The Securities and Exchange Commission is planning to roll out its own blockchain-based platform that enables a more secure digital authentication of reports and other documents filed by corporations.
The commission has issued for public comment a draft memorandum circular on blockchain-based digital signing and authentication of SEC documents using its verification of electronic records and information trust and authentication system.
VERITAS is a digital signature platform that will enable the transacting public to securely sign and authenticate SEC-related documents with the use of public-key cryptography.
The SEC said the system is designed to record digital signing events on a decentralized ledger, ensuring immutability, timestamping and cryptographic verification.
‘By integrating blockchain-based digital signing and authentication into our processes, we aim to strengthen the integrity and reliability of reports and documents submitted by corporations to the commission by making them immutable, permanent and indestructible,’ SEC chairperson Francis Lim said.
‘VERITAS also reaffirms our commitment to digital transformation not only by making transactions more secure and efficient, but also by reducing paperwork and cutting processing time to further improve how we do business,’ he said.
The SEC intends to immediately deploy VERITAS for public use once the guidelines are finalized.
The commission said its deployment would allow other government agencies to assess the benefits and advantages of blockchain technology and see how it could be applied within their own operations.
The draft rules seek to integrate VERITAS into the existing digital identity and credentialing system of the SEC under the electronic SEC universal registration environment (eSECURE) as well as the digital authentication platform under the electronic submission authentication portal (eSAP).
The SEC’s current authentication systems allow the public to register their corporations with the commission through a fully online process, without the need for wet signatures and notarized documents.
With VERITAS, the SEC will shift from the use of one-time passwords currently needed to authenticate documents under eSAP, to end-to-end encryption, multi-factor authentication and cryptographic signing mechanisms using the user’s private key.
The SEC said that one must first create an eSECURE account before gaining access to VERITAS under the draft circular.
Registration under eSECURE involves a mandatory credentialing process, which serves as an electronic know- your-customer procedure, to ensure that the person using the account is the one in charge of authenticating documents himself.
Submission of verified government-issued identification documents and a liveness detection protocol are required for credentialing process to establish a reliable and verifiable link between the digital signature and the legal identity of the signatory.
‘The use of end-to-end encryption, multi-factor authentication and cryptographic signing mechanisms through VERITAS will ensure that only authorized individuals can sign documents, thereby preventing unauthorized access, tampering or forgery,’ Lim said.