SlideShare a Scribd company logo
Digital Signature: Efficient,
Cut Cost and Manage Risk
Formula for Strong Digital Security
Signature
A person’s name written in a distinctive way, pattern
or characteristic as a form of identification by which
someone or something can be identified
RafidahAriffin
Sumerians, inventor of writing also invented
the first authentication mechanism, intricate
seals
History of Signature
This practice remain unchanged for over
1,400 years. Today it is still used and
applied in much the same way – by
scribbling one’s own name.
Affixing handwritten signatures practice
began within the Roman Empire in the
year AD 439, during the rule of Valentinian
III
History of Signature
Why fix something
that isn’t broken?
Security Objectives of A Signature
Authentication
Data Integrity
Non-repudiation
Easily forged
Does not maintain data integrity
Can be repudiated
However, Handwritten
Signatures…
Digital Signature
Also known as “Electronic
Signature” or “Digital Signature
Scheme” or “electronic seal”
Binary or digital code attach to an electronic transmit
message or document to authenticates and executes a
document and identifies the signatory.
Digital Signature Act
1997
“Security and commitment are key issues for commercial online
transactions, as the Internet is an open network prone to problems such
as identity, legal commitment, third party interference and manipulation
of information.”
- Malaysian Communication and Multimedia Commission (MCMC)
Introduces and implements the usage of Digital
Certificate for Internet based commercial
transactions.
In effect since 1st Oct 1998
Types of Digital
Signature
Certificate Authority (CA)
Revoke
Signed
on 2008
Basic Signature
Trust Status
Long-term Signature vs Basic Signature
Long-term signature
Basic signature
Certificate Status Info Timestamp
101100110101…
Hash encrypted with signer
private key
101100110101…
Hash encrypted with signer
private key
Why long-term signature is
important?
E.g. Bank Negara require records to be kept for 7 years.
In the period of 7 years, long-term signature will definitely preserve
the validity of signer.
How Does Digital
Signature Benefits
Your Business
Advanced Digital Signature Solution
(ADSS)
• Protecting information output
– signing and timestamping, notarising and archiving services for e-
invoicing, statements, acceptances, reports etc
• Protecting inbound information
– notarising/timestamping and archiving services for any received information for
larger organisations
• Protecting internal document workflows
– signing/approving documents or data to confirm a chain of approval (Server or Client
held documents)
• Confirming external transactions
– Using intelligent web-forms that results in both end-user signing and
corporate counter signing
– Allowing client documents and files to be signed + uploaded
ADSS - Services
Comprehensive e-business trust services
• Digital Signature creation - Server-side & client
side
• Digital Signature Verification Service
• Certificate Validation - OCSP client and OCSP
Server
• Timestamp - TSA Server
• Web-services Certificate Authority Services
Comprehensive integration options
• Web-services and HTTP, HTTPS services
• Auto File Processor (Watched Folder Mode)
• Secure Email Server
• Integration with business application that
requires workflow
ADSS – Integration Option
ADSS – Supported
Documents & Signature
PDF Documents
- Basic signature (visible / invisible)
- Certify signature
- Sign & timestamp & Long-term signatures
XML Documents
- XML DSig (XAdES ES)
- Timestamps (XAdES ES-T)
- Long-term signatures (XAdES X-Long)
- Explicit Policy and Archive (-EPES, ES–A)
PKCS#7 / CMS / SMIME
- Basic signature (CAdES ES)
- Timestamps (CAdES ES-T)
- Long-term signatures (CAdES X-Long)
- Explicit Policy and Archive (-EPES, ES–A)
Historic Verification
OCSP Validation (immediate verify & long term sign)
Time Stamp Authority (TSA) Server
Sign Verify
 
 
 
 
 
 
 
 
 
- 
 
info@ascertia.com
 
 
 
