2004 UCLA J.L. & Tech. 2

No Computer Exception to the Constitution: 1
The Fifth Amendment Protects Against Compelled Production of an Encrypted Document or Private Key
by Aaron M. Clemens2

Computer Crime Seminar
Georgetown University Law Center
Professors Richard Salgado3 & Christian Genetski4

The U.S. Constitution’s Fifth Amendment privilege against self-incrimination prevents the government from compelling a person to decrypt or reveal the private key to decrypt her electronic documents absent two circumstances.5 The government must either prove, by clear and convincing evidence, that the three-prong test in Fisher v. United States6 has been met, or provide use and derivative-use immunity for such production.

I. The Need For Computer Security

Unauthorized access to computer files has been a problem since the computer’s advent.7 Unauthorized access allows identity theft, fraud, and the revelation of intimate secrets.8 These potential problems are exacerbated for lawyers, who have an ethical duty to protect their clients’ privileged information.9 Without updated security to match snooping possibilities, the use of computers for client matters may soon, in effect, waive the attorney-client privilege.10 Despite this emerging insecurity, the computer, like the telephone, has evolved into a personal and professional necessity for many people.11 Ubiquitous portable high-speed wireless Internet is now a reality for many in America. Increasingly, actual face-to-face conversations are replaced by virtual face-to-face conversations, even between parents and children within voice range of each other.12 As computers are increasingly used for communication, privacy concerns are heightened.13 Just as telephone use does not forfeit a person’s expectation of privacy,14 computer use must not forfeit a person’s expectation of privacy. Therefore, for computers to reach their full potential, unauthorized access to computers must be reduced.15

Efforts are underway to alleviate computer security concerns. Secret passwords have long protected access to computer resources and computer files.16 But, due to advances in cyber-snooping, basic alpha-numeric passwords alone can no longer assure security.17 Cryptography is one answer to the security problem. Cryptography is the ancient art of preventing unauthorized access to messages by improving the use of basis passwords.18 Modern cryptology,19 such as the public and private key system, can ensure computer security.20

Public/private key cryptography allows the exchange of secure messages. The process begins when a sender encrypts a message using the public key of the intended recipient. Both the public and private keys consist of an arrangement of letters, numbers, and symbols. A public key21 can be made public without fear of undermining the security of a message encrypted with it.22 Only a viewer of the message with the right private key can decrypt the message.23 Without this private key, the encrypted information is incomprehensible. To illustrate, I may encrypt this article using my brother’s public key,24 and send it to him.25 In turn, he could use my public key to encrypt his replying comments. If our private keys remain private, we are assured of security.26 Modern technology briefly took away privacy,27 but subsequently recreated it.28

II. Privacy for All Would Allow Privacy for those Suspected of Crime

Encryption provides secure transmission of confidential legal documents, business transactions, and any other information. But criminals can and do use it,29 including terrorists,30 members of drug cartels,31 organized criminals,32 and child pornographers.33 Strong encryption through cryptography will likely remain both readily available and lawful.34 To combat crimes involving encrypted messages, prosecutors may seek compelled message decryption. For example, the government can subpoena a person to testify before a grand jury and bring the private key and/or a decrypted version of a seized message. The government can thereby compel decryption or the production of the private keys that will decrypt an encrypted message,35 unless the person exercises a valid privilege.36 If a person, without a valid privilege, refuses to comply with a lawful subpoena, punishment can include criminal contempt37 or an indeterminate fine and jail sentence.38 Lying to the court in response to a subpoena would expose a person to criminal perjury charges39 along with a possible contempt charge.40 Therefore, the history of the Fifth Amendment privilege against self-incrimination must be examined to determine whether a person, without immunity, can resist compelled decryption where such testimony could potentially be used to incriminate her at trial.

III. Applying the Fifth Amendment to Compelled Document Decryption

The Fifth Amendment provides that “no person . . . shall be compelled in any criminal case to be a witness against himself.”41 This privilege against self-incrimination has historically functioned to protect a “‘natural individual from compulsory incrimination through his own testimony or personal records.’”42 The Fifth Amendment, in conjunction with the exclusionary rule,43 prevents the government from gathering evidence in violation of the Fifth Amendment or using that evidence at trial.44

