跳到主要內容

臺灣博碩士論文加值系統

(216.73.217.17) 您好!臺灣時間:2026/09/14 23:49
字體大小: 字級放大   字級縮小   預設字形  
回查詢結果 :::

詳目顯示

我願授權國圖
: 
twitterline
研究生:王坤成
研究生(外文):Kun-Cheng Wang
論文名稱:憑證機構法律責任與風險管理之探討
論文名稱(外文):Research on Certification Authority's Responsibility and Risk Management
指導教授:余啟民余啟民引用關係
指導教授(外文):Jimmy C. Yu
學位類別:碩士
校院名稱:東吳大學
系所名稱:法律學系
學門:法律學門
學類:一般法律學類
論文種類:學術論文
論文出版年:2007
畢業學年度:96
語文別:中文
論文頁數:125
中文關鍵詞:電子簽章數位簽章電子文件憑證機構憑證註冊中心電子商務公開金鑰私密金鑰憑證機構作業基準損害賠償風險管理風險自留風險控制風險移轉風險規避責任保險
外文關鍵詞:Electronic SignatureDigital SignatureElectronic DocumentCertification AuthorityRegistration AuthorityPublic KeyPrivate KeyRisk ManagementRisk RetentionRisk ReductionRisk TransferenceRisk AvoidanceReliability Insurance
相關次數:
  • 被引用被引用:1
  • 點閱點閱:354
  • 評分評分:
  • 下載下載:0
  • 收藏至我的研究室書目清單書目收藏:0
在快速發展並且普及的電子商務市場裡,如何建立線上交易的安全性機制,是政府、企業、以及消費者一致關心的重要課題。在非電子商務的交易上,締約當事人為彼此確認身分資格,並避免事後否認蓋章,經常要求對方提供出經濟部核發之公司印鑑證明書或負責人資格證明書、戶政事務所核發之印鑑證明書;當發生簽名是否真正之爭執時,當事人經常申請刑事警察局等刑事鑑定機構作筆跡或文書鑑定。在電子商務的交易模式,則由憑證機構扮演上開機構之角色,負責審驗憑證申請人的身分、資格,並發給申請人私密金鑰,簽發公開金鑰憑證,以供驗證其與私密金鑰之配對關係,可資證明交易者之身分,以及其要約或承諾之意思表示,確保交易之安全。
我國電子簽章法對於憑證機構之侵權行為責任,於第14條第1項規定:「憑證機構對因其經營或提供認證服務之相關作業程序,致當事人受有損害,或致善意第三人因信賴該憑證而受有損害者,應負賠償責任。但能證明其行為無過失者,不在此限。」、第2項規定:「憑證機構就憑證之使用範圍設有明確限制時,對逾越該使用範圍所生之損害,不負賠償責任。」,使憑證機構能證明當其行為無過失,或被害人超過約定憑證使用範圍所生之損害,不負賠償責任;憑證機構亦以憑證實務作業基準約定賠償限額或免責條款,以減輕或免除其賠償責任,控制損失風險。然而賠償限額或免責條款之約定,必須通過消費者保護法第12條關於定型化契約規範之檢驗,才能達到風險管理的目標;而且就未限制憑證使用範圍,以及在憑證使用範圍內所發生之侵害,憑證機構仍有侵權行為之損害賠償責任風險,亦須設法予以納入風險控管之範疇。
憑證機構對於未限制憑證使用範圍,以及在憑證使用範圍內所發生之侵害,其損害賠償責任風險符合損失頻率低、損失幅度高之特性,應選擇風險移轉之策略,應投保責任保險或參加同業相互保險基金,以轉嫁潛在之損害賠償責任風險。目前國內市場上銷售之保單商品有「Information And Network Technology Errors Or Omissions Liability Insurance(資訊及網路技術錯誤或疏漏責任保險)」可供選購,其承保範圍係就被保險人之錯誤行為,因法律規定或保險契約承擔之約定,發生賠償責任所致財產上之損失,然該商品為移植自外國之英文保單,理賠條件至為繁瑣,文義解釋亦恐有爭議,整體保單也不盡然適用於憑證機構之責任風險。未來保險業者如要就憑證機構之責任風險研發「認證業務責任保險」中文保單,現有保險商品中性質相近者,例如「保險公證人責任保險」、律師或會計師之專業人員責任保險、或「產品責任險」等保單,均可資參照設計適合憑證機構實際風險需求之保單條款。
另外,憑證機構雖然主張與註冊中心並無互為代理之關係,但其間之損害賠償責任與風險問題,亦有待保險業者與憑證機構共同努力,使未來「認證業務責任保險」得以參照現行「營造工程綜合險」附加第三人意外責任險將主次承包商納入被保險人之方案,將註冊中心列為共同被保險人,共同受到保險之保障。

關鍵字:
電子簽章、數位簽章、電子文件、憑證機構、憑證註冊中心、電子商務、公開金鑰、私密金鑰、憑證機構作業基準、損害賠償、風險管理、風險自留、風險控制、風險移轉、風險規避、責任保險
In the e-commerce market that developed quickly and popularized, the Government, enterprises, and consumers all care about setting up a security system for the on-line trade. When people trade by the general way, in order to confirm the identity or qualification and avoid denying afterward for each other, the party often require the other side to present their company’s seal impression and director's qualification certificate that issued by the Ministry of Economic Affairs, or hand over the personal seal certificate that issued by the household registration office, if people argue about the signature or seal is real or not, the parties always apply to the Criminal Investigation Bureau or the reference institution to identify it. People trade by the e-commerce way, the Certification Authority will act the mentioned role of institution, the Certification Authority take the responsibility to prove the identity or qualification of the applicant, sign and issue the certificate of Public key to identify the pair relation with the Private key, so as to prove the identity of dealers and their intent for offer or acceptance, and to upholding the security of transactions.
