Digital Postmarks
   HOME

TheInfoList



OR:

A Digital Postmark (DPM) is a technology that applies a trusted time stamp issued by a
postal operator This is a list of postal entities by country. It includes: *The governmental authority responsible for postal matters. *The regulatory authority for the postal sector. Postal regulation may include the establishment of postal policies, postal rate ...
to an electronic document, validates electronic signatures, and stores and archives all
non-repudiation Non-repudiation refers to a situation where a statement's author cannot successfully dispute its authorship or the validity of an associated contract. The term is often seen in a legal setting when the authenticity of a signature is being challenged ...
data needed to support a potential court challenge. It guarantees the certainty of date and time of the postmarking. This global standard was renamed the Electronic Postal Certification Mark (EPCM) in 2007 shortly after a new iteration of the technology was developed by
Microsoft Microsoft Corporation is an American multinational technology corporation producing computer software, consumer electronics, personal computers, and related services headquartered at the Microsoft Redmond campus located in Redmond, Washing ...
and Poste Italiane. The key addition to the traditional postmarking technology was integrity of the electronically postmarked item, meaning any kind of falsification and tampering will be easily and definitely detected. Additionally, content confidentiality is guaranteed since document certification is carried out without access or reading by the postal operator. The EPCM will eventually be available through the UPU to all international
postal operators This is a list of postal entities by country. It includes: *The governmental authority responsible for postal matters. *The regulatory authority for the postal sector. Postal regulation may include the establishment of postal policies, postal rate ...
in the 191 member countries willing to be compliant with this standard, thus granting interoperability in certified communications between postal operators. In the United States, the
US Postal Service The United States Postal Service (USPS), also known as the Post Office, U.S. Mail, or Postal Service, is an independent agency of the executive branch of the United States federal government responsible for providing postal service in the U ...
operates a non-global standard called the Electronic Postmark, although it is soon expected to provide services utilizing the EPCM.


Providers

In the United States, until the end of 2010, Authentidate was the only authorized USPS EPM provider. However, this contract was allowed to expire.


The process

*An
electronic document An electronic document is any electronic media content (other than computer programs or system files) that is intended to be used in either an electronic form or as printed output. Originally, any computer data were considered as something inter ...
is created *Digital Postmarking
client software In computing, a client is a piece of computer hardware or software that accesses a service made available by a server as part of the client–server model of computer networks. The server is often (but not always) on another computer system, in ...
signs the document locally *The signed document is sent to the Digital Postmarking (DPM) service for
postmark A postmark is a postal marking made on an envelope, parcel, postcard or the like, indicating the place, date and time that the item was delivered into the care of a postal service, or sometimes indicating where and when received or in transit. ...
ing *Upon receipt, the DPM service first validates the authenticity of the signature *If the signature is valid then a timestamp is generated by the DPM service as a counter-signature that includes the date and time *The document, signature, validation results and timestamp are stored in the Digital Postmark
non-repudiation Non-repudiation refers to a situation where a statement's author cannot successfully dispute its authorship or the validity of an associated contract. The term is often seen in a legal setting when the authenticity of a signature is being challenged ...
database *A Digital Postmark Receipt, including the validation results and the timestamp, is returned to the client software *The client software wraps the original document with the DPM receipt *To verify the signature, local
cryptographic Cryptography, or cryptology (from grc, , translit=kryptós "hidden, secret"; and ''graphein'', "to write", or '' -logia'', "study", respectively), is the practice and study of techniques for secure communication in the presence of adve ...
verification can do a quick check of integrity or the full receipt or even the original document can be retrieved from the DPM service using the
XML Extensible Markup Language (XML) is a markup language and file format for storing, transmitting, and reconstructing arbitrary data. It defines a set of rules for encoding documents in a format that is both human-readable and machine-readable. T ...
Verify request by other parties at a later date and compared with the receipt stored with the document.


