarely allowed in order to prove or disprove intent to contract. ESGNCA§101(c)1. By simply clicking “I agree” intent is presumed.

The widespread enforceability of electronic signatures is also recognized as completely valid for purposes of liability protection by the Digital Millennium Copyright Act. DMCA§512(3)(A)(i). As a relatively settled area of internet law, it is important to understand the enforceability of electronic signatures, whether or not intent is manifest from the face of the agreement itself. Since these click wrap agreements are presumptively enforceable, it is important to advise your clients regarding the potential pitfalls accepting terms of an online transaction without fully understanding what they are agreeing to. Simply accepting these terms may interfere with your client’s right to the judicial system for dispute resolution, as click-on arbitration clauses are also generally enforceable. Your clients will not be able to rely on the Statute of Frauds in order to demonstrate that there was no intent to contract. With electronic signatures, intent is an objective standard, generally determined by the simple click of a mouse.

Read about Legal Digital Signatures.

Legal Electronic and Digital Signatures

A copestone of United States contract law is the general application of the Statute of Frauds to contractual agreements. Emerging forms of electronic commerce and new types of contractual relationships have begun challenge the very idea of determining the four corners of a contract. Many difficulties regarding contractual relationships emerge with the rapid increase of electronic commerce, most notably determining what creates a valid signature. Traditionally, the Statute of Frauds is a collective term describing several statutory provisions that deny enforcement of certain forms of contracts unless they are reduced to writing and signed by the party to be charged. The question with this traditional idea of the Statute of Frauds is how it refers to electronic commerce in defining whether the party being charged with the contract has actually “signed” the contract for purposes of enforcement.

Different forms of legislation dealing with internet law have attempted to define and specify digital and electronic signatures for purposes of determining enforceability. Generally, there are two broad categories of signatures when dealing with electronic contracts.

1. Electronic Signatures (“E-Signatures”)
2. Digital Signatures

2007/11/29

Digital Signature for Office 2007

Microsoft Office 2007 provides many improvements in security in comparison with its predecessors. And one of new functions is possibility of digital signature of documents. Signing a document, you confirm that you are the creator of document, and it will prove that a document wasn't changed since you created its creation.

You can create a digital signature for a document because of the same amount of reasons, on which you can affix your signature to a paper document. A digital signature is used for identification of digital documents creator (such as ordinary document, e-mail and macros) by cryptographic algorithms.
Digital signatures are based on digital certificates. Digital certificates are verifiers of identity issued by a trusted third party, called a certification authority (or CA). This works similarly to the use of standard identity documents in the non-electronic world. For example, a trusted third party such as a government entity or employer issues identity documents such as driver’s licenses, passports and employee ID cards on which others rely to verify that a person is whom he/she claims to be.

Digital certificates can be issued by certification authorities within an organization, such as a Windows® Server 2003 server running Windows Certificate Services, or a public certification authority such as VeriSign or Thawte.

Microsoft 2007 Office system documents can have invisible signatures or signatures lines added to them. When used together with other Microsoft 2007 Office system security technologies and security technologies included in the Microsoft Office Servers and Windows operating system, digital signatures provide another significant component of a strong defense in depth approach to security data stored in Microsoft 2007 Office system documents, workbooks and presentations.

2007/11/24

Electronic Signatures Higher Security Levels

Electronic Signatures Higher Security Levels

1. Usage of electronic signature pads in a "stand alone" application. This does not meet the test of a legal signature, especially because it does not bind the electronic signature to the document. Such signature can be removed simply by selection and pressing the delete button.
2. Use of digital signature software that encrypts the electronic signature, usage of Public/Private Key Infrastructure electronic signature technology. This safeguards electronic signatures and allows for verification of the signature with the use of the same software. The signature is captured using an electronic signature pads and stored in a file that can only be opened with a password. The signature generally meets all legal requirements and cannot be removed from the document.
3. By using digital certificates a signature also can be verified as “authentic”, similar to a notary public witnessing a paper signature. However, unlike a notary public witnessing a paper signature, these legal witnesses have not been established for the electronic world. These can be used within organizations to establish identities.
4. A higher form of security is to sign each document using digital signature pads. An electronic signature pad allows for a person to sign the document on screen. Similar to a paper signature, this allows for handwriting analysis to verify the authenticity of the signature.
5. The highest form of security is with the use of biometrics using a fingerprint or retina scan, which will unlock a person’s signature.

