Digital Signatures for Document
Management
This presentation will begin at 2:00 PM EDT 1 PM Central, 12 PM Mountain, 11 AM Pacific
Please check that the volume on your computer is at the highest setting since we stream our presentation in Voice over IP
AIIM Presents:
Digital Signatures for Document
Management
Bryant Duhon – Editor, AIIM E-DOC Magazine Jim Minihan – Partner, imerge Consulting
About AIIM
AIIM is the international industry association connecting users and suppliers of enterprise content management (ECM)
technologies - the tools and methods used to capture, manage, store, preserve, and deliver content in support of business
processes. For more than 60 years, AIIM has been a neutral and unbiased source for education and industry information,
standards, advocacy, and community. Learn more about AIIM at www.aiim.org.
Presented by:
Ramel Levin
Director of Marketing
ARX
Part I
Part I
-
-
Digital Signatures
Digital Signatures
Seeing is Believing
Digital Signatures
Digital Signatures
Digital Signatures
Digital Signatures
-
-
Seeing is Believing
Seeing is Believing
Digital Signatures
Digital Signatures
Digital Signatures
Digital Signatures
Digital Signatures
Digital Signatures
The Keys To
The Digital Future
Jim Minihan Partner 540 364 7640
The Keystone Component For
Document Management
Why Is This Important To ECM?
•
This completes the ECM infrastructure
•
Without digital signature you can’t achieve
the future
•
No other alternative has the ability to scale
as well
•
No other alternative provides the same
security and integrity
What A Signature Accomplishes
• Evidence: A signature authenticates a writing by identifying the signer with the signed document. When the signer makes a mark in a
distinctive manner, the writing becomes attributable to the signer.
• Ceremony: The act of signing a document calls to the signer's attention the legal significance of the signer's act, and thereby helps prevent
"inconsiderate engagements”.
• Approval: In certain contexts defined by law or custom, a signature expresses the signer's approval or authorization of the writing, or the signer's intention that it have legal effect.
• Efficiency and logistics: A signature on a written document often imparts a sense of clarity and finality to the transaction and may lessen the
subsequent need to inquire beyond the face of a document. • Deterrence: To discourage transactions of doubtful utility
Foundation of Signature Law
•
Historic–
English Common Law–
Uniform Commercial Code•
Modern–
Electronic Signatures in Global & National Commerce Act (ESIGN)–
Uniform Electronic Transactions Act (UETA)–
Electronic Signature•
Electronic Signature laws among the States are moreconsistent with each other than Paper and Ink Signature laws
•
Remarkable similarity among electronic signature laws of thesame type
What These Laws Achieve
• Guidance of when and how courts enforce
electronic/online agreements
• Establish the duties of the parties that would likely be
involved in a dispute
• Reduce evidentiary questions that must be resolved
by the courts
• By providing a stable legal infrastructure, encourage
adoption and development of electronic commerce
• Provide consumer protection and reduce fraud
• Allow for electronic records to remain electronic
What You Want To Achieve
• Security – The signer is the only one who could have
signed
• Authenticity – The signature will be accepted as real
• Integrity – What was signed has not been altered
between point A and B
• Non Repudiation – Connects a signer in a way that
prevents denying the agreement
• Authenticity – the signature can be authorized by a
secure process
• Enforceability – the signatures must be verifiable by
relying parties
Some Myths
•
The law is not clear on electronic signature
•
Benefits of electronic signature don’t justify
the effort to implement
•
The technology is too complex
•
The signatures will not be accepted
Electronic Signature
“Any electronic sound, symbol, or process, attached to or logically associated with a contract or other record and executed or
adopted by a person with the intent to signify adherence"
Digital
Signature
Flavors Of Signature
•
Electronic signature could be nothing more than
your name on an email
•
An image of your traditional signature
•
A biometric signature
•
Application based digital signature
•
PKI based digital signature
Keep In Mind
•
Any signature is based on a level of trust in the
signors identity and the process by which it is
invoked
•
Trust is not inherent in any technology
•
Technology must be used in a trustworthy
manner in order to establish trusted systems
•
Even a system that is being used in a
trustworthy manner is ineffective if we cannot
prove its reliability
Trust Need Drives Deployment
•
Trust models vary
•
Intra enterprise - we trust ourselves
•
Inter enterprise - we trust our agreements
•
Open – I have one signature universally accepted
•
Closed – I need a signature for every community I
do business in
•
Open But Bounded – Many Certificate Authority’s
with agreement between them as in the federal
model
Which Fits Your Need
•
Who is the relying party?
