Skip to content

E-podpis

SES,AES,QES,eIDAS

Ko govorimo o elektronskem podpisu ( e-signature) v EU, je referenca 910/2014, ki se imenuje tudi eIDAS ( “Electronic Identification and Trust Services for Electronic Transactions”).

Po eIDAS-u razlikujemo tri vrste nivojev elektronskega podpisa in sicer

1. Enostavni nivo (SES Simple electronic signature )

Ta nivo velikokrat uporabljamo, čeprav se tega ne zavedamo. To je recimo skeniran dokument z podpisom, potrditev soglašanja z pogoji poslovanja, ko se prijavljamo na spletni strani ipd.

Nivo zaščite in zagotovila je nizek. Takšen nivo ne zagotavlja, da je oseba, ki je podpisala dokument res prava oseba. Ne obstajajo tudi detajli potrditvenega dogodka kot so datum, čas. Takšen nivo ni zadosten za pravne zadeve.

2. Napredni nivo (AES Advanced electronic signature )

Bolj varen in zanesljiv saj mora podipirati naslednje zahteve eIDAS:

  • je edinstveno povezan s podpisnikom;
  • je sposoben identificirati podpisnika;
  • je ustvarjen z uporabo podatkov za ustvarjanje elektronskega podpisa, ki jih lahko podpisnik z visoko stopnjo zaupanja uporablja pod svojim izključnim nadzorom;
  • je povezan z podpisanimi podatki na način, da je zaznavna vsaka kasnejša sprememba podatkov.

Gornje pomeni, da lahko napredni e-podpis zagotovi, da je podpisnik tisti za katerega se predstavlja.

Kakšna je pravna vrednost naprednega elektronskega podpisa?

Tudi dokumenti, podpisani z naprednim e-podpisom, so dokaj zaščiteni, saj ponudniki za zaščito podatkov uporabljajo tehnologijo šifriranja. Nazadnje, napredni e-podpis uživa večjo stopnjo zaupanja v primerjavi s preprostim. V primeru sodnega spora mora tožeča stranka dokazati njeno veljavnost.

3. Kvalificirani nivo (QES Qualified electronic signature )

Kvalificirani e-podpis je najstrožja in najbolj kompleksna vrsta podpisov. Je edini, ki ima pravni ekvivalent lastnoročnega podpisa, zaradi česar so pogodbe 100-odstotno zapečatene in pravno zavezujoče v vseh državah članicah EU.

Tehnično gledano gre za napreden e-podpis, kar pomeni, da izpolnjuje zahteve v naprednem nivoju. Poleg tega pa je ustvarjen na podlagi uporabe naprave za ustvarjanje kvalificiranega podpisa (QSCD – qualified signature creation device) in se opira na kvalificirano potrdilo za elektronski podpis. Ti dve dodatni funkciji zagotavljata, da je kvalificirani e-podpis edinstven, zaupen in varen.

Poleg tega lahko kvalificirano potrdilo izda le kvalificirani ponudnik storitev zaupanja, subjekt, ki se redno revidira in nadzoruje, da se zagotovi najvišja raven varnosti. V primeru sodnega spora tehta toliko kot podpis z mokrim črnilom. Njegova veljavnost se domneva in uporablja se načelo obrnjenega dokaznega bremena. Če podpisnik izpodbija njegovo veljavnost, potem je on tisti, ki mora dokazati, da je e-podpis neveljaven.

Posted from: https://www.luxtrust.com/en/news/understanding-eidas-e-signature-levels-and-their-associated-legal-value

Posted from: https://ec.europa.eu/digital-building-blocks/wikis/display/ESIGKB/What+are+the+levels%2C+simple%2C+advanced+and+qualified+of+electronic+signatures

Trusted service providers Slovenia

https://eidas.ec.europa.eu/efda/tl-browser/#/screen/tl/SI

About SES,QES,QES

Types of Digital Signature: AES, QES, SES, explained

Posted from: https://www.docusign.com/en-gb/blog/types-digital-signature-aes-qes-ses-explained#:~:text=Simple%20electronic%20signature%20(SES)%3A%20For%20everyday%20transactions&text=It%20does%20not%20require%20strong,unique%20access%20code%20before%20signing.