Article 14 of the Electronic Signatures Act stipulate the tort responsibility of Certification Authority: “A certification service provider shall be liable for any damage caused by its operation or other certification-related process to the parties, or to a bona fide person who relies on the certificate, unless the certification service provider proves that it has not acted negligently.”, “Where a certification service provider clearly specifies the limitation for the use of the certificate, it shall not be liable for any damage arising from a contrary use.” Therefore the Certification Authority shall not be liable to compensate for the injury when it can prove no negligence in it’s act, or any damage arising from exceeding application limitation. The Certification Authority also set the compensation limit or exemption clause in the certification practice statement to lighten or avoid its compensation responsibility, so as to control the damage risk, however, these contract wording shall be regulated by the Article 12 of Consumer Protection Law; and further, if there is no limitation of application, or any damage arising from normal application, the Certification Authority still expose in the risk of the tort compensation responsibility.
The above-mentioned risk character of the Certification Authority is low loss frequency and high loss severity, for managing this kind of risk, business should select and adopt the strategy of Risk Transference, to insure for their responsibility or participate in the mutual insured fund that formed by the same business, so as to transfer the potential risk of compensation for liability. The reference insurance policy sold at present is ' Information And Network Technology Errors Or Omissions Liability Insurance', it’s main coverage is to pay loss by reason of liability of imposed by Law or assumed in an insured contract, but it was transplanted from foreign and written in English, the claims condition is complicated, the article meaning also probably caused dispute, the whole insurance policy is not suitable exactly for the liability risk of the Certification Authority. If the insurer should research and develop a Chinese liability insurance policy for the certification business, there are some similar character policies such as liability insurance of the insurance adjuster, lawyer, accountant, or the other professional person and the product liability insurance policy could be referred.
In addition, although the Certification Authority stated that there is not any agent relationship between them and the Registration Authority, the potential compensation responsibility and risk also need to be managed. When the insurers try to design the liability insurance of the Certification Authority, they could refer to the current ' Contractors’ All Risk Insurance' policy attach the Subcontractors as the Co-Insured, attach the Registration Authority as a Additional Insured.