ADSS – Signing Services
ADSS Client-side signing
Firewall
User
Business
application
ADSS Infrastructure
Servers
Firewall
Signing locally using local keys
External CAs
for OCSP and
CRL data
Go>Sign Professional
includes PDF viewing
and signing
functionality
It also enables DLP by
controlling local
saving, local printing
and screen copy.
Signature Verification
using trusted CA details
ADSS Client-side signing
• Documents can be signed anytime, anywhere
• A move from expensive paper based process to electronic
document
• DLP features included
• Signed using locally held private key from a Trustable third
party
• Protected under Digital Signature Act 1997
EFFICIENT
CUT COST
MANAGE RISK
ADSS Workflow Signing /
Verification
Sign
Verify
Timestamp
Review/
Approve
Countersign
Audit
Verify
Web Application
Review/
Upload
Review/
Approve
1 2 3 4
ADSS Workflow Signing /
Verification
• Document can be signed immediately by multiple person who might not
reside in the same office
• Can be integrated with any business application – document
management system
• A move from expensive paper based process to electronic document
• A single solution which offers multiple functions – signing, time
stamping & verification
EFFICIENT
CUT COST
MANAGE RISK
• Signed using private keys from a trustable third party
• Document’s integrity guaranteed with time stamping
• Protected under Digital Signature Act 1997
• Documents hashed using SHA-1 or SHA-2 with long key lengths
Auto File Processor (AFP) – File Signing &
Verifying
Auto File Processor
ADSS Server
Auto File Processor is a separate
Client Application that can:
• Watch multiple input folders
• Process documents intelligently
• Use one or multiple load-balanced
ADSS Servers to sign documents
• Manages each Signing Profile
• Manages all signing keys
• Performs signature generation
• Logs all transactions
• Provides detailed reports
One ADSS Server can be used or
for high availability two load balanced
ADSS Servers can be used
Final documents
(to be signed) Signed documents
Output FoldersInput Folders
Auto File Processor (AFP) – File
Signing & Verifying
• Multiple documents can be signed with a click of a mouse
• Signed documents are placed in a separate folders
• A move from expensive paper based process to electronic document
• Add new features to existing business application
EFFICIENT
CUT COST
MANAGE RISK
• Signed using private keys from a trustable third party
• Document’s integrity guaranteed with time stamping
• Protected under Digital Signature Act 1997
• All requests are securely logged
Internet
1) ERP system
sends email
ERP
System
Recipient
Secure Email
Server
ADSS
Server
2) Request
signature
3) Signature
4) Forward
email
5) Recipient
receives
signed email
Sign emails that are sent or received
Sign email attachments
Secure Email Server - signing email &
attachments
• Emails & attachments can be signed and verified automatically
• Preserves integrity
• Filter selection policies to be configured that define the type of emails
to verify
• A move from expensive paper based process to electronic document
• Add new features to existing business application
EFFICIENT
CUT COST
MANAGE RISK
• Sender & receiver clearly identified
• Signed using private keys from a trustable third party
• Protected under Digital Signature Act 1997
• All requests are securely logged
Secure Email Server - signing email &
attachments
• Provides multiple services
– Reducing the number of individual products required
• Provides a range of interfacing options
– Easy integration with existing business workflows
• Handles a number of document formats
– Supporting business needs for PDF, XML and Files
• Provides a range of signature formats
– Comprehensive signing and verification services
• Provides a single point of management & audit
– Comprehensive event and transactional logging
– Secure web-based management with role-based access controls
– Simplifies operational activities, reduces management and training costs, reduces
implementation & system costs
Advanced Digital Signature Solution
(ADSS)
ADSS - References
FINANCIAL INSTITUTION
• Deutsche Bundesbank and Banca d’Italia – To verify XML signatures
using long term and archive signature for security & legal strentgh
• LeasePlan, Belgium selected ADSS PDF Server to sign invoices and other
documents. Several thousand documents are signed each month using
long-term PDF PAdES signatures.
GOVERNMENT
• The British Library, UK - Long-term evidencing for the BL online digital
media archive.
• The National Communications Authority (ANACOM), Portugal - Uses
digital signatures for traceability, accountability and integrity to its
business document workflows.
Thank you.

More Related Content

PPTX
IPMA forum 2014
PPTX
Best Practices in Government
PDF
Aadhaar eSign Gateway- Leegality Digital Documentation Platform
PDF
APIdays Zurich 2019 - Blockchain APIs for the enterprise Stefano Tempesta
PDF
Utilizing PKI to Reduce Risk & Cost
PPTX
ZyloMed Transcription & Documentation Automation Services
PPTX
ZyloMed Transcription & Documentation Automation Services
PPTX
ComsignTrust Overview
IPMA forum 2014
Best Practices in Government
Aadhaar eSign Gateway- Leegality Digital Documentation Platform
APIdays Zurich 2019 - Blockchain APIs for the enterprise Stefano Tempesta
Utilizing PKI to Reduce Risk & Cost
ZyloMed Transcription & Documentation Automation Services
ZyloMed Transcription & Documentation Automation Services
ComsignTrust Overview

Viewers also liked (10)

