Follow Us

Suspects must reveal encryption keys, court rules

UK spooks in sigh of relief.

Defendants can't deny police an encryption key because of fears the data it unlocks will incriminate them, a British appeals court has ruled.

The case marked an interesting challenge to the UK's Regulation of Investigatory Powers Act (RIPA), which in part compels someone served under the act to divulge an encryption key used to scramble data on a PC's hard drive.

Failure to do so could mean a two-year prison sentence or up to five years if the case involves national security.

The appeals court heard a case in which two suspects refused to give up encryption keys, arguing that disclosure was incompatible with the privilege against self incrimination.

One of the suspects had been ordered not to move house without permission under a terrorism-prevention act. The man defied the order, and he and another man were arrested, according to the ruling from the England and Wales Court of Appeal Criminal Division.

Police also seized encrypted material on a disc belonging to the first man. When the second man was arrested, police saw he had partially entered an encryption key into a computer.

In its ruling, the appeals court said an encryption key is no different than a physical key and exists separately from a person's will.

"The key to the computer equipment is no different to the key to a locked drawer," the court found. "The contents of the drawer exist independently of the suspect; so does the key to it. The contents may or may not be incriminating: the key is neutral."

The right against self-incrimination is not without bounds, as suspects also can't refuse to give a DNA sample if properly compelled.

RIPA, passed in 2000 by the UK Parliament, is intended to give police new powers to conduct covert surveillance and wiretap operations in respect to new communication technologies.

The third part of RIPA concerning the disclosure of encryption keys came into force in October 2007. It was delayed since when RIPA was approved, law enforcement wasn't seeing wide use of encryption. It was also one of the more controversial parts of RIPA, as critics said companies could be at risk if law enforcement mishandled their data.

To obtain a key, a so-called "Section 49" request must first be approved by a judicial authority, chief of police, the customs and excise commissioner or a person ranking higher than a brigadier or equivalent. Authorities can also mandate that recipients of a Section 49 request not tell anyone except their lawyer that they have received it.






Send to a friend

Email this article to a friend or colleague:

PLEASE NOTE: Your name is used only to let the recipient know who sent the story, and in case of transmission error. Both your name and the recipient's name and address will not be used for any other purpose.

Techworld White Papers

State of software security report volume 4

If your business has anything worth protecting, be it money, intellectual property or a trusted...

Download Whitepaper

New threats demand innovative responses

Financial institutions in the UK remain susceptible to further systemic problems, as challenging...

Download Whitepaper

Delivering a competitive advantage through IT

IT organisations share a common mission; to optimise investments and streamline operations to...

Download Whitepaper

6 tips to mobilise your existing ERP

Enterprise mobile users throughout the global business community will number 1.19 billion by...

Download Whitepaper

Techworld UK - Technology - Business

Techworld Awards

Techworld Awards Winners 2011


Learn who the winners of this year's Techworld Awards are. Video footage coming soon...

Find out more
Techworld Mobile Site

Access Techworld's content on the move

Get the latest news, product reviews and downloads on your mobile device with Techworld's mobile site.

Find out more...

Site Map

* *