Key words:
Electronic Signature, Digital Signature, Electronic Document, Certification Authority, Registration Authority, Public Key, Private Key, Risk Management, Risk Retention, Risk Reduction, Risk Transference, Risk Avoidance, Reliability Insurance
第一章
緒論……………………………………………………………………10
第一節
研究動機…………………………………………………………10
第二節
研究目的…………………………………………………………12
第三節
研究內容與範圍…………………………………………………12
第四
節 研究方法…………………………………………………………13
第五節
文獻探討…………………………………………………………13
第二章
憑證機構之定位與功能………………………………………………15
第一節
電子簽章法之立法概述…………………………………………15
第二節
電子簽章法之立法原則與目的…………………………………16
第一項
電子簽章法之立法原則……………………………………16
第二項
電子簽章法之立法目的……………………………………18
第三節
電子簽章與數位簽章……………………………………………19
第一項
電子簽章……………………………………………………19
第二項
數位簽章……………………………………………………24
第四
節 憑證機構之定義…………………………………………………28
第五節
憑證機構之組織與業務範圍……………………………………31
第一項
憑證機構……………………………………………………31
第二項
公開金鑰……………………………………………………31
第三項
金融公鑰基礎建設…………………………………………32
第四
項 商業憑證機構………………………………………………37
第六節
憑證機構之功能…………………………………………………37
第一項
用戶憑證中心………………………………………………39
第二項
註冊中心……………………………………………………40
第三章
憑證於電子商務之應用………………………………………………41
第一節
憑證於電子商務應用之情形……………………………………41
第一項
證券期貨網路下單憑證……………………………………41
第二項
網路銀行憑證………………………………………………41
第三項
網路保險憑證………………………………………………42
第四
項 電子股務認證………………………………………………44
第五項
其他電子商務………………………………………………44
第二節
憑證於電子商務應用面臨之問題………………………………45
第一項
數位簽章遭冒用之問題……………………………………45
第二項
消費者保護之問題…………………………………………47
第三節
憑證機構產業的未來展望………………………………………47
第四
章 憑證機構之管理規範…………………………………………………50
第一節
憑證實務作業基準………………………………………………51
第二節
憑證實務作業基準之效力………………………………………57
第一項
憑證實務作業基準之法律性質……………………………57
第二項
憑證實務作業基準未經主管機關核定之影響……………58
第三節
憑證機構管理制度………………………………………………59
第四
節 憑證機構管理規範之修法方向…………………………………60
第五節
憑證機構之國際相互承認………………………………………68
第五章
憑證機構之法律責任…………………………………………………72
第一節
侵權行為責任……………………………………………………73
第二節
契約債務不履行責任……………………………………………75
第三節
賠償責任之限制…………………………………………………76
第六章
憑證機構之責任風險管理……………………………………………78
第一節
企業之責任風險…………………………………………………78
第二節
企業責任風險之成立要件………………………………………79
第一項
企業之侵權行為責任成立要件……………………………79
第二項
企業之契約責任成立要件…………………………………81
第三節
企業之責任風險管理……………………………………………81
第四
節 憑證機構之責任風險管理策略…………………………………83
第一項
風險管理之評估與策略……………………………………83
第二項
自提賠款責任準備金,風險自留…………………………84
第三項
約定憑證適用與限定賠償責任範圍,損失控制…………84
第四
項 投保責任保險或成立同業相互保險基金,風險移轉……86
第五項
退出市場,風險規避………………………………………91
第七章
結論與建議……………………………………………………………93
第一節
就憑證機構之損害賠償責任而言………………………………93
