Certified email explained

Certified email (known as Posta elettronica certificata in Italy, or PEC in short) is a special type of email in use in Italy,[1] Switzerland,[2] Hong Kong[3] and Germany.[4] Certified email is meant to provide a legal equivalent of the traditional registered mail, where users are able to legally prove that a given email has been sent and received by paying a small fee.

Registered mail is mainly used in Italy,[5] but there are present efforts to extend its legal validity according to the framework of the European Union.[6]

Description

A certified email can only be sent using a special Certified Email Account provided by a registered provider.When a certified email is sent, the sender's provider will release a receipt of the successful (or failed) transaction. This receipt has legal value and it includes precise information about the time the certified email was sent.Similarly, the receiver's provider will deliver the message in the appropriate certified email account and will then release to the sender a receipt of successful (or failed) delivery, indicating on this receipt the exact time of delivery.If either of these two receipts are lost by the sender, providers are required to issue a proof of transaction with equal legal validity, if this proof is requested within 30 months of delivery.

In terms of user experience, a certified email account is very similar to a normal email account.The only additional features are the receipts, received as attachments, providing details and timestamps for all transactions.A certified email account can only handle certified email and cannot be used to send regular email.

Technical process

The development of this email service has conceptual variations that are dominated by two-party scenarios with only one sender and one receiver as well as a trusted third party (TTP) serving as a mediator. As in traditional registered mail, many certified email technologies call for the parties involved to trust the TTP, or the "postman", because it has the capacity to reveal the identity of the sender to the recipient once the protocol is initiated.[7] There are, however, some applications based on multi-party email protocols; these include the technology originally proposed by Markowitch and Kremer, that involves an online or offline TTP in addition to the sender and receiver.[8] There is also a multi-party version, wherein a user can send the same email to multiple recipients. In this system, those who acknowledge the receipt are able to view the data. Some applications also offer add-in features, such as the integration of the concept of timeliness, wherein a participant to the process can terminate a session in finite time in order to avoid waiting for a reply forever.[9]

The mediation of a trusted third party (TTP) requires both parties, the sender and the recipient, to come to terms in approving who will be the mediator. In compliance scenarios, where a regulation may simply require a party to deliver a notice to a given recipient and be able to prove having done so (i.e. GDPR), the role of a TTP can be trusted to an electronic registered delivery service capable to secure timestamped evidence of the contents and delivery of the electronic message, without the recipient's intervention.[10]

Certified email in Italy

The Italian certified email (Posta elettronica certificata, PEC) was established in 2005[11] and it uses protocols described in the RFC 6109 (Request for Comments 6109), which was drafted in order to make the protocols public to the Internet community.

Since July 1 of 2013, all communications between enterprises and the Italian public administration are required to be sent through PEC and paper documents are no longer accepted.[12]

All matters concerning PEC in Italy are supervised and regulated by a special government agency called AgID ("Agenzia per l'Italia digitale") which determines the authorized certified email providers, the legal framework of PEC and the rules and terms of use.

Anyone may register a PEC address through a certified provider or reseller.

Starting from 2022, Italy is migrating from PEC to an EIDAS-compliant protocol, called Registered Electronic Mail. The switch over to the new protocol is being led by Roberto Reale[13] and Alessandra Antolini on behalf of AgID.

Comparison of Certified E-Mail providers in Italy
PEC provider eidas compatible 2024? DMA friendly (google\apple independent)Limitationaddress portability
Intesi Group will be in 2024 ?unknownno
Aruba (Actalis) partial nono
Infocertyesnono
...?Only for students and other business partnersno
TWT no ?...no
Sogei n\a ?Only for business partnersno
register.it no ?...no
Regione Marche - Posta Raffaello n\a ?suppressedno
Poste Italiane n\a ?...no
Consiglio Nazionale del Notariato no ?privateno
Namirial S.p.A. no ?n\ano
Cedacri Cert ...?...no
IN.TE.SA. S.p.A offline ?offlineno
Irideos S.p.A. (kolst) no ?no
Notartel S.p.A. ?no
Sogei no ?n\ano

See also

Notes and References

  1. Web site: Posta elettronica certificata – PEC. Linea Amica. Italian government. it. 2015-08-13.
  2. Web site: IncaMail. La Posta. it. 2018-12-24.
  3. Web site: GovHK: Electronic Authentication & Digital Certificates. www.gov.hk. 2015-08-13.
  4. Web site: De-Mail – einfach verschlüsselt und nachweisbar. www.cio.bund.de. de. 2019-09-22.
  5. Web site: Il futuro della PEC: Armonizzazione e riconoscimento in Europa - Diritto informatico: Notizie e guide. 9 March 2018.
  6. Web site: La Posta Elettronica Certificata verso le regole europee. 24 May 2017.
  7. Book: Applied Public Key Infrastructure: 4th International Workshop: IWAP 2005. limited. Zhou. Jianying. Kang. Meng Chow. Bao. Feng. Pang. Hwee-Hwa. IOS Press. 2005. 1-58603-550-9. Amsterdam. 80.
  8. Book: Information and Communications Security: 6th International Conference, ICICS 2004, Malaga, Spain, October 27-29, 2004. Proceedings. limited. Lopez. Javier. Okamoto. Eiji. Springer. 2004. 3-540-23563-9. Berlin. 40.
  9. Book: Information and Communications Security: 7th International Conference, ICICS 2005, Beijing, China, December 10-13, 2005, Proceedings. limited. Qing. Sihan. Mao. Wenbo. Lopez. Javier. Wang. Guilin. Springer Science & Business Media. 2005. 978-3-540-30934-5. Berlin. 1.
  10. Carlos Tico (2012). Method, a system and a computer program product for certifying that a destination email server has received an email message sent from a sender to at least one destination address. US Patent 9,742,722 B2 (2017) and EP2805455B1 (2018).
  11. Web site: Decreto del Presidente della Repubblica 11 febbraio 2005, n. 68. 2005-02-11. Agenzia per l'Italia Digitale. it. Regolamento recante disposizioni per l'utilizzo della posta elettronica certificata, a norma dell'articolo 27 della legge 16 gennaio 2003, n. 3..
  12. Web site: Posta elettronica certificata. Agenzia per l'Italia digitale. Italian government. 2018-12-24.
  13. Web site: REM SERVICES - Criteri di adozione standard ETSI - Policy IT .