Signatures Security

Signatures Security

There are various levels of security of paper documents. Mostly applications enable signing document without anyone attesting this act. But higher level of security requires participating of witnesses. The definitive level of security is to have your signature witnessed by a notary public.
Moreover, in the electronic world there are different levels of security for electronic signatures. An electronic signature is an image, commonly in "tiff" format, with no security features. It is easy to copy that image and past it into another document. This is a perilous form of electronic signatures that some people have accepted. This can be considered as level 0 form of security.
The higher levels of security of electronic signatures are described in Electronic Signatures Higher Security Levels article.

2007/11/02

Verisign Digital Signature

Digital Signatures became available as one of the AutoCAD extensions, part of the Autodesk Subscription program.

Verisign Digital Signature - How to Get

First of all, you need to get a digital signature. There are numerous certificate authorities that are happy to take your money and give you a digital signature -in fact, most of them offer a free trial option. Autodesk uses a company called Verisign as its digital-signature provider, but it isn't mandatory that you use them. The first time you launch the Digital Signature program, you will be sent to Verisign to get a digital signature (unless you already have one). There are different types of digital signatures depending on the level of security you need. If you want a digital signature that prompts for a password every time you use it, you'll have to pay more. You can even get a minimum-security signature on a 60-day trial basis for free, which I recommend until you decide you're completely sold on the digital-signature concept. When you're ready to make the commitment, you'll find you can get a digital signature for a year for $15.95. Digital signatures are stored in the REG file.

I found it very painful trying to move my digital signature from one computer to the next when I upgraded my laptop. I couldn't even buy another one because it was linked to my email address and Verisign kept telling me I already had a digital signature. After working with the Verisign customer service (and a few gray hairs later), I was finally able to figure out how to move it. Just a heads-up here!

Each digital signature ID is unique and is made up of a name, serial number, and an expiration date, along with other assorted information. Once you get your digital signature ID, AutoCAD will remember that long ID.

Verisign digital signature - How to attach in AutoCAD

After your digital signature is installed, you're ready to sign some documents. Simply execute the "Attach Digital Signature" command (external to AutoCAD), which is located in your Program menu under "Autodesk," and you'll see a dialog box displayed. We'll begin by selecting a couple of drawings we'd like to sign by picking the "Add files" button. There's even a simple Search mechanism included in the dialog, should you accidentally misplace your drawing files. After selecting the desired drawing files, you can time-stamp the signature by grabbing the time from the signing computer, or opt for an exact time from the time server of the National Institute of Standards and Technology, the U.S. Naval observatory, or Caltech University. Finish off your signature with any pertinent comments by inputting any appropriate text. When you're ready to make it official, select the Sign Files button. If all goes well you'll be prompted with the number of signed files. The status for these files will change in the dialog.

Verisign digital signature - How to attach in Outlook

  1. Go to https://digitalid.verisign.com/client/class1MS.htm in Internet Explorer.
  2. Fill in your first name, last name, email address and a simple memorable password (in the challenge phrase box)
  3. Select "I'd like to test drive a 60-day trial Digital Signature ID for free"
  4. Scroll down and accept, check the details and agree.
  5. When the email from Verisign comes in, copy the Digital PIN and click on the link.
  6. Paste the Digital PIN into the new webpage and click "INSTALL", again Agree/say yes to the boxes it presents.
  7. Open Outlook , go to Tools > Options > Security and tick the checkbox for "Add Digital Signature to outgoing messages"
  8. Click OK.