第二節
就憑證機構之責任風險管理而言………………………………94
參考文獻…………………………………………………………………………96
壹、
中文部分
一、
書籍
1. David
E. Bell & Arthur Schleifer Jr. 著,蔣永芳譯,風險管理,弘智文化事業,2001年9月2版。
2. Harold D. Skipper
著,賴麗華譯,風險管理國際觀:並論保險產業定位,美商麥格羅•希爾國際公司台灣分公司出版,2004年7月初版。
3. 吳
嘉生著,電子商務法導論,學林文化事業公司,2003年10月一版。
4. 周
天等合著,網路法律高手,書泉出版社,2002年4月初版。
5. 周
忠海等著,電子商務法新論,神州圖書出版公司,2002年11月初版。
6. 果
芸發行,網路VS.法律,財團法人資訊工業策進會科技法律中心,1999年2月初版。
7. 胡
宜仁主編,保險實務,三民書局,民國90年11月增訂四版。
8. 凌
氤寶、陳森松著,產物保險經營,華泰文化事業,2003年9月初版。
9. 凌
氤寶、康裕民、陳森松合著,保險學理論與實務,華泰文化事業,2001年9月三版。
10.陸義淋等合著,電子商務法律通,書泉出版社,2003年
11月初版。
11.陳繼堯、曾武仁等著,金融自由化下新
興風險移轉方法之運用現況與發展,財團法人保險事業發展中心發行,民國89年2月。
12.馮震宇著,企業E化
電子商務與法律風險,元照出版社,2002年。
13.馮震宇著,網
路法基本問題研究(一),學林文化事業公司,1999年。
14.劉尚志、陳佳麟合著,網際網路與電子
商務法律策略,元照出
版社,2001年3月。
15.蔡淑美著,企業網路經營法律實戰,永
然文化出版公司,民國91年6月初版。
16.鄭玉波著,劉
宗榮修訂,保險法論,三民書局,2003年6月修訂五版。
17.鄭燦堂著,風險管理理論與實務,五南圖書出版,2003年
10月初版。
二、
期刊論文
1. PL Huang ,
「金流發展現況、面臨困難及服務機制(Ⅰ)」,電子商務導航,第六卷第一期,民國93年3月1日。
2. PL Huang ,
「金流發展現況、面臨困難及服務機制(Ⅱ)」,電子商務導航,第六卷第一期,民國93年3月15日。
3. 王
傳芬,「網路交易法律問題之研究--以消費者保護為依歸」,國立台灣大學法律學研究所碩士論文,民國八十八年六月。
4. 余
啟民,「國際電子簽章法相關立法發展趨勢之淺析」,經濟部推動電子簽章法網站:http://www.esign.org.tw/docu_2_06.asp最後瀏覽日期:
5. 何
全德,「電子簽章法簡介-(九)憑證機構與電子認證」,行政院研考會網站:http://www.rdec.gov.tw/mis/eg/esign/es_9.htm最後瀏覽日期:
6. 何
紓萍、鄭秀芬、魏伶如,「電子商務資料的安全管理及保密措施」,吳鳳學報,第12期,民國93年5月。
7. 李
科逸,「電子文件及電子簽章國際最新立法趨勢之略述」,財團法人資訊工業策進會科技法律中心:http://stlc.iii.org.tw/stlc_c.htm最後瀏覽日期:
8. 李
科逸,「電子簽章法重要法律議題之探討及初議」,律師雜誌,第二五六期,民國九十年一月十五日。
9. 李
瑞生,「電子商務交易安全法制之研究」,私立東海大學法律學研究所碩士論文,民國九十一年四月。
10.林娟,「保
險業電子商務之趨勢」,保險資訊,第182期,2000年10月。
11.林育廷,「
電子支付相關法律問題之初探—以消費性電子資金移轉為例」,律師雜誌,第二五六期,民國九十年一月十五日。
12.林煒鎔,「
電子簽章與電子金融服務之應用—憑證機構法律責任之探討」,科技法律透析,民國92年8月。
13.林煒鎔,「
憑證機構之管理規範」,商業現代化,第53期,民國91年7月。
14.許慧如,「網
際網路上保險契約訂立之研究」,國立台北大學法學系碩士論文,民國九十年六月。
15.梁理旋,「2
002年亞洲PKI趨勢調查報告」,亞洲公開金鑰基礎建設論壇中華台北推動委員會網站:http://www.pki.org.tw/Schedule/9202_%A8%C8%ACwPKI%C1%CD%B6%D5%BD%D5%ACd%B3%F8%A7i.pdf最後瀏覽日期:
16.馮震宇,「論
電子商務之法律保護與因應策略」,月旦法學第八十期,民國91年1月。
17.郭佳玫,「論
現行網路交易爭議解決的法律問題」,科技法律透析,民國90年6月。
18.陳怡冰,「電
子保險契約效力之研究」,國立政治大學法律學系碩士論文,92學年度。
19.楊婉艷,「淺
談電子金融交易安全之環境」,科技法律透析,民國92年4月。
20.盧世寧,「保
險電子商務法律問題之研究」,國立政治大學風險管理與保險學系碩士論文,民國九十一年七月。
21.盧鄂生、吳啟文,「電
子認證與網路安全管理」,研考雙月刋,第二十五卷第一期,九十年二月。
22.賴文智,「企
業利用網路之法律議題」,月旦法學第九十期,民國91年11月。
23.魏志強,「我
國電子商務發展趨勢」,電子商務導航,第六卷第五期,民國93年5月1日。
24.