Biometric Signature

Biometric signatures involve verification or encryption via fingerprint, retina, iris, or voice, and are increasingly emerging as a way to ensure digital security. This type of signature is ideal for critical transactions where identity must be certified and verified.

Additionally, these advanced security features ensure the integrity of documents during and after the signing process.

While electronic signatures are still the predominant form of signature, digital signatures are expanding, and are a must-have in Europe. Because there is a lack of a common identity, each country accepts different types of identity. Due to eIDAS, Europe is slightly ahead of the U.S. in what it will accept for a digital signature.

Posted from: https://aragonresearch.com/glossary-biometric-signature/#:~:text=Biometric%20signatures%20involve%20verification%20or,must%20be%20certified%20and%20verified.

Signature block

A signature block, also known as a signature line or signature area, is a section typically found at the end of a document, email, letter, or formal communication where a person’s name, title, contact information, and often a handwritten or electronic signature appear. 

Posted from:https://signeasy.com/blog/business/signature-block/#:~:text=Formal%20business%20letters%20and%20emails,%2C%20company%2C%20and%20contact%20details.

NFC

Near-field communication (NFC) is a set of communication protocols that enables communication between two electronic devices over a distance of 4 cm (1.57 in) or less.[1]

The NFC Forum has helped define and promote the technology, setting standards for certifying device compliance.[3][4] Secure communications are available by applying encryption algorithms as is done for credit cards[5] and if they fit the criteria for being considered a personal area network.[6]

ISO/IEC

NFC is standardized in ECMA-340 and ISO/IEC 18092. These standards specify the modulation schemes, coding, transfer speeds and frame format of the RF interface of NFC devices, as well as initialization schemes and conditions required for data collision-control during initialization for both passive and active NFC modes. They also define the transport protocol, including protocol activation and data-exchange methods. The air interface for NFC is standardized in:

  • ISO/IEC 18092 / ECMA-340—Near Field Communication Interface and Protocol-1 (NFCIP-1)[63]
  • ISO/IEC 21481 / ECMA-352—Near Field Communication Interface and Protocol-2 (NFCIP-2)[64]

NFC incorporates a variety of existing standards including ISO/IEC 14443 Type A and Type B, and FeliCa (also simply named F or NFC-F). NFC-enabled phones work at a basic level with existing readers. In “card emulation mode” an NFC device should transmit, at a minimum, a unique ID number to a reader. In addition, NFC Forum defined a common data format called NFC Data Exchange Format (NDEF) that can store and transport items ranging from any MIME-typed object to ultra-short RTD-documents,[65] such as URLs. The NFC Forum added the Simple NDEF Exchange Protocol (SNEP) to the spec that allows sending and receiving messages between two NFC devices.[66]

NFC employs two different codings to transfer data. If an active device transfers data at 106 kbit/s, a modified Miller coding with 100% modulation is used. In all other cases Manchester coding is used with a modulation ratio of 10%.

Every active NFC device can work in one or more of three modes:

  • NFC card emulation Enables NFC-enabled devices such as smartphones to act like smart cards, allowing users to perform transactions such as payment or ticketing.
  • NFC reader/writer Enables NFC-enabled devices to read information stored on inexpensive NFC tags embedded in labels or smart posters.
  • NFC peer-to-peer Enables two NFC-enabled devices to communicate with each other to exchange information in an ad hoc fashion.

NFC tags are passive data stores which can be read, and under some circumstances written to, by an NFC device. They typically contain data (as of 2015 between 96 and 8,192 bytes) and are read-only in normal use, but may be rewritable. Applications include secure personal data storage (e.g. debit or credit card information, loyalty program data, personal identification numbers (PINs), contacts). NFC tags can be custom-encoded by their manufacturers or use the industry specifications.Posted from: https://en.wikipedia.org/wiki/Near-field_communication

Posted from: https://en.wikipedia.org/wiki/Near-field_communication

Leave a Reply

Your email address will not be published. Required fields are marked *