Technical Director
Technical Director
Electronic signatures and digital signatures are two terms that are commonly used to mean the same thing. Even within the security industry often marketing people tend to use the two terms interchangeably. However this is incorrect as within the technical and legal communities the two terms have very different meanings. When choosing a signing solution it’s very important to know exactly what is being offered.
Here we try to clear up the confusion by explaining the main differences between electronic signatures and digital signatures and describe their relative pros/cons. We also link the theory to what is actually implemented in practise in SigningHub. Read on and you are bound to be impressed with all the different types of signatures supported by SigningHub!
Firstly let’s clarify what are the generally accepted meaning of the terms e-signatures and digital signatures:
Digital signatures are created using cryptographic techniques, normally based on PKI systems, where the private signing key is only accessible to the owner. There are many different ways of implementing digital signatures, each offering different levels of security and trust for the above services. Some of these different approaches for implementing digital signatures are described later.
This leads to some interesting points:
The following table summarises the main pros/cons of each type of signature:
Pros | Cons | |
Electronic Signatures |
|
|
Digital Signatures |
|
|
Although digital signatures have most of the benefits in terms of security and trust, to create the best user experience it’s necessary to merge the concept of electronic signatures with digital signatures – and that’s exactly what we have done in SigningHub!
In an earlier blog article, we explained the differences between e-signatures and digital signatures. Click here to read this article. In the current blog we cover the different ways of creating e-signatures and digital signatures in Signinghub
SigningHub is a very powerful and flexible solution that caters for many different business scenarios, each with different trade-offs between security, ease of use, ease of management and costs. The following list shows the different types of signatures supported by SigningHub with increasing levels of security:
What is unique about SigningHub is that it can manage each user’s digital signing key securely at various levels of security and trustworthiness:
The “e-signature only” option as explained above is not recommended because it offers no security, however it can be useful for quickly getting a person’s signature without them having to register with SigningHub – hence it does have practical uses. However this should only be done when a second signer will be adding a digital signature afterwards (i.e. using one of the other methods mentioned above), this will lock the first user’s e-signature so that any subsequent modifications are easily detected.
As explained, SigningHub allows users to either create an electronic signature on its own or as part of a digital signature. In both cases users can e-sign using any of the following means:
e-signing using finger /stylus on a mobile device:
e-signing using mouse drawing:
e-signing by just typing your name:
e-signing by uploading scanned signature image:
e-signing using a specialist signature device:
Note: We support Signotec and Wacom signature tablets
Some countries do store the user’s hand-signature image on their eID cards, as such SigningHub can be taught to use this image as the e-sign.
As explained above user’s can create their digital signature using keys held centrally on the server (encrypted database or HSM), or keys held locally on a smartcard or secure USB token, or keys held inside their mobile device. Further to this, SigningHub supports the following different types of signatures:
We have all the bases covered in SigningHub. We support e-signatures only option but recommend using these together with digital signatures. We allow multiple ways of e-signing on multiple devices. In terms of digital signatures we allow multiple options for user’s signing key security, i.e. server, smartcard, secure USB token, mobile. We also support long-term signatures which can be verified in the future. We support Adobe CDS signatures and also EU qualified signatures. In addition to this the SigningHub core document workflow, tracking and notifications help to ensure your approval workflows are efficient and easy to manage.
The SigningHub “in-person signing” feature is a new capability that enables a person to electronically sign documents without requiring them:
In-person signing suits many business environments where members of the public need to electronically sign a document or form in front of a member of staff that witnesses this by signing with their digital signature.
The in-person signer creates a basic e-signature, i.e. a hand-signature image, on the document that records their intent or approval of the document content. The document and the e-signature is then locked to prevent further changes by the witness digital signature that is applied by the host of this face-to-face meeting.
This brief note describes the process.
First login and upload a document as normal. Add yourself as signer and then proceed to the document prepare window. Position your digital signature field in the required location as normal.
From within the advanced settings area select the “In-person signing” option:
This will show a pop-up window, where you can select the number of e-signature fields you want to add per host signer, an optional identifier for these fields and the page number on which they should be located:
When you click the “Add” button the in-person signing field is created on the document. The field is clearly marked to show that it is an in-person signing field:
Also the right-hand navigation panel shows the in-person signing field:
The document is now prepared. To save a template of all these settings click the “save template” button in the above screen. This enables you to automate the process the next time you need to create in-person field(s) on a similar document.
To start the workflow approval process you need to simply send the document. To initiate the in-person signing process sometime later, simply login to SigningHub and select the document to be signed in the pending folder OR click the hyperlink in the email notification.
The easy to use navigation tab immediately identifies the next action that needs to be completed before you can digitally sign and witness the e-signature:
At this stage simply pass your laptop, notebook, iPad or Android tablet to the customer (the in-person signer). If this was a PDF form, then the navigation tabs would guide the person to fill in the mandatory form fields in the prescribed order before proceeding to their e-signature field.
To e-sign they should click on their in-person field and the following window will be displayed:
This looks like the normal SigningHub digital signature window, except there is no requirement to enter an account password (since the in-person signer does not have an account on SigningHub).
Once the e-signature has been created, the e-signature image is inserted into the document and the digital signature field now becomes active waiting for the host’s digital signature:
As the witnessing host, you can then digitally sign in the normal way (e.g. using server-side signing, local smartcard/USB token signing or a mobile signature).
The completed document will look as follows:
A signed copy of the document can be provided to the in-person signer at this stage.
In-person signing provides a simple way for customers, citizens or anyone else to sign documents during face-to-face meetings, without requiring an account on SigningHub. The document and the person’s e-signature is witnessed and protected from unauthorised change by the digital signature applied by the host to complete the process.
The process discussed above is just one example. A document or form can have:
This flexibility ensures that the in-person signing functionality is useful for almost any business scenario.