Meaning
Administrative procedures for the generation, storage and destruction of digital signing credentials ensure the integrity of corporate electronic seals used in cross-border trade. Effective cryptographic key management governs the lifecycle of the private keys used to authenticate electronic contracts under the PRC Electronic Signature Law. It stops applying when keys are compromised through physical theft or when the underlying encryption algorithm is deemed obsolete by the State Cryptography Administration.
Within a corporate structure, these procedures prevent the unauthorized use of the digital identity of the company by junior employees or external agents.
Security Protocol
Generation of a private key must occur within a secure environment such as a hardware security module or a certified smart card. This cryptographic key management step ensures that the key material never exists in an unencrypted state on a general-purpose computer. Access to the signing environment is restricted to authorized personnel who have undergone background checks and have been assigned specific roles.
Multi-party authorization often requires two different individuals to present their credentials before a high-value signature can be generated. This prevents a single point of failure within the administrative chain. The physical storage of the hardware must be logged and monitored to detect any unauthorized access attempt.
When a key reaches the end of its designated life, the system must overwrite the storage media several times to prevent recovery.
Administrative Oversight
The State Cryptography Administration sets the standards for the commercial use of encryption within the borders of China. Companies must ensure that their cryptographic key management practices align with the requirements for the protection of state secrets and commercial data. This involves regular audits of the key logs to ensure that every signature can be traced back to a specific user and a specific time.
If a company uses a third-party certificate authority, the responsibility for key safety remains with the end user. The administration has the power to inspect the facilities where keys are managed and to demand the revocation of certificates if security breaches are discovered. Failure to maintain these standards can lead to the invalidation of all contracts signed during the period of non-compliance.
Regulatory Compliance
Filing requirements for cryptographic products used in China demand that foreign entities declare the type and purpose of their encryption systems. Cryptographic key management for these entities often involves using locally certified hardware to ensure compatibility with the national public key infrastructure. This ensures that the electronic seals are recognized by government platforms such as the National Enterprise Credit Information Publicity System.
During an audit, the company must demonstrate that it has a recovery plan in case keys are lost or destroyed. This plan must not include any backdoor that would allow unauthorized third parties to access the private key. The boundary of this requirement is set by the Cybersecurity Law, which protects the privacy of data while demanding cooperation for national security.
Evidence of proper management provides a defense in cases where a party claims that its digital seal was used without authorization. Courts look for a documented chain of custody and a log of all signing events to determine the liability of the corporation. A robust system reduces the risk of repudiation in commercial disputes.