Skip to content
Annuaire
Sections
Technology

Recording Digital Content Part 2

Recording Digital Content Part 2
L’essentiel

This article explores identification methods for digital evidence, focusing on the security, authenticity, and legal requirements of electronic signatures and cryptographic authentication processes.

À retenir

This article explores identification methods for digital evidence, focusing on the security, authenticity, and legal requirements of electronic signatures and cryptographic authentication processes.

Means of identification

Numerous traces can be qualified as written evidence, regardless of the medium used and the methods of their transmission. However, the origin of this electronic exchange must be secured and guarantee its authenticity. This consists of being able to identify the signatory and having sufficient guarantees in terms of identification and authentication.

Identification and authentication

In principle, identification is carried out by means of a signature which must be assessed and analyzed with regard to electronic signature devices. Alongside the establishment of such devices, there are other means of identification such as identification by smart cards, used for mobile phones or bank cards, or even signature certificates for hardware and software media, which constitute a process that does not directly identify the person from whom the act emanates but the person to whom the act will be attributed.

An electronic signature based on public key cryptology, known as a digital signature, also guarantees identification and can serve as evidence. With the digital signature, the identification of the signatory corresponds to the name of the person registered in the certificate as a signatory linked to an asymmetric key pair.

However, the question arises as to what could happen if the person appearing on the certificate makes their code or password, as well as a means of access to the Internet, available to another person of their choice. In this scenario, the act would not emanate directly from the identified person, but from another Internet user who would have the activation code for the signatory’s private key. It would be quite difficult to know from whom the act emanates. Therefore, the use of biometric processes such as fingerprints or eye scans would be a better way to attest that it is indeed the signatory who activated the private key with the signature creation data (directive art. 2).

Technically, the authentication operation consists of verifying the origin of the message, which implies an identification of the sender-signatory guaranteed by an independent third party and which can be verified by the recipient.

The certification service provider does not authenticate the content of acts whose content, nature and names of recipients it does not know. It cannot grant a unique digital identity certificate. It certifies that the signature creation device is carried out under the control of the signatory. It has an important role in the electronic identification operation, but in no way guarantees the security of exchanges.

Securing and authenticity

The verification of the identity of individuals is carried out in principle based on four requirements:

  • the process chosen requires the signature to be linked solely to the signatory
  • that it allows them to be identified
  • that it be created by means that the signatory can keep under their exclusive control
  • and finally, that it be linked to the data to which it relates in such a way that any subsequent modification of the data is detectable.

Within the framework of digital identification processes, the issuance of identity is carried out by means of an electronic certificate issued by the certification service provider. Registration can take place directly and quickly, upon presentation of supporting documents. This certificate, which contains the subscriber’s public key, is attached to the message that the party intends to sign by means of their private key, but it can also be made available in a database containing the certificates issued by the certification service provider. Also, the recipient of the signed message or file must ensure that the certificate containing the public key corresponding to the private key used to sign is valid and has not been revoked. They will consult the certificate revocation list in a directory published and updated by the provider issuing the certificates. The recipient must then verify the signature that the provider has affixed to the certificate up to the root certification authority, which is at the top of the hierarchy. With this electronic signature process, the identification requirement is respected.

Traceability must also guarantee integrity. The writing must be provided and kept without any alteration having occurred from the expression of the will to adhere to the content of the act until the judge is certain of its content.

With new technologies, the legal system must rely on items of evidence materialized in the form of pre-constituted traces. It is important that the electronic trace be established and preserved for the sake of integrity. This evidentiary obligation aims to guarantee the restoration of the trace from its preservation.

With the Internet, there is no original but only copies, except for the information system used. Therefore, the distinction will be made according to the nature of the medium and each medium will be subject to a different legal treatment. Indeed, the information contained on the original medium has a higher probative value than that appearing on the copy. Thus, an electronic act should count as the original from the moment it presents reliable guarantees regarding the maintenance of its integrity.

The notions of integrity and fidelity, however, allow the requirement for the intact nature of the writing to be transposed into the digital world. These notions differ from the notion of reliability which only applies to technical procedures and processes, as well as to computer systems that produce writings. The writings must be intact and the means used must be reliable.

Today, only an electronic signature based on a public key certificate can guarantee this integrity function. This tool automatically produces a hash of the signed message, which it encrypts by means of a cryptographic algorithm (by a function called “hash” or “control”). The signed message is accompanied by a resulting footprint, certifying that the document sent is identical to the message received. Then, the recipient of the message must verify that the signature is correct, via the result of the numerical calculation of the shortening of the message encrypted at the time of sending with the result of the calculation obtained upon receipt. It is from this moment that one can be sure that the message is fully integrated.

Sur votre appareil

Comprendre cet article

L’analyse utilise l’intelligence locale du navigateur lorsqu’elle existe, sinon un résumé extractif. Le texte n’est envoyé à aucun service extérieur.

Facebook X LinkedIn

Ensuite A lire aussi

April 6th at Grand Rex - Tech For Future
Innovation

April 6th at Grand Rex - Tech For Future

Celebrating the 90th anniversary of the Grand Rex, Tech For Future highlights French technology's commitment to ecological transition,…

1 min read

Free, no spam, one-click unsubscribe.