For the purposes of sections 28.600 to 28.678, unless the context expressly indicates otherwise, the following terms shall mean:
(1) "Accept a certificate":
- (a) To manifest approval of a certificate, while knowing or having notice of its contents; or
- (b) To apply to a licensed certification authority for a certificate, without canceling or revoking the application, if the certification authority subsequently issues a certificate based on the application;
- (2) "Asymmetric cryptosystem", an algorithm or series of algorithms which provide a secure key pair;
(3) "Certificate", a computer-based record which:
- (a) Identifies the certification authority issuing it;
- (b) Names or identifies its subscriber;
- (c) Contains the subscriber's public key; and
- (d) Is digitally signed by the certification authority issuing it;
- (4) "Certification authority", a person who issues a certificate;
- (5) "Certification authority disclosure record", an on-line, publicly accessible record which concerns a licensed certification authority and is kept by the division. A certification authority disclosure record has the contents specified by rule of the division pursuant to section 28.609;
- (6) "Certification practice statement", a declaration of the practices which a certification authority employs in issuing certificates generally, or employs in issuing a material certificate;
- (7) "Certify", the declaration of material facts by the certification authority regarding a certificate;
- (8) "Confirm", to ascertain through appropriate inquiry and investigation;
- (9) "Correspond", with reference to keys, to belong to the same key pair;
(10) "Digital signature", a transformation of a message using an asymmetric cryptosystem such that a person having the initial message and the signer's public key can accurately determine whether:
- (a) The transformation was created using the private key that corresponds to the signer's public key; and
- (b) The message has been altered since the transformation was made;
- (11) "Division", the commissions division of the office of secretary of state for the state of Missouri;
(12) "Forge a digital signature", either:
- (a) To create a digital signature without the authorization of the rightful holder of the private key; or
(b) To create a digital signature verifiable by a certificate listing as subscriber a person who either:
- a. Does not exist; or
- b. Does not hold the private key corresponding to the public key listed in the certificate;
- (13) "Hold a private key", to be able to use a private key;
- (14) "Incorporate by reference", to make one message a part of another message by identifying the message to be incorporated and expressing the intention that it be incorporated;
- (15) "Issue a certificate", the acts of a certification authority in creating a certificate and notifying the subscriber listed in the certificate of the contents of the certificate;
- (16) "Key pair", a private key and its corresponding public key in an asymmetric cryptosystem, keys which have the property that the public key can verify a digital signature that the private key creates;
- (17) "Licensed certification authority", a certification authority to whom a license has been issued by the division and whose license is in effect;
- (18) "Message", a digital representation of information;
- (19) "Notify", to communicate a fact to another person in a manner reasonably likely under the circumstances to impart knowledge of the information to the other person;
(20) "Operative personnel", one or more natural persons acting as a certification authority or its agent, or in the employment of or under contract with a certification authority, and who have:
- (a) Managerial or policy-making responsibilities for the certification authority; or
- (b) Duties directly involving the issuance of certificates, creation of private keys, or administration of a certification authority's computing facilities;
- (21) "Person", a human being or any organization capable of signing a document, either legally or as a matter of fact;
- (22) "Private key", the key of a key pair used to create a digital signature;
- (23) "Public key", the key of a key pair used to verify a digital signature;
- (24) "Publish", to record or file in a repository;
- (25) "Qualified right to payment", an award of damages against a licensed certification authority by a court having jurisdiction over the certification authority in a civil action for violation of sections 28.600 to 28.678;
- (26) "Recipient", a person who receives or has a digital signature and is in a position to rely on it;
- (27) "Recognized repository", a repository recognized by the division pursuant to section 28.672;
- (28) "Recommended reliance limit", the limitation on the monetary amount recommended for reliance on a certificate pursuant to subsection 1 of section 28.648;
- (29) "Repository", a system for storing and retrieving certificates and other information relevant to digital signatures;
- (30) "Revoke a certificate", to make a certificate ineffective permanently from a specified time forward. Revocation is effected by notation or inclusion in a set of revoked certificates, and does not imply that a revoked certificate is destroyed or made illegible;
(31) "Rightfully hold a private key", to be authorized to use a private key:
- (a) Which the holder or the holder's agents have not disclosed to any person in violation of subsection 1 of section 28.636; and
- (b) Which the holder has not obtained through theft, deceit, eavesdropping or other unlawful means;
- (32) "Signer", a person who creates a digital signature for a message;
(33) "Subscriber", a person who:
- (a) Is the subject listed in a certificate;
- (b) Accepts the certificate; and
- (c) Holds a private key which corresponds to a public key listed in that certificate;
(34)
(a) "Suitable guaranty", either a surety bond executed by a surety authorized by the department of insurance to do business in this state, or an irrevocable letter of credit issued by a financial institution authorized to do business in this state by the division of finance or division of credit unions in the department of economic development, which, in either event, satisfies all of the following requirements, that it:
- a. Is issued payable to the division for the benefit of persons holding qualified rights of payment against the licensed certification authority named as the principal of the bond or customer of the letter of credit;
- b. Is in an amount specified by rule of the division pursuant to section 28.609;
- c. States that it is issued for filing pursuant to the provisions of sections 28.600 to 28.678;
- d. Specifies a term of effectiveness extending at least as long as the term of the license to be issued to the certification authority; and
- e. Is in a form prescribed by rule of the division;
- (b) A suitable guaranty may also provide that the total annual liability on the guaranty to all persons making claims based on it may not exceed the face amount of the guaranty;
- (c) A financial institution acting as a certification authority may satisfy the requirements of this subdivision* from its assets or capital, to the extent of its lending limit as provided by law;
- (35) "Suspend a certificate", to make a certificate ineffective temporarily from a specified time forward;
(36) "Time-stamp", either:
- (a) To append or attach to a message, digital signature or certificate a digitally signed notation indicating at least the date and time the notation was appended or attached, and the identity of the person appending or attaching the notation; or
- (b) The notation thus appended or attached;
- (37) "Transactional certificate", a valid certificate incorporating by reference one or more digital signatures;
(38) "Trustworthy system", computer hardware and software which:
- (a) Are reasonably secure from intrusion and misuse;
- (b) Provide a reasonable level of availability, reliability and correct operation; and
- (c) Are reasonably suited to performing their intended functions;
(39)
(a) "Valid certificate", a certificate which:
- a. A licensed certification authority has issued;
- b. The subscriber listed in it has accepted;
- c. Has not been revoked or suspended; and
- d. Has not expired;
- (b) A "transactional certificate" is a valid certificate only in relation to the digital signature incorporated in it by reference;
(40) "Verify a digital signature", in relation to a given digital signature, message and public key, to determine accurately that:
- (a) The digital signature was created by the private key corresponding to the public key; and
- (b) The message has not been altered since its digital signature was created.
(L. 1998 S.B. 680 § 3)
* Word "subsection" appears in original rolls.