An electronic signature is a legal concept that is defined in the eIDAS Regulation by the following:
‘electronic signature’ means data in electronic form which is attached to or logically associated with other data in electronic form and which is used by the signatory to sign; (eIDAS Article 3.10)
This implies that an electronic signature may be represented by any type of data associated with a person and a content in electronic form. For example, it may be a text with a person's name in the end of an email, or a visual stamp within an electronic document.
A digital signature, on the other hand, refers to a mathematical and cryptographic concept that is widely used to provide concrete and practical instances of electronic signatures. The definition given by ETSI TR 119 100 is that of
Digital signature is data appended to, or a cryptographic transformation of a data unit that allows a recipient of the data unit to prove the source and integrity of the data unit and protect against forgery e.g. by the recipient.
A digital signature provides a proof of the content integrity and the signature creator.
These two concepts should be distinguished, as all electronic signatures are not necessarily digital signatures.
For more information about electronic signatures, you will need to look into eIDAS Regulation, that distinguish three types of electronic signatures:
1. 'Simple' electronic signatures
See definition for "electronic signature" above.
2. Advanced electronic signatures (AdES)
An advanced electronic signature is an electronic signature which is additionally:
- uniquely linked to and capable of identifying the signatory;
- created in a way that allows the signatory to retain control;
- linked to the document in a way that any subsequent change of the data is detectable.
The most commonly used technology able to provide these requirements relies on the use of a public-key infrastructure (PKI), which involves the use of certificates and cryptographic keys.
Advanced signature is a digital signature.
3. Qualified electronic signatures (QES)
A qualified electronic signature is an advanced electronic signature which is additionally:
- created by a qualified signature creation device (QSCD); and
- is based on a qualified certificate for electronic signatures.
For more information about electronic signatures please see eSignature FAQ from the European Commission website.