Benefits of digital postmarks

The DPM is fundamentally a
non-repudiation Non-repudiation refers to a situation where a statement's author cannot successfully dispute its authorship or the validity of an associated contract. The term is often seen in a legal setting when the authenticity of a signature is being challenged ...
service supporting designed to protect the sanctity of mail in its digital form: *
Digital signature A digital signature is a mathematical scheme for verifying the authenticity of digital messages or documents. A valid digital signature, where the prerequisites are satisfied, gives a recipient very high confidence that the message was created b ...
verification * Timestamping of successfully verified signatures * Standalone timestamping *
Encryption In cryptography, encryption is the process of encoding information. This process converts the original representation of the information, known as plaintext, into an alternative form known as ciphertext. Ideally, only authorized parties can decip ...
* Validation of certificate trust chains * Storage and archival of all non-repudiation evidence data required to support subsequent challenges * Legal significance. In addition to federal and state legislative frameworks, the DPM holds legal weight with respect to the following legislation, which have been established to encourage people to form and sign contracts and agreements electronically: ** Government Paperwork Elimination Act (GPEA), 1998 ** Uniform Electronic Transaction Act (UETA), 1999 ** Electronic Signatures in Global and National Commerce Act (ESIGN), 2000 Working with current infrastructure, it is easy to implement - providing functionality even with no client-side software, and provides automated functionality with client software.


Additional benefits

*Proactive differentiation "good" email from
spam Spam may refer to: * Spam (food), a canned pork meat product * Spamming, unsolicited or undesired electronic messages ** Email spam, unsolicited, undesired, or illegal email messages ** Messaging spam, spam targeting users of instant messaging ( ...
and
phishing Phishing is a type of social engineering where an attacker sends a fraudulent (e.g., spoofed, fake, or otherwise deceptive) message designed to trick a person into revealing sensitive information to the attacker or to deploy malicious softwar ...
. *Improved service quality by applying the same standards that govern physical mail to
email Electronic mail (email or e-mail) is a method of exchanging messages ("mail") between people using electronic devices. Email was thus conceived as the electronic ( digital) version of, or counterpart to, mail, at a time when "mail" meant ...
. *Stronger authentication than other standards such as (
Sender ID Sender ID is an historic anti- spoofing proposal from the former MARID IETF working group that tried to join Sender Policy Framework (SPF) and Caller ID. Sender ID is defined primarily in Experimental RFC 4406, but there are additional parts in RFC ...
and
DKIM DomainKeys Identified Mail (DKIM) is an email authentication method designed to detect forged sender addresses in email (email spoofing), a technique often used in phishing and email spam. DKIM allows the receiver to check that an email claimed ...
). *Compliance with all federal laws and regulations. *
Postal operator This is a list of postal entities by country. It includes: *The governmental authority responsible for postal matters. *The regulatory authority for the postal sector. Postal regulation may include the establishment of postal policies, postal rate ...
enforcement: Mail fraud is virtually non-existent with physical mail due to the legal framework and the vigorous efforts of the U.S. Postal Inspection Service. Digital Postmarks have the same
legal recourse A legal recourse is an action that can be taken by an individual or a corporation to attempt to remedy a legal difficulty. * A lawsuit if the issue is a matter of civil law * Contracts that require mediation or arbitration before a dispute can go ...
for email fraud as for physical
mail fraud Mail fraud and wire fraud are terms used in the United States to describe the use of a physical or electronic mail system to defraud another, and are federal crimes there. Jurisdiction is claimed by the federal government if the illegal activit ...
. *Significant mailing cost reduction to only a few cents.