–
Internal users only
–
Limited related outside users
• EDI model
–
Outside users defined by narrow industry
• VAN model
–
Extensive unrelated users
Questions To Resolve
• Is it truly an electronic “transaction”?
– In a legal sense
• Does it require a signature?
– Often this is tradition rather than requirement
– Look to statute and need rather than history
• How much do you care about who is at the other end of the
transaction?
– Totally…gimme that DNA
– Some…as long as the bill is paid
– Not at all…we give this to everyone
Why Do It Now?
•
This is the last mile to the fully digital
environment
•
Finally…you can stop converting to paper
•
Sign transactions that cannot be reduced to
paper
•
Increased efficiency and reduced costs
– In specific applications can reduce cycle time by 50%
– Eliminate express delivery charges
Some Applications
• DMV electronic titles • Securing messages in emails • E Notary • Apostils • Recording of Deeds • Court filings • Higher Education • FDA Gateway • USPTO filings • NRC filings • Bid submissions • Bond Issuance • Expense Reports • Travel Requests • HR TransactionsWhere To Use It?
•
For received documents that have not
been otherwise locked or authenticated
•
In workflow transactions where event
based approval is not enough
•
To finalize important business records
•
Non document E commerce transactions
•
Sign official documents
How To Get Started
•
Educate your lawyers – this technology is legitimate
and it can displace paper
•
Start with internal deployment where you define what
is signed for internal consumption;
– Workflow, service level agreements, HR, expense reports
•
Continue to internal documents maintained for
compliance reasons;
– Financial statements, HR, tax records
How To Get Started
•
Take advantage of government commitment by filing
regulatory and compliance documents;
– EPA, OSHA, Labor, State functions
•
Move to working with outside parties for external
acceptance of the signature;
– Selected trading partners for business transactions, contracts, approvals
– Industry groups
– Your customers
On The Horizon
• Beyond ECM and ERM signature adoption becomes
even more important
• Investment in vetting identity can be leveraged to more
purposes
– System access
– Facility access
• Your ability to sign electronically will expand as the rest
of the world adopts
• Your identity credential can be federated when needed
Multi-Factor Token Very High High Medium Low Employee Screening for a High Risk Job Obtaining Govt. Benefits Applying for a Loan Online Access to Protected Website PIN/User ID Knowledge Based One-Time Password
PKI/ Digital Signature
HSPD-12 PIV Card
Increased Need for Identity Assurance
Biometrics
Increased Strength
Presented by:
Ramel Levin
Director of Marketing
ARX
Part III
Part III
-
-
Digital Signatures
Digital Signatures
What to Look For?
How to Choose a Solution?
•
•
Founded in 1987
Founded in 1987
•
•
Specialty: Digital Signature Solutions
Specialty: Digital Signature Solutions
•
•
Large Client Base (2,400+
Large Client Base (2,400+
customers)
customers)
About ARX
About ARX
Q
Q
Seals Documents
Seals Documents
Simple to Use
Simple to Use
Graphical Signatures
Graphical Signatures
Graphical Signatures
Graphical signatures = Less Psychological impact
Multiple Signatures
Multiple Signatures
Multiple Signatures
Make sure subsequent signings do not invalidate prior signings
Application Support
Application Support
Application Support
Make sure the current & future documents types you intend to sign are supported by the solution you choose
Make sure the current & future documents types you intend to sign are supported by the solution you choose
Compliance
Compliance
Compliance
Review the regulations of your industry
Transportability
Transportability
Transportability
A portable signature format can be verified anytime, anywhere
Q&A
Q&A
Ramel Levin [email protected] www.arx.com Ramel Levin Ramel Levin [email protected] [email protected] www.arx.com www.arx.comQuestions?
On the bottom left hand side of your screen, type your question in the white box and hit
Upcoming Webinars
July 23rd – Automated Document Classification for
Supercharged Workflows
August 6th – Should you Outsource your Email Archiving
August 13th – Bring Business Process Efficiencies to eDiscovery
August 20th – A Strategy for Content-driven Transactions