PKI Law - Principal Topics
I.  Basics of Public Key Cryptography V.  PKI Accreditation - The Right Combination
II. What PKI Does  - The Killer Apps VI. Secure Electronic Commerce as an Industry 
III.Technology Battlefields VII. Individual Rights of PKI End-Users and "Consumers"
IV. Global PKI Legislation/Regulation VIII. Useful PKI Websites and Compilations of PKI Links
PKI Law Older Postings  - Easiest More Difficult For Experts
  Year 1999           Go to  ==>  [Later Year 2000] ==> [Earlier Year 1998]

December 1999
12/13 at V.a  The so-called "EU Electronic Signatures Directive" - Directive 1999/93/EC of the European Parliament and of the Council of 13 December 1999 on a Community framework for electronic signatures

November 1999
11/10 at II.c  Identrus L.L.C. approved by Federal Reserve as CA as nonbank sub of Foreign and US commercial banks. 
11/3 at VII.b  HHS Prop. Regulations Implmenting HIPAA (Health Information Portability and Accountability Act)
11/3 at VII.d.  COPPA (Children's Online Privacy Protection Act of 1998) Full Text of FTC Adoption of Final Rule Implementing COPPA

October 1999
10/15 at V.d. AICPA/CICA WebTrustSM Principles and Criteria for Business-to-Consumer Electronic Commerce
10/20 at VII.d.  COPPA (Children's Online Privacy Protection Act of 1998) FTC Press Release re Adoption of Final Rule Implementing 

September 1999
9/19 at V.a. (Update of 6/22/99) Official version of the European Commission Electronic Signature Directive. Courtesy Hans Nilsson

July 1999
7/22 at IV.a. (Update of 4/22/99) Revised (6/29/99) UNCITRAL Draft Uniform Rules on Electronic Signatures. Courtesy John Gregory 
7/22 at V.a.  (Update of 6/22/99) Final Export Team Rep(7/20/99)of EESSI (European Electr.Sig.Standardiz Init. Courtesy Hans Nilsson
7/22 at VI.d. (Update of 6/28/99) PKI for electronic filing of real estate deeds in B.C. Final Version Enacted 7/15/99. Courtesy of Ron Usher
7/21 at IV.e. July 6 Comments on S.761 (Federal pre-emption of non-UETA) by John M. McCabe, NCCUSL Legal Counsel
7/21 at IV.e. Draft of Uniform Electronic Commerce Act to be considered by Unif Law Conf of Canada Aug 99. Courtesy of John Gregory
7/21 at IV.e. Comments on NCCUSL's UETA by ABA Section of Science & Technology.  Prepared  by Tom Smedinghoff of MBC
7/20 at VI.c Summary of  $45 M credit card cyberscam, Aug 99 Scientific American, exploiting weakness of authentication using secret PIN
7/13 at III.e. White paper (7/12/99) about Surety.com's Digital Notary(R) Service, "Time is of the Essence" by Merrill of McC&E
7/3 at VIII.c. Top 25 E-Commerce Websites picked by Mass Electronic Commerce Assn. Courtesy of Tom Hopcroft 
7/1 at IV.e.  Australia Electronic Transactions Bill 1999 (Intro 6/30/99) is minimalist, like UNCITRAL.  Courtesy Colin Minihan, Austr A.G.
7/1 at IV.e.  In 1995 NJ abolished the Statute of Frauds except for land and wills. Here is 1991 NJ Law Rev Comm Rept. Courtesy M Garde

June 1999
6/30 at IV.e. NJ A.3039 Intro 5/3/99.  Electronic record satisfies writing for S of  F for UCC 2-201, 2A-201. Courtesy Maureen Garde.
6/30 at IV.c. Summary of Illinois Electronic Commerce Security Act in June 99 Ill B.J. article by R.J. Robertson and Tom Smedinghoff 
6/30 at IV.e. S.761 Commerce Com 6/23/99 Markups (not in Thomas yet) pre-empting non-UETA State legis. Courtesy Dan Greenwood
6/30 at IV.c. The Illinois Electronic Commerce Security Act, drafted by Tom Smedinghoff of McBride Baker & Coles in Chicago. 
6/30 at IV.c. "Moving With Change: Electr. Signature Legis as a Vehicle for Advancing E-Commerce," Smedinghoff & Bro, MBC Spr 99
6/29 at V.a.  BS 7799 (99 Edition) British Standard,  Part 1 - 1995 - The Code of Practice, Part 2 - 1998 - The Requirements Specification.
6/28 at IV.d. Swedish Digital Signature Standards. 
6/28 at IV.d. Italian Digital Signature Law (The Bassanini Law 3/15/97), English Translation
6/28 at VI.d. PKI used for electronic filing of real estate deeds in Prov of British Columbia. Bill introduced 6/28/99. Courtesy of Ron Usher.
6/23 at VI.c. Merrill slides, "Electronic Banking - Internet Security & Fin Privacy" NJ League Bankers Compli Sem 6/24/99 Jamesburg NJ
6/22 at V.a.  Final draft (6/18/99) of EESSI (European Electronic Signature Standardization Initiative) Expert Team Report. Truly excellent!
6/20 at IV.e. UETA (Uniform Electronics Transactions Act) Approval Draft for NCCUSL Annual Meeting July 23, 1999
6/20 at VIII.b FIPS 140-1 (1994) by NIST.  Overall requirements for the design and implementation of cryptographic algorithms, modules 
6/20 at IV.e. UCITA (Uniform Computer Information Transactions Act, formerly UCC Art 2B), Approval Draft for NCCUSL Mtg 7/23/99
6/17 at VI.c. Merrill slides, "Security in Online Trading  - Digital Signatures and Encryption," American Conference Inst, NYC 6/15/99
6/17 at VI.c. NPR news clip 6/8/98 describing spoof of the e-mail identity of the dean of MIT. Courtesy of Tom Melling, Perkins Coie 
6/15 at II.f.  Merrill slides for "Security Issues in Online Trading," New York City 5/24/99, Institute for Internatl Research. Nonrepudiation.

