Showing posts with label assignments. Show all posts
Showing posts with label assignments. Show all posts

Monday, 25 September 2023

J 5/23 - Electronic Signatures are Invalid

Back in December 2021, I wrote about electronic signatures in light of the then recently published notice from the EPO about them being used as evidence for registering a transfer of rights. Before going any further, I recommend reading my previous post so you are familiar with the concept of digital/electronic signatures, if you are not already. In brief, the situation at the time was that, if a digital signature was to be used it would need to comply with fairly strict requirements to pass the test of being considered valid. It was evident at the time, as I tried to make clear, that a mark on a document that appeared to be a digital signature, but without the required certification, would not pass the test. Evidently, however, not everyone realised this and attempts were made to record assignments at the EPO with such documents. European application 21204983.7, filed in the name of Gyrus ACMI, Inc., is one such example, and appears to be the first one on this issue that has resulted in an appeal decision. 

In March 2022, the applicant's representative filed a request pursuant to Rule 22 EPC to record a transfer of rights regarding the application. The registration fee was paid and the request was accompanied by an assignment document, purportedly signed by both parties. The signature part of the assignment document as submitted to the EPO looked like this:

Both signatures were evidently not done by hand, but an indication that the document had at some stage been electronically signed was provided by a DocuSign Envelope ID at the top of the assignment document, which looked like this:
It is impossible to tell from the EP register whether the document that was submitted was in fact the electronically signed version, since these documents are resampled versions and any signatures would be stripped out. However, it is evident based on what happened next that what was submitted was merely a dumb copy without any actual digital signatures, because an objection was raised shortly afterwards by the EPO Legal Division in a communication dated 24 March 2022, stating:

"With regard to the electronic signatures attached to the Patent assignment submitted on 14 March 2022, we are unable to access the electronic certificates attached to them. We therefore cannot assess whether the signatures fulfil the requirements set out in the notice from the European Patent Office dated 22 October 2021 concerning electronic signatures on documents submitted as evidence to support requests for registration of a
transfer of rights under Rules 22 and 85 EPO and requests for registration of a licence or other rights under Rule 23 EPC (OJ EPO 2021,A86).

Your attention is therefore drawn to the definition and requirements of a qualified electronic signature provided under Article 3(12), (15), (23) Regulation (EU) No 910/2014. Please note that the qualified electronic signatures must be electronically verifiable by an accessible qualified certificate attached thereto. Only the original (digital) format of the electronically signed document allows such verification. Scanned or similarly reproduced documents do not serve this purpose.

You are therefore invited to re-submit the document in question in PDF format bearing either a verifiable electronic signatures or a handwritten signatures within two months of notification of the present communication".

Rather than going back and getting a proper digitally signed document or one with handwritten signatures, the applicant's representative argued back to the Legal Division that, because the assignment document contained text string signatures from both parties, the document should be accepted. The Legal Division disagreed, pointing out that only documents bearing qualified electronic signatures within the meaning of Regulation (EU) No 910/2014 could be accepted, according to the EPO notice of 22 October 2021. Such signatures, as pointed out by the Legal Division, "must be electronically verifiable by means of a digital qualified certificate included in the document filed. Only the original, digital format of the electronically signed document permits such verification". After some more (rather pointless) arguments from the applicant's representative, a final decision was made on 23 February 2023 to reject the request for recordal. An appeal was then filed in March 2023, arguing in part that Rule 2 EPC and the Decision of the President dated 14 May 2021 concerning the electronic filing of documents permitted assignments with text string signatures to be used for recordal purposes. 

The Board of Appeal, deciding on the papers alone, issued their decision in J 5/23 on 4 September 2023 (which, incidentally, is incredibly quick for a BoA decision). The unsurprising aspect of the decision is that the Board did not agree with the appellant that the general rules for filing documents could apply also to recordal of assignments. There was, however, a substantial sting in the tail, which is that the Board have decided that electronic signatures of any kind (qualified or otherwise) do not meet the requirements of Rule 22(1) EPC. The reasoning from the Board was in essence that the definition of the word "signature" in Article 72 EPC has not been changed to allow electronic signatures. At the time the EPC entered into force, and also according to standard dictionary definitions, the word "signature" meant something written by hand. If this were to be interpreted to also include electronic signatures, the question arose as to what kind of electronic signature could qualify within the meaning of Article 72 EPC. Given that Article 72 EPC required there to be clear and unambiguous formal requirements for the transfer of a European patent application, it would be at odds with this rationale if - without any explicit legal basis - any type of text in electronic form could be considered a signature (see point 2.4.5). In the Board's view, the Notice from the EPO concerning electronic signatures could not overrule the definition of a signature in Article 72 EPC. What would be required is agreement between the contracting states to provide an updated interpretation, which would apparently go beyond what the Administrative Council was able to do. The Board's concluding statement was the following:

"In conclusion, the Board, applying the general rule of interpretation pursuant to Article 31 VCLT to the term "signature" in Article 72 EPC, i.e. interpreting this term in good faith according to its ordinary meaning in the applicable context and taking account of the purpose of this legal provision, holds that this term - in the absence of a different definition in the Implementing Regulations (see point 2.11 below) - must be understood as referring to a handwritten depiction of someone's name, written on the assignment "contract" referred to in Article 72 EPC. In the absence of any such handwritten signature, an assignment agreement does not comply with the formal requirements under Article 72 EPC and, under Rule 22(3) EPC, has no effect vis-à-vis the EPO. It follows from Rule 22(3) EPC that it is beyond the EPO's jurisdiction whether or not such a contract, in cases of non-compliance with the requirements of Article 72 EPC, also has no effect between the parties to the contract themselves. If necessary, this question must be decided by the competent national court according to the applicable law regulating the consequences of non-compliance with formal requirements for contracts" (point 2.9, emphasis added).

The Board does then, however, go on to indicate that this might be fixed by changing the Rules:

"While under the present legal framework the term "signature" must be understood as referring to handwritten signatures only, Article 72 EPC does, as such, not prohibit the legislator of the Implementing Regulations to the EPC, i.e. the Administrative Council, from specifying the meaning of the term "signature" in the Implementing Regulations (see G 3/19, Reasons XXVI.4). Taking due account of the rationale underlying Article 72 EPC (see points 2.4.2 and 2.4.3 above), such a definition could include a reference to some form of electronic signature and still respect the boundaries set by Articles 72 and 164(2) EPC. Providing such a definition in the Implementing Regulations would then change the context in which the term "signature" in Article 72 EPC is interpreted pursuant to Article 31 VCLT (see points 2.5 to 2.5.6 above), both by the departments of the EPO and by national courts." (point 2.11)

The upshot of all this is that, not only is it now clear that a "text string" signature in an assignment document is not acceptable but, based on this decision, all types of electronic signatures are now considered invalid for the purposes of recording an assignment. As of right now, all practitioners will need to revise their advice to clients that assignments must have handwritten signatures. It looks like there are only two options available if the EPO wants digital signatures to get accepted. The first option would be to somehow overturn this decision by getting the Enlarged Board of Appeal to decide on the matter, although there is of course no guarantee that the Enlarged Board would decide in any other way. This could in any case only happen once there have been two conflicting decisions, so it would first need another case to decide the other way for the President or a Board of Appeal to kick the issue further upwards. Perhaps there is another appeal currently pending? The alternative, which may be far less appealing but which could be a quicker option, would be to get the Administrative Council to amend the Implementing Regulations to change the context in which the term "signature" is interpreted, as suggested in point 2.11 of the decision. For the time being, however, it appears that using electronic signatures for assignments are effectively dead in the water. 

Postscript: Thanks to the anonymous commenter who has pointed out the final line in the decision (pdf version). Take a look:



Friday, 17 December 2021

Digital Signatures and Digital Signing

Adding a signature to a document is fundamentally a way of providing assurance that the person whose signature it is has approved of its contents. A signature by itself is, however, not a very secure way of doing this. Handwritten signatures can be easily forged, copied or even machine written. Especially when provided in copied form, there is no definitive way of telling whether a signature on a document is genuine and actually proves that the person did in fact sign the document. 

Do these signatures look genuine?

To get more assurance, it is possible for example to get a notary to certify that a signature is genuine, the notary then being used as a trusted third party that is vouching for the signature being genuine. For further reassurance, the document itself can be protected from being altered by adding ribbon and seals, which provide assurances that the document that has been signed has not changed since being signed. Doing all this takes time and money, so in practice it is often taken on trust that a signed document is genuine. For documents relating to patent proceedings at the European Patent Office, the UK IPO and elsewhere, the office will accept a copy of a signed document and assume that it is genuine, the assumption being that the document was originally hand signed and then copied, provided it looks real. 

How can you tell this signature is genuine?
The process of using copies of genuine handwritten signatures and filing these online in pdf form at the EPO, typically to register an assignment, is standard practice and usually works without any trouble, provided the formal requirements of being able to identify the assignor and assignee are met and that duly authorised representatives of both parties have signed. I have personally arranged to have many assignments recorded at both offices this way with no trouble, even though in many cases I did not and could not verify myself that the signatures were genuine. Over the past couple of years, however, as personal contact has become the exception, there has been more interest in the use of digital signatures. The problem at the moment is that many people still do not actually know what one is, let alone how to properly use one. 

At risk of stating what should be the obvious, a digital signature is not something that is written by hand or pasted on a computer screen that looks like one written by hand on a piece of paper. It should be clear that this type of signature is far too easy to fake. If spotted, such signatures should be (and often are) rejected. Even if you sign by hand your actual signature on a computer screen, the proof that it was you is non-existent because anyone else could have done the same by copying and pasting an image of your signature from somewhere else, the result being indistinguishable. 