Applicable services

The Digital Postmark can be used for a variety of business applications: *signing Web forms and documents *delivery of secure documents *interpersonal messaging


Brief history

Key dates in the development of the digital postmark:The Digital Postmark: Security for Cyberspace Mail
/ref> ;1998–1999 *The
USPS The United States Postal Service (USPS), also known as the Post Office, U.S. Mail, or Postal Service, is an independent agency of the executive branch of the United States federal government responsible for providing postal service in the U. ...
and
Canada Post Canada Post Corporation (french: Société canadienne des postes), trading as Canada Post (french: Postes Canada), is a Crown corporation that functions as the primary postal operator in Canada. Originally known as Royal Mail Canada (the opera ...
develop the first digital postmark. ;1999 *The UPU Standards Board begins the process to develop a global technical standard ( S43) for the digital postmark. ;2001 *A workshop hosted by USPS decides on a consistent visual image for digital postmarks offered by Posts. ;2002 *USPS launches its digital postmark, the "Electronic Postmark". Development work on the S43 standard is completed. Microsoft agrees to define and produce an interface in W2000/XP and Office 2000 and XP 2003 to support the digital postmark. ;2003 *The UPU Standards Board formally adopts the S43 standard
See article)
. ** It defined a technical standard – "S43 - Electronic PostMark Interface" – which was approved by the UPU Standards Board in November 2003 as a technical standard for the postal industry. *Portugal’s postal service launches a legally recognized digital postmarks service. ;2004 *The UPU Congress adopts a proposal to amend the UPU Convention to legally define the digital postmark, formally recognizing it as a new optional
postal service The mail or post is a system for physically transporting postcards, letters, and parcels. A postal service can be private or public, though many governments place restrictions on private systems. Since the mid-19th century, national postal syst ...
. *September: The UPU Legally Defined the EPM as a ''Postal Service''
See article)
** This makes the EPM an optional postal service for UPU member countries, placing the EPM in the same category as
Express Mail Express mail is an expedited mail delivery service for which the customer pays a premium for faster delivery. Express mail is a service for domestic and international mail, and is in most nations governed by the country's own postal administration ...
. ** The UPU definition provides international technological and enforcemen
standards
. ;2005 *Adobe agrees to support the inclusion of the digital postmark. *La Poste France develops an S43-based digital postmark server. It is used as early as 2006. ;2006 *The UPU Standards Board approves version 3 of the standard S43, the first to enable cross-border and global traffic using digital postmarks. *January: The UPU Approved a DPM Regulation

This regulation was passed as an amendment with the letter mail regulation. ** Every postal service has a UPU regulation that manages the service and regulates how the posts will cooperate in that service. This makes it easier to assist member countries in developing the market for worldwide digital postmark services. ** This DPM Regulation has dramatically increased interest in the EPM worldwide. * Poste Italiane develops a plug-in to enable Microsoft Office users to connect to a backend server, which delivers digital postmarks that comply with the UPU’s S43 technical standard. ;2007 *April: The UPU Approved the renaming of Digital postmark to Electronic Postal Certification Mark EPCM


