adacom loader
Please Wait
Articles

Quantum Preservation 

Quantum Preservation  main image

By Konstantinos Noussias, Trust Services Director ADACOM 

The Long-Term Validity of Digital Signatures and Seals 

The quantum threat concerns the entire chain of trust. Electronic signatures, seals, and timestamps rely on keys and algorithms that will soon be considered vulnerable. The protection of today’s documents must therefore begin before these mechanisms cease to be considered secure. 

The Threat to Existing Documents 
Loan agreements, property titles, corporate minutes and public contracts are currently signed using algorithms such as RSA and ECC. A sufficiently powerful quantum computer could eventually make it possible to forge signatures based on these algorithms. 
This does not automatically invalidate the legal validity of a qualified electronic signature. It may, however, undermine the ability to prove that the signature was valid and the document remained intact when it was created. Migrating to post-quantum algorithms for new signatures does not, on its own, protect an already signed file. 

Preservation Starts Today 
eIDAS provides a qualified preservation service for qualified electronic signatures and seals, in order to extend their trustworthiness beyond their period of technological validity. The process must begin while the original algorithms, certificates and revocation of information remain trustworthy. 
When a document is enrolled, the service records the validation result of the signature or seal, collects the certificates, revocation information and other validation data, and creates a preservation evidence record. The evidence protects the document and documents the status of the signature at that specific point in time. 

The Chain of Successive Protection 
Before a certificate expires or the key length, signature algorithm or hash function protecting the evidence is no longer considered sufficient, the service adds a new layer of protection. The new evidence covers the original document and the entire previous chain, using a new key, a new certificate and stronger algorithms. 
The user’s original signature is not replaced. It is retained and surrounded by successive verifiable evidence records. Because each new layer is created while the previous one remains trustworthy, it can later be demonstrated that the original signature was valid before its algorithm became vulnerable. 

The Timestamp Also Requires Preservation 
A timestamp proves that the protected data existed at a specific point in time, but it is not immune to threats indefinitely. It too relies on a cryptographic key, certificate, signature algorithm and hash function. For this reason, it is renewed before its mechanisms are weakened, so that the new timestamp also protects the previous one. 

The Role of the Qualified Trust Service Provider (QTSP) 
Qualified preservation is provided only by a QTSP that holds the relevant qualified status for the specific service. Compliance with standards such as ETSI TS 119 511 and ETSI TS 119 512, continuous cryptographic monitoring and the timely renewal of evidence are what maintain the trustworthiness of signatures and seals for 10, 20 or 30 years. 

For organizations, the decision is not simply where to store their documents, but how they will be able to prove their origin, integrity and validity when today’s technology is no longer considered secure. 

Talk to our team → Contact Us Now, at https://www.adacom.com/contact-us

Read the article in greek here: https://issuu.com/boussiasmedia/docs/netweek_503_e-magazine/25