2004-06-22 | Resolución 086/2004

Added · Updated

Resolution 086/2004 Approving the Digital Signature Regulation

The Board of Directors of the Central Bank of Bolivia approves the Digital Signature Regulation, which establishes the legal framework for using digital signatures to ensure security and validity in electronic document exchanges within the Payment System. The regulation mandates that electronic documents exchanged in the High-Value Payment System, Electronic Clearing Houses, and compensation and settlement service entities must be digitally signed, defining specific requirements for signatories, certification entities, and digital certificates. It sets a maximum validity period of one year for digital certificates, requires a ten-year retention period for certificate and document records, and outlines obligations for authentication, integrity, and non-repudiation. The regulation enters into force on July 1, 2004.

Banco Central de Bolivia logo

Bolivia

Banco Central de Bolivia

Click to view thumbnail

BOARD RESOLUTION NO. 086/2004 SUBJECT: GENERAL MANAGEMENT – APPROVES DIGITAL SIGNATURE REGULATION.

HAVING SEEN: Law No. 1670 of October 31, 1995. Law No. 1488 of April 14, 1993, on Banks and Financial Entities, modified by Law No. 2297 of December 20, 2001. The Statute of the Central Bank of Bolivia of December 13, 2001. The Regulation of Electronic Clearing Houses and Compensation and Settlement Services, approved by Board Resolution No. 138/2003 of December 4, 2003. The UNCITRAL Model Law on Electronic Signatures of July 5, 2001. Minutes of the Subcommittee on Payment System Policies and Operations (SPOSIP), No. 15/2004 of June 3, 2004. Report from the SIPE Payment System Project Management No. 14/2004 of June 9, 2004. Report from the Legal Affairs Management SANO No. 129/2004 of June 14, 2004.

CONSIDERING: That Article 54, subsection o) of Law No. 1670 and Article 11, numeral 30 of the BCB Statute establish as an attribute of the Board of Directors of the Issuing Entity to approve, modify, and interpret the Statute and regulations of the BCB, by two-thirds of the votes of all its members, without the need for any additional administrative act.

That Article 3 of Law No. 1488, modified by Article 6 of Law No. 2297, provides that within the framework of the Payment System, the Central Bank of Bolivia will establish the regulatory framework for the digital signature to provide security and operational capability to electronic transfers.

That Article 6 of the Regulation of Electronic Clearing Houses and Compensation and Settlement Services establishes that operations of the ECH that do not have documentary backing must comply with the use of digital signature mechanisms, according to the regulations established by the BCB.

That the draft Digital Signature Regulation has been prepared within the framework of international regulations on International Commercial Law, approved by the United Nations.

That the Regulation of Electronic Clearing Houses and Compensation and Settlement Services approved by Board Resolution No. 138/2003 in its Article 6, subsection a), numeral 1.2, establishes that Electronic Clearing Houses that do not have documentary backing must comply with the use of digital signature mechanisms according to the regulations established by the BCB.

That the Subcommittee on Payment System Policies and Operations (SPOSIP) has reviewed and approved the draft Digital Signature Regulation.

That Report SIPE No. 14/2004 indicates that due to the importance acquired by payment operations through electronic means and the need for these to be carried out within adequate frameworks of legal security, and that it is necessary to regulate their operation by limiting risks through the use of digital signatures, it recommends presenting to the consideration of the Board of the BCB for its corresponding approval, the draft Digital Signature Regulation.

That Report SANO No. 129/2004 considers that the draft Digital Signature Regulation does not contravene any legal provision, and therefore it is the attribute of the Board of Directors of the Issuing Entity to consider its approval.

THEREFORE, THE BOARD OF DIRECTORS OF THE CENTRAL BANK OF BOLIVIA RESOLVES:

Article 1.- Approve the Digital Signature Regulation in its VI Chapters and 21 Articles, which is attached as an annex to this Resolution, which will enter into force as of July 1, 2004.

Article 2.- The Presidency and General Management are entrusted with the execution and compliance of this Resolution.

La Paz, June 22, 2004


Juan Antonio Morales A.


Juan Medinaceli V. Enrique Ackermann A.


José Luis Evia V. Fernando Paz B.

ANNEX DIGITAL SIGNATURE REGULATION FOR THE PAYMENT SYSTEM

CHAPTER I GENERAL PROVISIONS

Article 1. (Object). The present Regulation aims to regulate the use of the Digital Signature to provide security and validity to electronic documents within the framework of the Payment System.

Article 2. (Scope of Application). The present Regulation applies to the exchange of electronically signed documents in the Payment System, which comprises the High-Value Payment System administered by the Central Bank of Bolivia (BCB), the Electronic Clearing Houses, and operations in entities that provide compensation and settlement services, defined in the Regulation of Electronic Clearing Houses and Compensation and Settlement Services approved by BCB Board Resolution No. 138/2003.