PPT
What is digital signature or DSC
PDF
Digital Signature
PPT
Digital signature
PPT
Digital Signature
PPT
Digital Signature
PDF
E tutorial - digital signature
PPT
Digital signature
PPTX
Seminar ppt on digital signature
PPT
Digital Signature
PPT
Introduction to Digital signatures
What is digital signature or DSC
Digital Signature
Digital signature
Digital Signature
Digital Signature
E tutorial - digital signature
Digital signature
Seminar ppt on digital signature
Digital Signature
Introduction to Digital signatures
Ad

Similar to Digital signature efficient, cut cost and manage risk (20)

PPT
Ascertia Adss Server Capabilities
PPTX
the PDF Signing Slide slide howto guidance
PPTX
Linkedin.Deck
PPT
Ascertia Adss Server Signing & Verifying
PDF
DS-Entrust-SSL-Document-Signing-APR16-WEB2
PDF
SIGNificant Enterprise Platform (Server based)
PPTX
Digital Signatures
PDF
Carrie Peter
PDF
Digitise and complete transactions within minutes - DocuSign Digital Transact...
PPTX
How electronic signature software helps create electonic signature securely
PDF
The Canadian Perspective: Legal Best Practices for E-Signatures in Insurance
PPTX
Securing eHealth, eGovernment and eBanking with Java - IT-Tage 2020 Conference
PPTX
ComsignTrust Overview
PPTX
Digital Signatures solution by ComsignTrust
PPTX
Cryptography
PDF
IPSCA Caja fuerte electronica Cloud Day Eurocloud Spain
PPTX
Document Management System (DMS)
PPTX
Carrie Peter
PDF
Eezi sign WEB
PDF
IT for Escrow & Title Firms
Ascertia Adss Server Capabilities
the PDF Signing Slide slide howto guidance
Linkedin.Deck
Ascertia Adss Server Signing & Verifying
DS-Entrust-SSL-Document-Signing-APR16-WEB2
SIGNificant Enterprise Platform (Server based)
Digital Signatures
Carrie Peter
Digitise and complete transactions within minutes - DocuSign Digital Transact...
How electronic signature software helps create electonic signature securely
The Canadian Perspective: Legal Best Practices for E-Signatures in Insurance
Securing eHealth, eGovernment and eBanking with Java - IT-Tage 2020 Conference
ComsignTrust Overview
Digital Signatures solution by ComsignTrust
Cryptography
IPSCA Caja fuerte electronica Cloud Day Eurocloud Spain
Document Management System (DMS)
Carrie Peter
Eezi sign WEB
IT for Escrow & Title Firms
Ad

More from ChunJia Sio (7)

PDF
Financial sector development in Myanmar
PDF
Vulnerability Management as a Service
PDF
The Future of Banking Mobility
PDF
Evolving stringent regulatory requirements (reworked)
PDF
SSL for server to-server authentication
PDF
Smartphone & tablets: threats or opportunity
PDF
Empowering smes with mobile payment
Financial sector development in Myanmar
Vulnerability Management as a Service
The Future of Banking Mobility
Evolving stringent regulatory requirements (reworked)
SSL for server to-server authentication
Smartphone & tablets: threats or opportunity
Empowering smes with mobile payment

Recently uploaded (20)

