Signature activation data (SAD)

SAD (Signature Activation Data), defined in EN 419241, binds signatory, key and DTBS/R via SAP to activate a QSCD for eIDAS remote signing.

Signature Activation Data (SAD) is the piece of evidence that links a specific signatory, their signing key and the exact data to be signed (DTBS/R), and that authorises a remote signing system to activate the signing key for that data. It is the mechanism used to demonstrate sole control over the key for remote (server-side) qualified electronic signatures under eIDAS, and is needed to reach sole control assurance level (SCAL) 2. This per-signature binding is what distinguishes SCAL2 from SCAL1, where the provider authorises signing on the signatory's behalf without it - see the SCAL entry for that comparison. SAD is defined in the CEN standard EN 419241-1 for server-side signature creation, and is carried to the signature activation module (SAM) by the signature activation protocol; under EN 419241-2 the SAM forms part of the qualified signature creation device (QSCD)'s trusted boundary rather than being a separate external system. Many remote signing providers implement this through the Cloud Signature Consortium API (CSC API). It is generated after the signatory has authenticated (for example with an app, PIN or biometric check); the SAM verifies the SAD and, if valid, authorises the QSCD's cryptographic module to use the signature creation data it holds, without the key material ever leaving the device.

Frequently asked questions

Back to glossary