21 Code For Federal Regulation Parts 1305, 1311 Page 57

ADVERTISEMENT

Public key means the key of a key pair that is used to verify a digital signature. The
public key is made available to anyone who will receive digitally signed messages from the
holder of the key pair.
Public Key Infrastructure (PKI) means a structure under which a Certification Authority
verifies the identity of applicants, issues, renews, and revokes digital certificates, maintains a
registry of public keys, and maintains an up-to-date Certificate Revocation List.
§ 1311.05 Standards for technologies for electronic transmission of orders.
(a) A registrant or a person with power of attorney to sign orders for Schedule I and II
controlled substances may use any technology to sign and electronically transmit orders if the
technology provides all of the following:
(1) Authentication: The system must enable a recipient to positively verify the signer
without direct communication with the signer and subsequently demonstrate to a third party, if
needed, that the sender’s identity was properly verified.
(2) Nonrepudiation: The system must ensure that strong and substantial evidence is
available to the recipient of the sender’s identity, sufficient to prevent the sender from
successfully denying having sent the data. This criterion includes the ability of a third party to
verify the origin of the document.
(3) Message integrity: The system must ensure that the recipient, or a third party, can
determine whether the contents of the document have been altered during transmission or after
receipt.
(b) DEA has identified the following means of electronically signing and transmitting
order forms as meeting all of the standards set forth in paragraph (a) of this section.
(1) Digital signatures using Public Key Infrastructure (PKI) technology.
57

ADVERTISEMENT

00 votes

Related Articles

Related forms

Related Categories

Parent category: Legal