A real digital signature is something quite different. A digital signature, if done correctly, performs all the original functions of a genuine original handwritten signature but without the need for an authenticated paper copy. To work, a digital signature must be kept in its original form along with the document it is supposed to be authenticating. Without the code making up the digital signature, in combination with the original document, the signature is meaningless because it cannot be verified, defeating its whole purpose. A common confusion I have seen is when a scanned pdf is presented with what seems to be a digital signature, but the process of scanning has stripped it out, leaving only a mark on a computer file that suggests it was signed. This is, of course, useless and not even as good as a scanned copy of a handwritten signature.

To go back to basics, digital signing at its heart involves asymmetric cryptography. A user who wants to sign something will have a private key, which they keep to themselves, and a public key, which is open for all to see. The user can apply their private key to a document (or, in practice, a hash of a document) to produce a signature string. Anyone else can then use the combination of the document, signature and public key to cryptographically prove that the user's private key was used to sign the document. The signature therefore proves that the document was signed by the user. The only assumption made is that nobody else had access to the user's private key. It is fundamental to the ability to verify the signature that the document and signature are kept together and in their original state. If either is altered by even one single bit, the signature will not validate. 

An example of digital signing I have used before relates to how the Bitcoin system works. Bitcoin addresses (P2PKH types) are representations of the public key part of a public-private key pair. The owner of the bitcoin associated with an address is in possession of the private key and therefore only they are capable of 'spending' the bitcoin. In practice, transferring ownership from one address to another involves a process of digital signing, in which the owner signs a transaction with their private key to the effect that only the owner of the private key of the recipient address can then do any further transactions with whatever is sent to that address. Since all transactions are publicly available, anyone can verify how much any particular address contains. Another feature is that the owner of an address can verify that they own it by digitally signing a message linked to the address. An example I have used before is the following:

I, Tufty Sylvestris, confirm that I am the owner of the following address.

bc1quklwszfchvfzpxa7wk8pge7ykczcg0pv54wc8a

IA0TdtltWrzK62rDVw/WkZ36hNOGshhw8UFXySK7VFY9Nv5mQWr6B3aXpDpFH15gPH7uUJsPzlLB/T+eKkXjMWo=

To go back to the principle of signing documents, the message part corresponds to the document. The message is signed with the private key corresponding to the address, resulting in the signature string. Anyone can then verify that the signature is genuine by copying these components into a signature verifying tool, such as the one provided within the Electrum Bitcoin wallet, or one available online. You do, however, have to be very careful that the tool you are using for verification is not in some way compromised or you could be easily fooled

An additional problem with using just a public-private key pair is that you do not necessarily have a link between the owner of the private key and a specific person unless you have some other way of figuring out who the owner of the private key is. To take a well known example, the owner of the private key to address 12c6DSiU4Rq3P4ZxziKxzrL5LmMBrzjrJX is, beyond any reasonable doubt, the person who was behind the pseudonym Satoshi Nakamoto because this address was the destination for the very first 50 (spendable) bitcoin that were mined on 9 January 2009. 

For any normal use, it is necessary to provide a link between a private key and an actual person. A usual way to do this is for private keys for use in digital signing to be issued and certified by trusted authorities. For the EPO, this is done by a user's private key being securely stored on a smart card issued by the EPO to a patent attorney together with a PIN. With possession of the PIN and the smart card, the attorney can sign a document to the satisfaction of the EPO. Documents can only be signed with physical possession of the card and knowledge of the PIN, providing a decent level of security. This works very well for everyday activities of an EP attorney, who can use their smart card to digitally sign documents that are sent online to the EPO. The same principle can also be used to sign any documents. I can, for example, take any pdf document and apply a digital signature from my smart card that proves I signed the document. The document with its signature attached could then be sent to someone who wanted evidence that I signed it and they would be able to verify with a single click that the signature was valid.

The EPO has recently announced, in the November 2021 issue of the Official Journal, that "a qualified electronic signature" will be "considered to fulfil the legal requirement for a signature with respect to data in electronic form in the same way that a handwritten signature does with respect to data on paper". On the face of it, this seems quite straightforward. Provided the digital signature can be verified, the EPO will accept it. Clearly a signature produced using an EPO-issued smart card will work. Other signatures should also work, such as those issued by Docusign, which are increasingly common. The key, however, is that it must be possible to verify the signature. As a patent attorney, if I am asked whether something will qualify to be used in support of, for example, a request to record an assignment, the answer should be simple. If I can verify it myself, it should be ok. If I am presented with a copied pdf with a stamp stating that it has been digitally signed, the answer is of course no. 

Another feature of the new rule is that, as I know from recent personal experience, documents that have been signed on screen and passed off as handwritten signatures are now more likely to be rejected. Under the new provisions, before trying to record an assignment that looks like it might have been signed on a screen rather than by hand, ask yourself whether it looks like it meets the requirements and, if not, go back to your client and ask how the document was signed.