Global usage

Recognizing the great potential of the Digital Postmark, numerous
postal administration This is a list of postal entities by country. It includes: *The governmental authority responsible for postal matters. *The regulatory authority for the postal sector. Postal regulation may include the establishment of postal policies, postal rate ...
s worldwide have begun deploying DPM-based solutions. Five postal services – ''Canada, France, Italy, Portugal and the United States'' – have developed their own digital postmark and use it today. Major software developers are also working to incorporate the global standard into popular applications used by millions of people worldwide. *
United States The United States of America (U.S.A. or USA), commonly known as the United States (U.S. or US) or America, is a country primarily located in North America. It consists of 50 states, a federal district, five major unincorporated territorie ...
''(first launched EPM in 1996; current EPM released March 2003)'' *
France France (), officially the French Republic ( ), is a country primarily located in Western Europe. It also comprises of Overseas France, overseas regions and territories in the Americas and the Atlantic Ocean, Atlantic, Pacific Ocean, Pac ...
''(first launch in 1999)'' *
Canada Canada is a country in North America. Its ten provinces and three territories extend from the Atlantic Ocean to the Pacific Ocean and northward into the Arctic Ocean, covering over , making it the world's second-largest country by tot ...
''(launched 1st quarter 2003)'' *
Portugal Portugal, officially the Portuguese Republic ( pt, República Portuguesa, links=yes ), is a country whose mainland is located on the Iberian Peninsula of Southwestern Europe, and whose territory also includes the Atlantic archipelagos of ...
''(launched September 2003)'' *
Italy Italy ( it, Italia ), officially the Italian Republic, ) or the Republic of Italy, is a country in Southern Europe. It is located in the middle of the Mediterranean Sea, and its territory largely coincides with the homonymous geographical re ...
''(launched 2005 by Poste Italiane as Posteitaliane.mail, now Posteitaliane.post)'' *
Egypt Egypt ( ar, مصر , ), officially the Arab Republic of Egypt, is a transcontinental country spanning the northeast corner of Africa and southwest corner of Asia via a land bridge formed by the Sinai Peninsula. It is bordered by the Mediter ...
''(contracted with provider 1st quarter 2005)'' *
Switzerland ). Swiss law does not designate a ''capital'' as such, but the federal parliament and government are installed in Bern, while other federal institutions, such as the federal courts, are in other cities (Bellinzona, Lausanne, Luzern, Neuchâtel ...
''(contracted with provider July 2005)'' *
Brazil Brazil ( pt, Brasil; ), officially the Federative Republic of Brazil (Portuguese: ), is the largest country in both South America and Latin America. At and with over 217 million people, Brazil is the world's fifth-largest country by area ...
''(contracted with provider 2004)'' *
China China, officially the People's Republic of China (PRC), is a country in East Asia. It is the world's most populous country, with a population exceeding 1.4 billion, slightly ahead of India. China spans the equivalent of five time zones and ...
''(preparing to launch)'' *
Netherlands ) , anthem = ( en, "William of Nassau") , image_map = , map_caption = , subdivision_type = Sovereign state , subdivision_name = Kingdom of the Netherlands , established_title = Before independence , established_date = Spanish Netherl ...
''(preparing to launch)'' *
United Kingdom The United Kingdom of Great Britain and Northern Ireland, commonly known as the United Kingdom (UK) or Britain, is a country in Europe, off the north-western coast of the continental mainland. It comprises England, Scotland, Wales and North ...
''(preparing to launch)'' The
Universal Postal Union The Universal Postal Union (UPU, french: link=no, Union postale universelle), established by the Treaty of Bern of 1874, is a specialized agency of the United Nations (UN) that coordinates postal policies among member nations, in addition to t ...
(UPU) has identified trust services as the greatest opportunity for global postal growth. Specifically, they identified the Digital Postmark as the most important trust service; providing an excellent defense against online fraud and abuse.{{citation needed, date=June 2021


Electronic postmarks

The
United States Postal Service The United States Postal Service (USPS), also known as the Post Office, U.S. Mail, or Postal Service, is an independent agency of the executive branch of the United States federal government responsible for providing postal service in the U ...
(USPS) Electronic Postmark (EPM''©'') is a proprietary variation of the Digital Postmark issued by the USPS. It was introduced in 1996 by the U.S. Postal Service as a service offering that provides proof of integrity and authentication for electronic transactions. Through the USPS EPM web-based service, any third-party can verify the authenticity of electronic content. This electronic proof, postmarked by the Postal Service, provides evidence to support non-repudiation of electronic transactions. The EPM is designed to deter and detect the fraudulent tampering or altering of electronic data.


Key features

The USPS wrote that the key features of their Electronic Postmark are: *Content authentication web-based service (based upon
American Bar Association The American Bar Association (ABA) is a voluntary bar association of lawyers and law students, which is not specific to any jurisdiction in the United States. Founded in 1878, the ABA's most important stated activities are the setting of acad ...
br>PKI Guidelines)
proves document authenticity and timestamp accuracy to detect and prevent fraud. *Integrates easily into existing applications with standard-based interfaces. *Verify options include; local (''self contained'') & centralized (''Internet based''). *Verification is free. *128 Bit SSL encryption insuring privacy and security of communications. *Data stays private. Service never has access to your content and requires no modification or transmission of content. (only a hash code of the file is logged as evidence of authenticity.)