Article 3. (Definitions). For the purposes of interpreting this Regulation, the following definitions are established: a. Administrator: Legal entity responsible for centralizing and processing operations in the Payment System, as well as managing compensation and settlement processes. b. Authentication: Verification of the identity of the sender of an electronically signed document. c. Digital Certificate: Electronic document that links a public key with the signer, whose purpose is to certify their identity. d. Self-Signed Digital Certificate: Digital Certificate generated by a signer or signatory and presented by a participant, without the intervention of a Certification Entity. e. Private Key: An alphanumeric key created through mathematical algorithms, the exclusive responsibility of the signer and kept by them. f. Public Key: An alphanumeric key created through mathematical algorithms, linked to a private key and included in the signer's Digital Certificate. g. Asymmetric Cryptography: Set of techniques consisting of the use of private and public keys to encrypt and decrypt information, applied to data to ensure its confidentiality, integrity, and authenticity. h. Electronic Document: Data message created, sent, communicated, received, and stored by electronic means. Electronic is understood as the use of technology that has electrical, digital, magnetic, wireless, optical, electromagnetic, or other similar properties. i. Digitally Signed Electronic Document: Electronic document to which the asymmetric cryptographic method of Digital Signature generation has been applied. j. Certification Entity: Entity that issues Digital Certificates and provides services related to digital certification. k. Digital Signature: String of characters generated by an asymmetric cryptographic method, attached or associated with an electronic document to ensure its authenticity, integrity, and non-repudiation. l. Signer or Signatory: Natural person responsible for the creation of the Digital Signature, legally accredited by a participant or administrator of a Payment System. m. Identification Hash (“Hash” or Digest): The result of applying mathematical algorithms to the electronic document, transforming it into a fixed-length string of characters, uniquely associated with the data of the original electronic document. n. Integrity: Quality of the digitally signed electronic document of being protected against accidental or fraudulent alterations. o. Participant: Legal entity authorized to perform operations in the Payment System. p. Repudiation: Refusal by the signer or signatory of an operation or communication made to acknowledge their participation in it.

CHAPTER II DIGITAL SIGNATURE

Article 4. (Use of Digital Signature). Electronic documents exchanged in Payment Systems must be digitally signed and comply with what is established in this Regulation. Digital signature validation procedures must include the use of digital certificates.

Article 5. (Purpose of Digital Signature). The Digital Signature aims to provide security and validity to the electronic document sent by the signer or signatory, guaranteeing: a) That the electronic document was digitally signed by the signatory (authentication); b) That the electronic document has not undergone alterations during its transmission (integrity); and c) That the signer cannot deny an electronic document that has been signed using their private key (non-repudiation).

Article 6. (Characteristics of Digital Signature). The Digital Signature, to be used in the Payment System, must possess the following minimum characteristics: a) The data for the creation of the digital signature must be under the exclusive control of the signatory. b) It must identify the signatory. c) It must be unique for each digitally signed electronic document. d) It must be verifiable, using the signatory's public key. e) It must be linked to the electronic document sent, such that if it is modified, the Digital Signature is invalidated.

CHAPTER III OF THE SIGNER OR SIGNATORY AND RESPONSIBILITIES OF THE PARTICIPANT AND THE RECIPIENT OF THE ELECTRONIC DOCUMENT

Article 7. (Accreditation of Signatories in the Payment System). Each participant must accredit to the administrator of the Payment System in which it operates, the signer(s) that will represent it, granting powers of representation with sufficient attributes. Each signer must have their respective Digital Certificate, issued in accordance with the procedures and standards defined contractually between the Administrator and the participants of a Payment System. In cases where the participant defines that the generation of its operations will be carried out through an automated computer system, the legally accredited representative whose name is recorded in the respective Digital Certificate will be considered the signatory.

Article 8. (Obligations of the Signer or Signatory). Contracts between administrators and participants of a Payment System must include at least the following obligations: a) Digitally sign the electronic document according to the procedures agreed contractually. b) Maintain exclusive control and due confidentiality of the private key under their responsibility. c) Comply with the provisions contained in this Regulation. When a participant in a Payment System generates its digitally signed electronic documents through an automated computer system, it must ensure that the data and the signature creation mechanism are securely and confidentially protected to avoid unauthorized use.

Article 9. (Responsibilities of the Participant Regarding its Signers). I. Each participant is responsible for the acts of its signers or signatories by virtue of the powers conferred upon them, and must promptly inform the administrator of the Payment System in which it operates of any changes or revocations made to the conferred powers. II. Contracts between administrators and participants of a Payment System must consider at least the following responsibilities: a) For the content of the electronically signed documents with the signatory's private key and for the effects they generate. b) For the information provided for the generation of the Digital Certificate and for its content. c) For the unauthorized use of the private key. d) For the effects of the use of the digital signature, when the revocation of the Digital Certificate is not requested for the causes defined contractually and in this Regulation.

Article 10. (Responsibility of the Recipient of a Digitally Signed Electronic Document). Contracts between administrators and participants of each Payment System must establish as the responsibility of the recipient of a digitally signed electronic document, to verify and act accordingly regarding: a) the validity of the digital signature, b) the validity of the Digital Certificate; and c) any limitation contained in the Digital Certificate.

