Blockchain and the evidentiary value of data
18/05/2023 2023-06-19 10:23Blockchain and the evidentiary value of data
Edited by Lorenzo Savastano[1]
- Blockchain: A New Ground for "Chasing Money"
The report "Cryptocurrencies: Tracing the Evolution of Criminal Finances”, published last year by the agency law enforcement of European Union Europol, has clearly highlighted how the illicit use of virtual currencies – for the purposes of laundering capital of illicit origin – no longer appears to be confined to the area of Cybercrime, instead being linked to any type of illicit activity (especially, but not only) of an economic-financial nature.
An observation which is also confirmed in the latest newsletter of the Bank of Italy, published last December, where we learn that the reports of suspicious transactions attributable to digital asset, which have increased significantly in the last three years, are increasingly related not only to typically cyber crimes, such as computer fraud or episodes of ransomware, but also to tax offences.
These are data that confirm how the "Tracks of money” – to be pursued, according to the famous Falconian teaching for the reconstruction of the most complex criminal scenarios – have now moved onto less conventional but increasingly widespread and used terrains: the virtual registers of the Blockchain.
In this regard, this paper aims to offer a reflection on a dilemma of significant impact on the professional practice of financial police officers employed in the reconstruction of money laundering phenomena perpetrated through the use of distributed electronic register technology, which can be summarised in the question: What is the evidentiary value of the data reported on a blockchain?
- “Open” and “Closed” Distributed Ledger Technology
As is known, technology blockchain it is a particular form of Distributed Ledger Technology (DLT), or an electronic register shared between multiple users of the same network computer, whose data are protected both through cryptographic techniques and through the so-called redundancy of the data (ie copies of the same information can be validated and archived at all active participants in the registry)[2].
Specifically, we are talking about blockchain because the stored transactions are grouped into a sequence of “blocks” linked together cryptographically, thus creating a chronological and unalterable record of all the transactions carried out up to that point.
Among the various possible distinctions that can be traced within the aforementioned technologies, the one that best lends itself to a “investigative" capable of bringing out the possible probative value of the transactions recorded in the electronic registers, is the one based on the model of governance underlying by network users.
In detail, it is usual to distinguish between two macro-types of DLT:
- public or permissionless (“open”), that is, capable of allowing access to any user intending to join the network, both by generating new transactions – thus assuming the function of miner (transaction validation and finalization process) – either by reading the transaction log recorded in the ledger.
Given these characteristics, protocols of this type are mainly used in the so-called cryptocurrency sector (eg. the blockchain di Bitcoin ed Ethereum), in which each participant can access and operate in network without the need to identify yourself or be previously authorised.
- private or permissioned (“closed”), usually operating on behalf of a Community which share a common interest and are characterised by the presence of a “Central Authority” responsible for validating new blocks in the chain and capable of discriminating user access to the network. In this case, access to the role of miner It is limited to a limited number of users.
This is, as we will see, a basic distinction for discerning the possible "estate" in judicial proceedings of data stored on DLT electronic register technology, since it allows for easier reading in line with current provisions – both European and national – concerning the evidentiary value of electronic documents.
- Union and national legislation on timestamps
Regulation (EU) No 910/2014 of the European Parliament and of the Council of 23 July 2014 (hereinafter: Regulation eIDAS), in order to create a digital single market within the political borders of the European Union, introduces – among others – a series of tools useful for the digital certification of data and information contained in “electronic tracks".
In particular, the Regulation eIDAS outlines a peculiar procedure for validating computer data called “electronic signature”, to which genus they belong to:
- the "electronic signature" so-called pure: consisting of data in electronic form, enclosed or logically associated with other electronic data and used by the signatory to sign;
- the "advanced electronic signature”: electronic signature uniquely connected to the signatory, suitable for identifying him, created with means that the signatory can use under his own exclusive control and linked to the signed data in such a way that any modification can be detected;
- the "qualified electronic signature”: advanced electronic signature associated with a certificate issued by a qualified service provider.
The national precipitate of the European provisions is the Legislative Decree of 7 March 2005, number 82 (Digital Administration Code – CAD) which, in addition to adapting domestic legislation to standard Union, alongside these tools, the "digital signature", that is to say "a particular type of qualified signature based on a system of cryptographic keys, one public and one private, correlated with each other, which allows the holder of the electronic signature via the private key and a third party via the public key, respectively, to make manifest and verify the origin and integrity of an electronic document or a set of electronic documents"(empty art. 1, paragraph 1, letter s CAD).
That being said, with reference to the probative value of the electronic document – validated with one of the aforementioned procedures – within judicial proceedings, it is important to highlight how the Regulation eIDAS, in art. 25 (titled “Legal effects of electronic signatures”) establishes that “An electronic signature may not be denied legal effect and admissibility as evidence in legal proceedings solely on the grounds of its electronic form or because it does not meet the requirements for qualified electronic signatures.".
This latter procedural rule was adopted in Italy in Article 20, paragraph 1. CAD, where it is established that the electronic document satisfies the written form requirement and has the effectiveness provided for by art. 2702 of the Civil Code (i.e., it constitutes full proof until a complaint of forgery is filed) “[…] when a digital signature, another type of qualified electronic form or an advanced electronic signature is affixed to it or, in any case, it is created following the computerised identification of its author, through a process having the requirements set by AgID [Agency for Digital Italy, ed.]… in order to guarantee the security, integrity and unalterability of the document and, in a manifest and unequivocal manner, its traceability to the author".