US legal environment

The USPS listed laws relevant to EPM as follows: *18 U.S.C. §1343
Wire Fraud Mail fraud and wire fraud are terms used in the United States to describe the use of a physical or electronic mail system to fraud, defraud another, and are Federal crime in the United States, federal crimes there. Jurisdiction is claimed by the ...
*18 U.S.C. §2701
Electronic Communications Privacy Act Electronic Communications Privacy Act of 1986 (ECPA) was enacted by the United States Congress to extend restrictions on government wire taps of telephone calls to include transmissions of electronic data by computer ( ''et seq.''), added new pro ...
(ECPA) *18 U.S.C. §2510 regarding electronic communications. Definitions (17)Electronic storage means **(A) any temporary, intermediate storage of a wire or electronic communication incident to the electronic transmission thereof **(B) any storage of such communication by an electronic communication service for purposes of backup protection of such communication. *18 U.S.C. §2710 regarding unlawful access to stored electronic communications *18 U.S.C. §1028, Fraud and related activity in connection with identification documents and information *18 U.S.C. §1029, Fraud and related activity in connection with access devices.United States Postal Service. (2006). ''Benefits of EPM''
USPS Benefits of EPM website
/ref>


Additional


Other definitions

A ''Digital Postmark'' (DPM) is also a
network security Network security consists of the policies, policies, processes and practices adopted to prevent, detect and monitor unauthorized access, Abuse, misuse, modification, or denial of a computer network and network-accessible resources. Network securi ...
mechanism, developed by
Penn State #Redirect Pennsylvania State University The Pennsylvania State University (Penn State or PSU) is a Public university, public Commonwealth System of Higher Education, state-related Land-grant university, land-grant research university with campu ...
researchers Ihab Hamadeh and George Kesidis, to identify which region a packet or a set of packets comes from. It was developed as a way to combat
spam Spam may refer to: * Spam (food), a canned pork meat product * Spamming, unsolicited or undesired electronic messages ** Email spam, unsolicited, undesired, or illegal email messages ** Messaging spam, spam targeting users of instant messaging ( ...
and
denial-of-service In computing, a denial-of-service attack (DoS attack) is a cyber-attack in which the perpetrator seeks to make a machine or network resource unavailable to its intended users by temporarily or indefinitely disrupting services of a host connect ...
(
virus A virus is a submicroscopic infectious agent that replicates only inside the living cells of an organism. Viruses infect all life forms, from animals and plants to microorganisms, including bacteria and archaea. Since Dmitri Ivanovsky's 1 ...
) attacks by isolating the source of such attacks, while still allowing "good" messages to pass through. A digital postmark works when a perimeter router marks up a packet border with its region-identifying data. Also called a " border router packet marking", it uses an obsolete or unused portion of the packet to place the regional mark-up. When room does not exist in any one portion of the packet, the region information can be broken up and hashed in a subsequently retrievable way.


See also

*
Trusted timestamping Trusted timestamping is the process of securely keeping track of the creation and modification time of a document. Security here means that no one—not even the owner of the document—should be able to change it once it has been recorded provide ...
*
UPU Upu or Apu, also rendered as Aba/Apa/Apina/Ubi/Upi, was the region surrounding Damascus of the 1350 BC Amarna letters. Damascus was named ''Dimašqu'' / ''Dimasqu'' / etc. (for example, "Dimaški"-(see: Niya (kingdom)), in the letter correspon ...
*
USPS The United States Postal Service (USPS), also known as the Post Office, U.S. Mail, or Postal Service, is an independent agency of the executive branch of the United States federal government responsible for providing postal service in the U. ...


References


External links


USPS Electronic Postmark PageUSPS EPM siteUniversal Postal Union homepagePurchase UPU S43-3 StandardUniversal Postal Union - Postal Technology CenterUSPS Glossary of Postal Terms (Publication 32)Worldwide Postal Network in Figures, October 2006Article: New marking process traces spammers, pirates and hackersETSI Specialist Task Force 318: Registered Emails
Postal systems Postal markings Computer network security