May 1999
5/13 at VI.d.  Dept of Defense Announces 2000-2002 schedule for DOD-wide PKI, interoperable w external CAs. Thanks Dave Sweigert.
5/13 at VI.b.  Slides by Merrill, "Negotiating a Winning Electronic Commerce Outsourcing Agmt" at ICM Outsrc Conf  in Chicago, 5/19/99
5/12 at VII.c.  Speech by President Clinton (5/4/99) on Privacy of Financial Information, and identity fraud and online securities fraud
5/12 at III.c. Article (July-Aug 95) "The Square Root of NOT," by Brian Hayes, discussing quantum computing and factoring algorithms
5/12 at VII.b.Slides (5/8/99) on privacy legal issues in health care by Bob Burger, Myrna Wigod, Chas Merrill of McCarter & English
5/12 at III.c. Slides (4/15/99) by Mark Kubiec, Ph.D., (Berkeley Chemistry Dept) explaining how quantum and DNA computing work
5/12 at III.f.  Article (4/9/99) by Prof. Lawrence Lessig, "The Code is the Law" - West Coast Code (S.V.)  & East Coast Code (Congress) 
5/11 at II.b.   Re attorney ethics of unencrypted e-mail - ABA Formal Opinion No. 99-413 (3/10/99),  Draft Model Rule 1.6 (3/23/99)
5/8 at VIII.e.  10/5/98 Paper by NSA authors. Mainstream operating systems are inadequate to provide security. Thanks Rick Hornbeck 
5/5 at VII.c.  The Jan 4, 1999 ACES RFP of the U.S. General Services Admin uses PKI to authenticate both the RFP and responses
5/2 at VIII.d.  Not the Orange Book  (1992 rev 98) by Paul Merrill, summary of the Orange Book & Rainbow Series. Thanks Rick Hornbeck
5/2 at V.b.   1/4/99 Posting of Final Government of Canada Certificate Policy Matrix of 8 CPs - Signatures & Confidentiality, each 4 levels
5/2 at VII.b.  1998 Article on tension between medical privacy and legitimate access, courtesy of John Christiansen of Miller Nash in Seattle
5/1 at VI.c.    4/99 article about $3.2 million of e-Bay bids by teen using his parents' PIN, with questions about PKI nonrepudiation
5/1 at VII.d.  Law Review Article (1998) by Prof Jerry Kang of UCLA Law School, "Transaction Privacy in Cyberspace Transactions"