As a corollary to the aforementioned provision, the following paragraph 1 ter establishes – finally – that “the use of the qualified or digital electronic signature device is presumed to be attributable to the holder of the electronic signature, unless the holder provides proof to the contrary".
More specifically, placing an electronic signature on the document produces the effect of “timestamp“, defined by the Court of Cassation as “the process of generating …, by a trusted third party, a “digital signature of the document” to which is associated the information relating to a specific date and time"[3]. A legal effect, as is evident, very similar to the described function of timestamp specific to technology blockchain.
If, otherwise, the electronic document is not authenticated with one of the aforementioned technological procedures, the aforementioned CAD provision establishes the rule of free assessment of the evidence by the competent judge. Specifically, pursuant to the second sentence of the aforementioned paragraph 1: of art. 20, CAD, “The suitability of the electronic document to satisfy the written form requirement and its probative value can be freely assessed in court, in relation to its characteristics of security, integrity and unalterability”.
In this case, in particular, the date and time of creation of the electronic document will be enforceable against third parties only if "affixed in accordance with the Guidelines” issued pursuant to art. 71 CAD, or to the fees and standard of cyber security contained (mainly but not exclusively) in the Prime Ministerial Decree of 13 November 2014.
- Reflections on the “electronic traces” of blockchain
The digital data validation systems identified by the CAD, in compliance with the Union parameters of the Regulation eIDAS, bring the argumentative cursor back to the DLT technology described in the introduction, opening up a series of operational reflections on the usability – within the context of a judicial proceeding – of the information printed on the registers of the blockchain.
Resuming the aforementioned distinction between networks open e closed, it can in fact be easily deduced that the validity "legal” of the transactions printed on blockchain appears to change depending on the type of "network” in which they are hosted.
Specifically:
- in the open blockchains, since – as seen – prior identification of users is not required, the operational problem essentially lies in the traceability of the transaction to the user which determines its verification, since the electronic keys are not issued by subjects having the requirements attributable to the Trust Service Provider, or the "qualified trust service providers" referred to in Articles 13 and following of the Regulation eIDAS.
In detail, this is a category of providers of electronic services, normally provided for a fee, consisting of – inter alia - in the "creation, verification and validation of electronic signatures, electronic seals or electronic time stamps, electronic registered delivery services and certificates relating to such services”, in possession of the stringent requirements set out in the aforementioned European Regulation.
For this reason, in this taxonomy of DLT, an assimilation does not appear to be possible tout court of the evidentiary relevance of the transactions reported on blockchain to that of documents signed with an advanced electronic signature, since the cryptographic keys used in DLTs are not comparable to this type of electronic signature. Therefore, in such cases, the rule of free evaluation by the judge, which will have to decide on the suitability of the written form of the document on the basis of the parameters set out in the aforementioned paragraph 1 of art. 20 CAD;
- in the closed blockchains, the fact that access is permitted only to individuals already identified by the platform that makes the information register available allows for a more straightforward solution to the problem of identifying the actual owners of the cryptographic keys.
Where the provider of services connected to digital asset meet the criteria set for the category of the aforementioned TSPs, it will then be possible to create an advanced electronic signature system with which to sign transactions based on the blockchain, giving such information the probative value provided for by art. 2702 of the Civil Code.
- The boundary between VASP and TSP
Finally, in order to examine the “judicial dress" of the data reported in an electronic register based on DLT technology, it will therefore be necessary to measure the possible assimilation of the two categories of Virtual Asset Service Provider (VASP) regulated by Legislative Decree 21 November 2007, n. 231 (i.e. providers of services relating to the use of virtual currency and providers of digital wallet services), to the category of "qualified trust service providers” outlined by the Regulation eIDAS.
In practice, therefore, only if the parameters for issuing cryptographic keys by VASPs satisfy the security, integrity and technological immutability requirements imposed by the aforementioned Guidelines, drawn up in compliance with the Italian provisions of the CAD and the EU provisions of the Regulation eIDAS, the data relating to user transactions may – in fact – be considered a legally recognized electronic document.
A perspective which, as is evident, would make the transactions imprinted on the blockchain not only indelible electronic traces at the disposal of investigators, but also solid "evidence” at the disposal of the Judicial Authority.
[1] Major of the Guardia di Finanza, serving at the Economic-Financial Police Unit of Milan (ppgad@pucrs.br).
[2] In this regard, among the various contributions, we would like to point out: POTENZA G., Fintech and Blockchain, in AA.VV. (edited by CORAPI E. and LENER R.), The Different Sectors of Fintech: Problems and Prospects, Milan, 2019, p. 76; ANNUNZIATA F. – CONSO A., Cryptocurrencies in Italian and international law, in AA.VV. (edited by AVELLA F.), Bitcoin and Cryptocurrencies, Milan, 2021, pp. 20 et seq.; SAVASTANO L., Following the (virtual) money: the evidentiary value of electronic transactions imprinted on the blockchain, its Il Centauro – Training and refresher magazine for police forces, n. 256 of May 2023.
[3] Court of Cassation, Civil Section, First Ordinary Section, February 13, 2019, no. 4251.