資策會科技法律中心,「數位簽章與CA認證的法律淺析」,http://stlc.iii.org.tw/04-1-1.htm最後瀏覽日期:

貳、
外文部分
一、
書籍
1.
August, Ray A., International Business Law, Prentice Hall, 2000.
2.
Baumgarten, Jon A., Epstein, Michael J., Grogan, Allen R., Johnston, Ronald L., Wiley, Richard E., Butler, Robert J., Business and Legal Guide to Online Internet Law, Glasser LegalWorks, 1997.
3.
Boss, A.,Electronic Data Interchange Agreements: A Guide and Sourcebook, Icc Pub, 1994.
4.
Casey, Timothy D., ISP Liability Survival Guide: Strategies for Managing Copyright, Spam, Cache, and Privacy Regulations, John Wiley & Sons, Inc., 2000.
5.
Campbell, Dennis, Law of International on-Line Business A Global Perspective, Sweet & Maxwell, 1998.
6.
Efrraim, Turban., David King, Lee, Jae K., Viehland, Dennis., Electronic Commerce 2004: A Managerial Perspective, Third Edition, Prentice Hall International, Inc., 2003.
7.
Ferrera, Gerald R. et al., Cyberlaw: Text and Cases, 2nd Edition, South-Western College /West, 2001.
8.
Ford, Warwick & Baum Michael S., Secure Electronic Commerce: Building the Infrastructure for Digital Signatures and Encryption, 2nd Edition, Prentice Hall PTR, 2000.
9.
Information Security Committee, Digital
Signature Guidelines -- Legal Infrastructure for
Certification Authorities and Secure Electronic
Commerce, American Bar Ass’n, 1996.
10.
Kono, Toshiyuki et al., Selected Legal Issues of E-Commerce (Law and Electronic Commerce), Kluwer Law International, 2002.
11.
Lodde, r Arno R. and Henrik W. K. Kaspersen, e Directive: Guide to European Union Law on E-Commerce, Kluwer Law International, 2002.
12.
National Research Council, Computer at Risk: Safe Computing in the Information Age (1991).
13.
National Research Council, Cryptography’s Role in Securing the
14.
Perritt, Henry H., Jr. Law And The Information Superhighway, Aspen Publishers , 2003.
15.
Schneier, Bruce. Applied Cryptography: Protocols, Algorithms, and Source Code in C ,Second Edition, 1996.
16.
Spindler, Gerald and Fritjof Borner, E-Commerce Law in Europe and the USA, Springer, 2001.
17.
Weber, Rolf H., Regulatory Models for the Online World, Kluwer Law International, 2002.
18.
Wigger, Willem J. H. International Commerce Law, Klower Law International, 2001.
19.
Winn, Jane Kaufman, The Law of Electronic Commerce, 4th Edition, Aspen Publishers , 2001.
二、
期刊與網站
1.
Allard, Nicholas W, & David A. Kass, Law and Order in Cyberspace: Washington Report, 19 HASTINGS COMM/ENT L.J. 563 (1997).