PPTX
VMware vSphere Foundation How to Sell Presentation-Ver1.4-2-14-2024.pptx
PDF
cuic standard and advanced reporting.pdf
PDF
How UI/UX Design Impacts User Retention in Mobile Apps.pdf
PPTX
Cloud computing and distributed systems.
PDF
Unlocking AI with Model Context Protocol (MCP)
PDF
Build a system with the filesystem maintained by OSTree @ COSCUP 2025
PDF
Spectral efficient network and resource selection model in 5G networks
PDF
Machine learning based COVID-19 study performance prediction
PPTX
Effective Security Operations Center (SOC) A Modern, Strategic, and Threat-In...
PPTX
Programs and apps: productivity, graphics, security and other tools
PDF
Agricultural_Statistics_at_a_Glance_2022_0.pdf
PPTX
20250228 LYD VKU AI Blended-Learning.pptx
PDF
Optimiser vos workloads AI/ML sur Amazon EC2 et AWS Graviton
PDF
The Rise and Fall of 3GPP – Time for a Sabbatical?
PDF
7 ChatGPT Prompts to Help You Define Your Ideal Customer Profile.pdf
PPTX
Understanding_Digital_Forensics_Presentation.pptx
PDF
Building Integrated photovoltaic BIPV_UPV.pdf
PDF
TokAI - TikTok AI Agent : The First AI Application That Analyzes 10,000+ Vira...
PDF
Review of recent advances in non-invasive hemoglobin estimation
PDF
Approach and Philosophy of On baking technology
VMware vSphere Foundation How to Sell Presentation-Ver1.4-2-14-2024.pptx
cuic standard and advanced reporting.pdf
How UI/UX Design Impacts User Retention in Mobile Apps.pdf
Cloud computing and distributed systems.
Unlocking AI with Model Context Protocol (MCP)
Build a system with the filesystem maintained by OSTree @ COSCUP 2025
Spectral efficient network and resource selection model in 5G networks
Machine learning based COVID-19 study performance prediction
Effective Security Operations Center (SOC) A Modern, Strategic, and Threat-In...
Programs and apps: productivity, graphics, security and other tools
Agricultural_Statistics_at_a_Glance_2022_0.pdf
20250228 LYD VKU AI Blended-Learning.pptx
Optimiser vos workloads AI/ML sur Amazon EC2 et AWS Graviton
The Rise and Fall of 3GPP – Time for a Sabbatical?
7 ChatGPT Prompts to Help You Define Your Ideal Customer Profile.pdf
Understanding_Digital_Forensics_Presentation.pptx
Building Integrated photovoltaic BIPV_UPV.pdf
TokAI - TikTok AI Agent : The First AI Application That Analyzes 10,000+ Vira...
Review of recent advances in non-invasive hemoglobin estimation
Approach and Philosophy of On baking technology