CHAPTER IV VALIDITY AND PROBATIVE EFFECT OF THE DIGITAL SIGNATURE

Article 11. (Validity of Digital Signature). The Digital Signature will be valid for use in the exchange of electronic documents in a Payment System only if the procedure and means employed for its generation comply with what is established in this Regulation. The contract signed between participants and the administrator of a Payment System is sufficient documentation for the purposes of recognizing and legal validity of the Digital Signature between the parties.

Article 12. (Probative Effect of Digital Signature). The Digital Signature that complies with the characteristics indicated in this Regulation, binds the participant and its signer to the digitally signed electronic document and attributes authorship of it, with the same validity and probative efficacy that the Law grants to the handwritten signature, under the provisions of the Consolidated Text of Law No. 1488.

CHAPTER V OF CERTIFICATION ENTITIES

Article 13. (Contractual Definition of Certification Services). For the certification of Digital Signatures, the administrator and participants of each Payment System will contractually define one of the following modalities: a) The service of a Certification Entity, or b) Self-Signed Digital Certificates accepted between the parties.

Article 14. (Requirements of the Certification Entity). The Certification Entity, eligible to provide certification services to a Payment System must:

  1. Have norms and practices defined in an operations manual or equivalent document, which includes: a) Procedures for the generation of the certificate and record keeping. b) Access procedures to information for administrators, participants, and signers. c) Norms and procedures related to the certificate lifecycle.
  2. Provide the necessary means to enable the timely revocation of the Digital Certificate.
  3. Ensure that the recipient of digitally signed electronic documents has access to the necessary means to allow verification of: a) The identity of the participant and the signer or signatory through the Digital Certificate. b) Any limitation of the Digital Certificate. c) The validity of the Digital Certificate. d) Any limitation on the scope or degree of responsibility established by the certifier.

CHAPTER VI DIGITAL CERTIFICATE

Article 15. (Content of the Digital Certificate). The Digital Certificate must contain, at least, the following information: a) Data identifying the participant and its corresponding signer or signatory; b) Signer's public key; c) Identification of the asymmetric cryptographic system used to generate the Digital Certificate Signature; d) Date and time of issuance and expiration of the Digital Certificate; e) Any limitation of use and responsibility to which the Digital Certificate is subject; f) Algorithm and identification hash of the Digital Certificate; g) Serial number of the Digital Certificate. When the Digital Certificate is issued by a Certification Entity, it must additionally contain the identification and be digitally signed by said entity.

Article 16. (Validity of the Digital Certificate). The Digital Certificate will be valid until the expiration date indicated in it. In no case shall the validity be greater than one (1) year.

Article 17. (Procedures for the Issuance of a Digital Certificate by Certification Entities). The procedures established by Certification Entities for the issuance of Digital Certificates must be contractually recognized between the administrator and the participants of a Payment System.

Article 18. (Issuance of Self-Signed Digital Certificates). Self-Signed Digital Certificates must be generated under the procedures and specifications expressly defined in the contract signed between the participants and the administrator of the Payment System in which they operate, within the framework of the provisions of this Regulation. Once the Self-Signed Digital Certificates are generated, the administrator and participants of the Payment System, through their legal representatives with sufficient powers for this effect, must carry out the exchange of their respective certificates before a Notary of Public Faith, who will attest to the act and the content of the certificates, verifying the identity and powers of both parties.

Article 19. (Use of Self-Signed Digital Certificates). Self-Signed Digital Certificates may be used in the exchange of electronic documents in the Payment System until a Certification Entity legally established in the country is established.

Article 20. (Revocation of the Digital Certificate). I. The revocation of the Digital Certificate implies its disabling by the Certification Entity, or its cancellation in the case of Self-Signed Digital Certificates, invalidating its use for new digitally signed electronic documents. II. The contract signed between the administrator of a Payment System and the participants will include the conditions, procedures, and causes for the revocation of Digital Certificates. III. Participants and administrators of a Payment System must contractually obligate themselves to revoke the Digital Certificate in any of the following cases: a) When the confidentiality of the private key has been called into doubt or is in danger of being used improperly. b) When the private key has been deleted, destroyed, or is inaccessible. c) When the participant cancels the powers conferred upon the signer. d) By judicial order or competent administrative authority.

The above list is not exhaustive.

Article 21. (Conservation of Digital Certificates and Digitally Signed Electronic Documents). The Certification Entity eligible to provide certification services to a Payment System must maintain for at least ten (10) years a repository of data related to Digital Certificates, as well as the electronic record of valid, expired, and revoked Digital Certificates. In the case of Self-Signed Digital Certificates, administrators and each participant of the Payment System must maintain for at least ten (10) years a repository of data related to Digital Certificates, as well as the electronic record of valid, expired, and revoked Digital Certificates.

Administrators and each participant of the Payment System will be responsible for maintaining for at least ten (10) years the repository of digitally signed electronic documents.

More like this from BCB

BCB published 7 documents in the last 30 days. We email you each new one the day it's published.

Topics
Share