Electronic Signatures for Teleworker

On December 13th 1999 the European Union approved a directive regarding electronic signatures, proving the whole union with a common legal framework for the use of signatures in electronic form. Austria was one of the first countries to implement this directive and the Austrian signature law is in effect since January 1st 2000. Electronic signatures are important for teleworking, as they allow to represent one aspect of physical presence (manual signature on a sheet of paper) to be transported to remote work an transfer over communication networks. Another advantage is, that one particular problem associated with electronic signatures (the presentation problem, see below) might lead to a standardization of document formats. This would help telework immensely, as data-exchange would be made much easier.

On this page some general remarks on signatures are presented, including a definition and some advantages and problems important for telework. Finally, you can find a collection of links to legal resources, technical standards for the implementation and certificate authorities.


The Austrian signature law defines "electronic signatures" as:
electronic data attached to or logically linked with other electronic data which serve to authenticate, that is establishing the identity of the signatory.
In this definition the main aspect of a signature is included, the connection between a document and an individual person.

Electronic signatures <-> Digital signatures

Electronic signatures have a very broad range and for example public key systems or signature dynamics can be used. However, in most cases only on subtype is used (and therefore the two names are often mixed; but the distinction should always be remembered): digital signatures. These consist of a private key (used for signing a hash-value of the document) and a public key (cited in a certificate, connecting this particular key to a unique person).


However, there are also some problems connected with signatures: They possess advantages, but they cannot fulfill each and every requirement and have their own problems. Some important ones of them are:
Presentation of the data to be signed: The signature is always applied to the binary data of a document, but not to the visual representation itself. If there are differences between them (e. g. different character sets, colors, macros changing the appearance, etc.), the signed document is valid, but is not what the signatory wanted (or believed) to sign. Because of this a secure viewer is needed, which guarantees that all information is presented and that the document will always be presented in the same form, regardless when and where it is viewed.
Uniqueness of the signed document: The signed document is signed, and so the "owner" can be traced, but it is not encrypted and there is no "copy-protection" included. It can be duplicated how often it is needed and is therefore not suited for certain applications, e. g. bearer certificates or other tasks requiring a unique original. This can only be emulated with a central repository, but this is outside the scope of signatures.

Signing documents

With electronic signatures documents can be signed so everybody can check who approved their content. This is important for telework, as in this case often no version on paper exists. Such documents could therefore not be used in connection with telework. A large area of application for this is the government, where a basic requirement is that the person approving a certain document can always be traced, also for a long time in the future. But the public sector is not the only area for the use of signatures, companies employing teleworkers can also profit from them: Tracing the origin and way of processing is much easier with signatures, as they are defined according to a set standard (easier programming) and modifications are always detectable after signing (Also a possibility to avoid transmission errors).

General advantages of a public key infrastructure (PKI)

Using digital signatures will in most cases require a public key infrastructure (PGP is not suited to producing legally binding signatures; no authority guarantees for the correctness of the data). This includes that every user, who whiches to create signatures, receives a (at least one) certificate, which is commonly stored on chipcards (at least for secure signatures). But this certificate can also be used for different things than just signing documents:
Logon: The certificate is usually stored on a chipcard. So logon is possible by simply inserting the chipcard. For a more secure logon, a single signature might be required to prove, that the certificate in the card is not a copied one. The advantage here is, that the chipcard is a physical object and exists only once. If it is missing it will be detected much earlier than when a password is disclosed.
User identification: If the teleworker accesses the companys data through a website, he can be automatically identified through his certificate (no logon necessary). An example for this is SSL (Secure Socket Layer). Also the connection can be secured through encryption to prevent eavesdropping. This is a very large advantage, as problems with implementing login, distributing and changing passwords or preventing unauthorized access disappear. Another very large advantage is, that no custom or special software is needed, only a common webbrowser and a secure server is required.
Simple encryption: As in the chipcard the private key according to the certificate is stored, encryption can be used very easily: There is no need to distribute a shared secret key or special private keys. The key used for signing (or another one stored in the chipcard; better for security) can be used for agreeing on a session key. At the same time, anyone getting access to the remote computer (even to his account) of the teleworker cannot decrypt the data as he has no access to the card and the contained private key.

Publications (Overview)

Legal documents


Signature law (German)

Signature order (German)

Inofficial translation of the Signature law (English)

Inofficial translation of the Signature order (English)

Ministerial draft and Statements to it (German)

Government bill (Including annotations; German)

Report of the legislative committee (German)


Current Signature law (Art. 3 IuKDG) (German)

Proposal for amendment (German)


Both languages are authentic.

Signature directive (German)

Signature directive (English)

Materials to the signature directive



A-SIT (Zentrum für sichere Informationstechnologie - Austria / Secure Information Technology Center - Austria): Confirmation institute according to § 19 SigG

Telekom-Control (TKC)

Certification authorities


A-sign (Datakom)

TrustSign (e-Sign; A-Trust): Not accredited!

AD Cert (Arge Daten)

net.surance Security (EA Generali)

CryptoConsult (Mag. Ulrich Latzenhofer)

Globalsign (Belsign Austria; Innovation Systems Informationstechnologie GmbH): Not accredited! Should be accredited in Belgium according to the TKC.



Thawte (Now Verisign subsidiary)


Bundesamt für Sicherheit in der Informationstechnik - Projektbüro Digitale Signatur (BSI; Germany)

European Telecommunications Standards Institute - Draft on Electronic Signature Standards (ETSI)