Digital signature efficient, cut cost and manage risk

  • 1. Digital Signature: Efficient, Cut Cost and Manage Risk Formula for Strong Digital Security
  • 2. Signature A person’s name written in a distinctive way, pattern or characteristic as a form of identification by which someone or something can be identified RafidahAriffin
  • 3. Sumerians, inventor of writing also invented the first authentication mechanism, intricate seals History of Signature
  • 4. This practice remain unchanged for over 1,400 years. Today it is still used and applied in much the same way – by scribbling one’s own name. Affixing handwritten signatures practice began within the Roman Empire in the year AD 439, during the rule of Valentinian III History of Signature
  • 5. Why fix something that isn’t broken?
  • 6. Security Objectives of A Signature Authentication Data Integrity Non-repudiation
  • 7. Easily forged Does not maintain data integrity Can be repudiated However, Handwritten Signatures…
  • 8. Digital Signature Also known as “Electronic Signature” or “Digital Signature Scheme” or “electronic seal” Binary or digital code attach to an electronic transmit message or document to authenticates and executes a document and identifies the signatory.
  • 10. “Security and commitment are key issues for commercial online transactions, as the Internet is an open network prone to problems such as identity, legal commitment, third party interference and manipulation of information.” - Malaysian Communication and Multimedia Commission (MCMC) Introduces and implements the usage of Digital Certificate for Internet based commercial transactions. In effect since 1st Oct 1998
  • 12. Certificate Authority (CA) Revoke Signed on 2008 Basic Signature Trust Status
  • 13. Long-term Signature vs Basic Signature Long-term signature Basic signature Certificate Status Info Timestamp 101100110101… Hash encrypted with signer private key 101100110101… Hash encrypted with signer private key
  • 14. Why long-term signature is important? E.g. Bank Negara require records to be kept for 7 years. In the period of 7 years, long-term signature will definitely preserve the validity of signer.
  • 15. How Does Digital Signature Benefits Your Business
  • 16. Advanced Digital Signature Solution (ADSS) • Protecting information output – signing and timestamping, notarising and archiving services for e- invoicing, statements, acceptances, reports etc • Protecting inbound information – notarising/timestamping and archiving services for any received information for larger organisations • Protecting internal document workflows – signing/approving documents or data to confirm a chain of approval (Server or Client held documents) • Confirming external transactions – Using intelligent web-forms that results in both end-user signing and corporate counter signing – Allowing client documents and files to be signed + uploaded
  • 17. ADSS - Services Comprehensive e-business trust services • Digital Signature creation - Server-side & client side • Digital Signature Verification Service • Certificate Validation - OCSP client and OCSP Server • Timestamp - TSA Server • Web-services Certificate Authority Services
  • 18. Comprehensive integration options • Web-services and HTTP, HTTPS services • Auto File Processor (Watched Folder Mode) • Secure Email Server • Integration with business application that requires workflow ADSS – Integration Option
  • 19. ADSS – Supported Documents & Signature PDF Documents - Basic signature (visible / invisible) - Certify signature - Sign & timestamp & Long-term signatures XML Documents - XML DSig (XAdES ES) - Timestamps (XAdES ES-T) - Long-term signatures (XAdES X-Long) - Explicit Policy and Archive (-EPES, ES–A) PKCS#7 / CMS / SMIME - Basic signature (CAdES ES) - Timestamps (CAdES ES-T) - Long-term signatures (CAdES X-Long) - Explicit Policy and Archive (-EPES, ES–A) Historic Verification OCSP Validation (immediate verify & long term sign) Time Stamp Authority (TSA) Server Sign Verify                   -    info@ascertia.com      
  • 20. ADSS – Signing Services
  • 21. ADSS Client-side signing Firewall User Business application ADSS Infrastructure Servers Firewall Signing locally using local keys External CAs for OCSP and CRL data Go>Sign Professional includes PDF viewing and signing functionality It also enables DLP by controlling local saving, local printing and screen copy. Signature Verification using trusted CA details
  • 22. ADSS Client-side signing • Documents can be signed anytime, anywhere • A move from expensive paper based process to electronic document • DLP features included • Signed using locally held private key from a Trustable third party • Protected under Digital Signature Act 1997 EFFICIENT CUT COST MANAGE RISK
  • 23. ADSS Workflow Signing / Verification Sign Verify Timestamp Review/ Approve Countersign Audit Verify Web Application Review/ Upload Review/ Approve 1 2 3 4
  • 24. ADSS Workflow Signing / Verification • Document can be signed immediately by multiple person who might not reside in the same office • Can be integrated with any business application – document management system • A move from expensive paper based process to electronic document • A single solution which offers multiple functions – signing, time stamping & verification EFFICIENT CUT COST MANAGE RISK • Signed using private keys from a trustable third party • Document’s integrity guaranteed with time stamping • Protected under Digital Signature Act 1997 • Documents hashed using SHA-1 or SHA-2 with long key lengths
  • 25. Auto File Processor (AFP) – File Signing & Verifying Auto File Processor ADSS Server Auto File Processor is a separate Client Application that can: • Watch multiple input folders • Process documents intelligently • Use one or multiple load-balanced ADSS Servers to sign documents • Manages each Signing Profile • Manages all signing keys • Performs signature generation • Logs all transactions • Provides detailed reports One ADSS Server can be used or for high availability two load balanced ADSS Servers can be used Final documents (to be signed) Signed documents Output FoldersInput Folders
  • 26. Auto File Processor (AFP) – File Signing & Verifying • Multiple documents can be signed with a click of a mouse • Signed documents are placed in a separate folders • A move from expensive paper based process to electronic document • Add new features to existing business application EFFICIENT CUT COST MANAGE RISK • Signed using private keys from a trustable third party • Document’s integrity guaranteed with time stamping • Protected under Digital Signature Act 1997 • All requests are securely logged
  • 27. Internet 1) ERP system sends email ERP System Recipient Secure Email Server ADSS Server 2) Request signature 3) Signature 4) Forward email 5) Recipient receives signed email Sign emails that are sent or received Sign email attachments Secure Email Server - signing email & attachments
  • 28. • Emails & attachments can be signed and verified automatically • Preserves integrity • Filter selection policies to be configured that define the type of emails to verify • A move from expensive paper based process to electronic document • Add new features to existing business application EFFICIENT CUT COST MANAGE RISK • Sender & receiver clearly identified • Signed using private keys from a trustable third party • Protected under Digital Signature Act 1997 • All requests are securely logged Secure Email Server - signing email & attachments
  • 29. • Provides multiple services – Reducing the number of individual products required • Provides a range of interfacing options – Easy integration with existing business workflows • Handles a number of document formats – Supporting business needs for PDF, XML and Files • Provides a range of signature formats – Comprehensive signing and verification services • Provides a single point of management & audit – Comprehensive event and transactional logging – Secure web-based management with role-based access controls – Simplifies operational activities, reduces management and training costs, reduces implementation & system costs Advanced Digital Signature Solution (ADSS)
  • 30. ADSS - References FINANCIAL INSTITUTION • Deutsche Bundesbank and Banca d’Italia – To verify XML signatures using long term and archive signature for security & legal strentgh • LeasePlan, Belgium selected ADSS PDF Server to sign invoices and other documents. Several thousand documents are signed each month using long-term PDF PAdES signatures. GOVERNMENT • The British Library, UK - Long-term evidencing for the BL online digital media archive. • The National Communications Authority (ANACOM), Portugal - Uses digital signatures for traceability, accountability and integrity to its business document workflows.