Singapore legislation
Regulation 22
of Electronic Transactions (Certification Authority) Regulations 2010
Regulation 22
Secure digital signatures
Subregulation 1
The technical implementation of the requirements in paragraph 3 of the Third Schedule to the Act must be such as to ensure that it is computationally infeasible for any person, other than the person to whom the signature correlates, to have created a digital signature which is verified by reference to the public key listed in that person’s certificate.
Subregulation 2
The signature on its own should be such as to —
ensure that the name or other unique identifiable notation of the person to whom the signature correlates be incorporated as part of the signature and cannot be replaced or forged; and
readily present such indicia of identity to a person intending to rely on the signature.
Subregulation 3
The technical implementation should ensure that —
the steps taken towards the creation of the signature must be under the direction of the person to whom the signature correlates; and
no other person can reproduce the sequence of steps to create the signature and thereby create a valid signature without the involvement or the knowledge of the person to whom the signature correlates.
Subregulation 4
The technical implementation should indicate to a relying party of a signature whether the document or record that the signature purports to sign has been modified in any way and this indication should be revealed in the process of verifying the signature.