April 1999
4/30 at II.c.   Classic early article (Dec 1995) by Phillip Hallam-Baker of Verisign, comparing dozens of various PKI payment schemes
4/30 at IV.d.  Germany Digital Signature Law enacted June 13, 1997 - the first digital signature law enacted in Europe
4/30 at VIII.a.  mbc.com by Tom Smedinghoff of McBride Baker & Coles - Comprehensive summary and full text of global dig sig laws 
4/30 at VIII.d. pkinfo.com by David Sweigert of GTE/BBN - PKI Links emphasizing standards orgs and technical, and some legal PKI issues 
4/29 at IV.d.  March 1999 revision of European Union Draft Directive on electronic signatures (including PKI), expected to be final draft.
4/29 at V.c.   March 1999 RFC 2527, embodying the IETF PKIX4 draft of Chokhani and Ford 
4/24 at II.b.   Summary of ABA Ethics Opinion 99-413 (Mar 15, 1999, approved April 17, 1999). Ethics - Attorney/Client Secure Commun. 
4/24 at IV.d. The 5-part Govt of Canada Bill C-54 on Electronic Commerce. 1. Privacy; 2. Validates Elect Records, 3. Electronic Evid.
4/24 at V.d.  "Monogamous, Promiscuous and Polygamous Models of Electronic Commerce," Merrill art. Kluwer EDI Law Rev Sept 1995. 
4/23 at IV.e. The Millennium Digital Commerce Act, S.761 and H.R. 1320, Abraham, McCain. Pre-empts State Law for UETA! (4/5/99)
4/23 at IV.c. US OMB Proposed Elimination of the Govt Paper Work Elimination Act of 1998. (Mar 99)
4/23 at IV.c. Access with Trust, by FPKI, GITS, OMB
4/22 at IV.d. Article by Suzanne Perry (4/19/99) in Reuters, noting EU movement on both Directives - Digital Signatures and Consumer 
4/22 at IV.a. UNCITRAL Draft Uniform Rules on Electronic Signatures with Report of Working Group, 34th Session Vienna 2/25/99
4/22 at IV.d. EU Draft Directive on Digital Signatures, Mar 30, 1998 Draft, with some commentary
4/22 at IV.d. Article by Dr. Bernd Tremml summarizing the EU Directive on Unfair Terms in Consumer Contracts (Spring 1997)
4/22 at V.b.  The CARAT Draft PKI Guidelines of the Internet Council of NACHA (10/27/98)
4/22 at IV.c. Analysis (Apr 1999) of State statutory provisions enacted to govern presumptions in a PKI transaction.  By McBride firm
4/22 at I.b.   Analysis (Apr 1999) of State statutory provisions enacted to govern liability of CAs.  By McBride Baker and Coles
4/22 at I.b.   CA Liability Analysis, Feb 1998 White Paper by Smedinghoff of McBride firm for American Bankers Assoc (ABAecom)
4/22 at I.b.   The Certification Practice Statement of the leading CA, Verisign, Inc., version 1.2 May 30, 1997 
4/21 at V.c.  Two new (3/29/99) drafts of Common Criteria Protection Profiles by NIST's Stoneburner: COTS & COTS Operating Systems 
4/21 at II.c.  Effross delightful and inciteful review of book by Vartanian, Ledig & Bruneau, 21st Century Money, Banking & Commerce
4/20 at IV.b. Proposed (6/23/97) Technical Standards for Electronic Filing in U.S. Courts by Judicial Conf. Courtesy of Cohasset
4/20 at II.b.  Slides of Merrill (4/19/99) PLI Speech 6/23/99 in NYC on "Atty/Client Secure Communications - Professional Responsibility"
4/20 at IV.e. NCCUSL and ALI 4/7/99 Press Release regarding Uniform Computer Information Transactions Act (Former UCC 2B)
4/19 at I.a.    Slides for Speech by Sabett & Merrill 2/8/99 and 2/25/99 in Wash DC and Palo Alto on "Public Key Infrastructure (PKI)"
4/19 at IV.e. NCCUSL 3/19/99 Draft of Uniform Electronic Transactions Act with Reporter's Notes
4/19 at II.d.  Slides from Merrill Speech 11/8/98 in Chicago on "Self-Authenticating Records" at Cohasset Managing Electronic Records Conf

 Year 1999           Go to  ==>  [Later Year 2000] ==> [Earlier Year 1998]  [

I.  Basics of Public Key Cryptograpy
a.  How Public Key Cryptography Works c.  Sink the Clipper Chip Forever 
b.  The Role of Certification Authorities (CAs) d.  PKI General Bibliography
II.  What PKI Does  - The Killer Apps
a.  Digital Signatures d.  Document Integrity 
b.  Secure Messaging  e.  Securing Access to Private Info
c.  Payments  f.  Non-Repudiation 
III.  Technology Battlefields
a.  Encryption Cracking (Under Construction) d.  Biometrics
b.  Smart Cards  e.  Time-Date Stamping
c.  Quantum and DNA Computing (Under Construction)
IV.  PKI Global Legislation/Regulation
a.  Toward a Global PKI  d.  Outside the US Today
b.  Judicial Activities e.   Technology-Neutral non-PKI Minimalist E-Commerce Legislation
c.  US Initatives Today
V.  PKI Accreditation - The Right Combination 
a.  The Process of PKI Accreditation c.  PKI  Standards: The  Rows - IETF PKIX4
b.  Draft Certificate Policies (CPs) and Certification Practice Statements d.  PKI Standards: The Columns - Different Objectives 
VI.  Secure Electronic Commerce as an Industry
a.  The Players (Under Construction) c.  Examples of PKI Use
b.  The Economics (Under Construction)
VII.  Individual Rights of PKI End-Users and "Consumers"
a.  General - Focus on the Application Not on the Technology d.  Privacy - Human Dignity and the Right to be Left Alone
b.  Privacy - Personal Health Information e.  Liability - Between CA and End-Users (including Consumers)
c.  Privacy - Personal Financial Information f.   Liability - Between End-Users, (including Consumers)
VIII.  Useful PKI Websites and Compilations of PKI Links
a. Legal Emphasis  d.  Standards and Standards Organizations Emphasis
b. Technical Emphasis 
c. Combined Legal and Technical
Chas Merrill/Webmaster
Website including text and graphics and compilation are copyright 1998 Charles R. Merrill, Esq. and McCarter & English, LLP.  Materials authored by others are copyright such authors, other than for purposes of this compilation. Website design and internet consultation by Mark Pruner of Web Counsel, LLP.  Contributions to PKILaw in the form of text and/or links are welcomed and should be emailed to Chas Merrill or snailmailed, preferably with hard copy and disk, to Charles Merrill, Esq., McCarter & English, L.L.P., Four Gateway Center, 100 Mulberry Street, Newark, New Jersey 07101-0652, 973/622-4444.

Home