2.
Almaguer, Alejandro E. & Roland W. Baggott III, Notes & Comment: Shaping New Legal Frontiers: Dispute Resolution For the Internet, 13 OHIO ST. J. on DISP. RESOL. 711 (1998).
3.
Anthony J. Bellia, Jr., "Contracting with electronic agents", EMORY L. J., vol. 50, fall 2001.
4.
Boss, Amelia H. The International Commercial Use of Electronic Data Interchange and Electronic Communications Technologies, 48 BUS. LAW. 1787 (1991).
5.
________ & Winn, Jane Kaufman, The Emerging Law of Electronic Commerce, 52 BUS. LAW. 1469 (1997).
6.
________. Electronic Commerce and the Symbiotic Relationship Between International and Domestic Law Reform, 72 TUL. L. REV. 1931 (1998).
7.
Budnitz, Mark E. Privacy Protection for Consumer Transactions in Electronic Commerce: Why Self-Regulations is Inadequate, 46 S. C. L. REV. 847 (1998).
8.
Bundesgesetzblatt, “Law Governing Framework Conditions for Electronic Signatures” , BGBI. Teil I S. 876 vom 21, 2001.
9.
Electronic Messaging Services Task Force, The Commercial Use of Electronic Data Interchange -- A Report and Model Electronic Data Interchange Trading Partner Agreement, 45 BUS. LAW 1645 (1990).
10.
Frene, Georges. Electronic Commerce: A New Economic and Policy Area, J. INTERNET BANKING & COMMERCE,http://www.arraydev.com/commerce/jibc/9704-08.htm.
11.
Froomkin, A. Michael. The Metaphor Is the Key: Cryptography, The Clipper Chip, and the Constitution, 143 U. PA. L. REV. 709 (1995).
12.
James G. Barnes & James E. Byrne “E-Commerce and letter of credit law and practice” INT’l LAWYER Vol. 35 No.1. spring 2001.
13.
Johnson, David R. & David Post, Law and Borders – The Rise of Law in Cyberspace, 48 STAN. L. REV. 1367 (1996).
14.
Kang, Jerry. Information Privacy in Cyberspace Transactions, 50 STAN. L. REV. 1193 (1998).
15.
Reisner, Jeffrey M. California Extends Consumer Protection to Business on the Internet, 3 No. 4 Multimedia Strategist 5 (1997).
16.
Ritter, Jeffery B. & J. Keith Harmon, Doing Business on the Internet -- Electronic Data Interchange: The Foundation Technology for Electronic Commerce, 452 PLI/Pat 467 (1996).
17.
Rustad, Michael L. Commercial Law Infrastructure for the Age of Information, 16 J. MARSHALL J. COMPUTER & INFO. LAW 255
(1997).
18.
United Nation’ s Commission on International Trade Law Working Group on Electronic Commerce, “UNCITRAL Model Law on Electronic Signatures” , 2001.
19.
Winn, Jane K. Couriers Without Luggage: Negotiable Instruments and Digital Signatures, 49 S.C. L. REV. 739 (1998).
20.
________. Open Systems, Free Markets, and Regulation of Internet Commerce, 72 TUL. L. REV. 1177 (1998).
21.
_________. Power Practice -- Trends in Computer Law; Texas Welcome Electronic Signatures, TEXAS LAWYER, Aug. 11, 1997.
22.
Yates, John C. Electronic Commerce and Electronic Data Interchange, 507 PLI/Pat 147 (1998).
23.
________. Recent Legal Issues in Electronic Commerce and Electronic Data Interchange, 430 PLI/Pat 271 (1996).
24.
美國PKI: http://csrc.nist.gov/pki/
25.
新加坡PKI: http://www.ida.gov.sg/idaweb/pnr/infopage.jsp?infopageid=I1932
QRCODE
 
 
 
 
 
                                                                                                                                                                                                                                                                                                                                                                                                               
第一頁 上一頁 下一頁 最後一頁 top
無相關期刊