The connotations of electronic signature and digital signature are different. Digital signature is one of the electronic signature technologies, but they are also closely related. At present, the signature mentioned in the Electronic Signature Law generally refers to "digital signature".
e-signature
In order to understand what an electronic signature is, we need to start with the traditional manual signature or stamp. In traditional business activities, in order to ensure the security and authenticity of transactions, written contracts or official documents should be signed and sealed by the parties or their responsible persons, so that both parties to the transaction can identify who signed the contract and ensure that the signer or seal recognizes the contents of the contract, thus making the contract legally valid. In the virtual world of e-commerce, contracts or documents are expressed and transmitted in the form of electronic documents. In electronic documents, the traditional handwritten signature and seal can not be carried out, and it must be replaced by technical means. Electronic signature is an electronic technical means, which can identify the true identities of both parties in electronic documents, ensure the security, authenticity and inertia of transactions, and play the same role as handwritten signature or seal.
Legally speaking, signature has two functions: identifying the signer and indicating the signer's approval of the contents of the document. UNCTAD's Model Law on Electronic Signatures defines an electronic signature as "data contained in, attached to or logically related to a data message, which can be used to identify the signer related to the data message and show that the signer approves the information contained in the data message"; Is there a provision in the EU directive on the framework of electronic signature? Quot Data attached in electronic form or logically associated with other electronic data, as an authentication method, is called electronic signature.
There are many technical means to realize electronic signature, but the mature electronic signature technology widely used in advanced countries in the world is "digital signature" technology. Since technology neutrality is a basic principle of making laws, there is no reason to say that public key cryptography is the only technology that can make signatures, so it is necessary to define a more general concept to adapt to the future development of technology. The signature mentioned in the current electronic signature law generally refers to "digital signature".
digital signature
The so-called "digital signature" is to generate a series of symbols and codes through some cryptographic operation to form an electronic password for signature, rather than writing a signature or seal. For this kind of electronic signature, technical verification can also be carried out, and its verification accuracy is incomparable to that of general manual signature and seal verification. "Digital signature" is a kind of electronic signature method with the most common application, the most mature technology and the strongest operability in e-commerce and e-government. It uses standardized procedures and scientific methods to identify signers and approve electronic data content. It can also verify whether the original text of the file has changed during transmission, and ensure the integrity, authenticity and non-repudiation of the transmitted electronic file.
In the ISO7498-2 standard, digital signature is defined as "some data attached to a data unit, or the cryptographic transformation of the data unit, which allows the receiver of the data unit to confirm the source and integrity of the data unit and protect the data from being forged by people (such as the receiver)". The American Electronic Signature Standard (DSS, FIPS 186-2) defines digital signature as "using a set of rules and a parameter to calculate data, and the identity of the signer and the integrity of the data can be confirmed through this result". According to the above definition, PKI(Public Key Infrastructino) provides the cryptographic conversion of data units, and enables the receiver to judge the source of data and verify the data.
The core executing agency of PKI is the electronic certification service provider, commonly known as CA(Certificate Authority), and the core element of PKI signature is the digital certificate issued by CA. The PKI services it provides are authentication, data integrity, data confidentiality and non-repudiation. The method is to encrypt/decrypt by using the certificate public key and its corresponding private key to generate the signature and verification signature of the digital message. Digital signature is the use of public key cryptography and other cryptographic algorithms to generate a series of symbols and codes, forming an electronic password for signature, rather than writing signatures and seals; This kind of electronic signature is also technically verifiable, and its verification accuracy is incomparable with manual signature and stamp verification in the physical world. This signature method can be used for authentication in a large number of trusted PKI domains or multiple trusted PKI domains, especially for security authentication and transmission on the Internet and WAN.
The biggest difference between "digital signature" and ordinary text signature is that it can use graphic files with distinctive personality. You can use a scanner or drawing tool to make your signature, seal and even photos into BMP files as the material of "digital signature".
At present, there are many softwares that can provide "digital signature" function, and the usage and principle are similar, among which "OnSign" is the most commonly used one. After installing "OnSign", the shortcut button of "OnSign" will appear on the toolbars of programs such as Word and Outlook. You need to enter your password every time you use it to ensure that others can't steal it.
For the file sent by using "OnSign", the recipient also needs to install "OnSign" or "OnSign Viewer" to make it have the function of recognizing "digital signature". According to the design of "OnSign", any tampering and interception of document content will invalidate the signature. Therefore, when the other party approves your "digital signature", you can be sure that this file was sent by yourself and has not been tampered with or intercepted. Of course, if the recipient is not at ease, he can also click the blue question mark on "Digital Signature" and "OnSign" will automatically check it again. If there is something wrong with the file, a red warning sign will appear on the "Digital Signature".
In the network era when e-mail is frequently used, making good use of "digital signature", just like "registered letter" in traditional letters, undoubtedly adds another protective barrier to the security of network transmission files.