The type of privacy provided by strong encryption has precedent in America. During the time our Constitution developed, government officials regularly lacked direct access to secret communications.45 At the adoption of the Bill of Rights, “private communications were far more secure than they are today [because] one could have a secure conversation by going for a quiet walk in an open field.”46 At the end of the 18th century, government agents had no long distance microphones, body wires, or hidden tape recorders. Also, people would “encrypt letters in ciphers that no government could break.”47 One encryption system created by Thomas Jefferson48 near the end of the 18th century remained unbreakable for more than a century.49 In fact, “[m]odern encryption seems poised to re-create the functional equivalent of the privacy available in the late 1790s and to apply it to devices like telephones and modems, which are increasingly replacing face-to-face contact and letter writing.”50

While secrecy shrouded many communications, the framers of our Constitution most assuredly knew that crime existed and that criminals communicated in secret.51 Yet, half the Bill of Rights limits the government’s power to prosecute criminals.52 With privacy and crime existing simultaneously, the Fifth Amendment was ratified with full knowledge that criminals could and would take advantage of any limitation on government’s ability compel them to become witnesses against themselves. The privilege against self-incrimination was created in reaction to abuses of power by King George III,53 and sought to limit prosecutorial abuse. Nothing of constitutional magnitude has altered this state of affairs since the Bill of Rights’ ratification.54

Further, despite its potential for abuse by criminals, the privacy protected by the Fifth Amendment’s privilege against self-incrimination has many benefits.55 The United States Supreme Court outlined these benefits in interpreting the scope of the privilege in Murphy v. Waterfront Comm’n of New York Harbor.56 In Murphy, union officials refused to testify, even with a state grant of immunity, because federal prosecution remained possible. The Court reversed the New Jersey Supreme Court in holding that, “the constitutional privilege against self-incrimination protects a state witness against incrimination under federal as well as state law and a federal witness against incrimination under state as well as federal law.”57 The Murphy Court recognized that the privilege may sometimes be “a shelter to the guilty” but that it is “often a protection to the innocent.”58 Some criticize the privilege for preventing compulsory process and thus preventing innocent defendants from exonerating themselves by grilling the guilty.59 However, the Murphy Court, with no dissent, found the privilege justified the privilege for numerous reasons,60 including its “unwillingness to subject those suspected of crime to the cruel trilemma of self-accusation, perjury or contempt.”61

IV. Compelled Decryption or Production of Private Keys Implicates the Fifth Amendment

An assertion of the privilege against self-incrimination is nullified where the government provides use and derivative-use immunity.62 This immunity removes any danger of prosecution due to the person’s compelled testimony. Therefore, such a grant of immunity is “coextensive with the scope of the privilege against self-incrimination.”63 Some scholars, most prominently Phillip R. Reitinger,64 have argued that compelled decryption of documents can occur without a grant of use and derivative-use immunity because providing immunity for the act of producing the decrypted document or private key will satisfy the privilege against self-incrimination.65 Mr. Reitinger warned that because cryptology “restricts the ability of law enforcement to protect the public from the depredations of criminals,” compelled production “is a minimal accommodation to the need for public security.”66

Despite contrary assertions,67 the Fifth Amendment’s privilege against self-incrimination prevents the government from compelling either decryption of encrypted documents or production of a private key unless use and derivative-use immunity is granted or the government has met, by clear and convincing evidence, the three-prong test from Fisher v. United States.68 Mr. Reitinger concluded that immunity need not be granted by using the Fisher test in determining whether compelled production will violate the privilege against self-incrimination. Aside from one error,69 Mr. Reitinger correctly enumerated how the Fisher Court held that compelled production of documents may implicitly communicate incriminating facts where the act will: “(1) concede the existence of a document; (2) concede possession, location, or control of a document; [or]70 (3) assist in authentication of a document.”71 Compelled decryption or production of private keys may infringe on all of the three above concerns, thereby causing such compelled testimony to implicitly communicate incriminating facts and thus violate the Fifth Amendment’s privilege against self-incrimination. In sum, under Fisher, the government can compel message decryption or private key production only where it proves that the requested document or private key: (1) exists; (2) was possessed, located or controlled by the person it is requested from; and (3) will not have its authentication assisted by this decryption or production.72

(A) Standard of Proof

(1) The Burden of Proving Compelled Production of Message Decryption or Private Key Production Must Rest With the Government

The government must bear the burden of proving each of the three prongs from Fisher. This burden is necessary to enforce the right to be free from self-incrimination and the presumption of innocence.73 This burden is also important because the proliferation of encrypted documents means that many innocent people use them74 and encrypted documents may soon bear great similarity to plaintext documents. The government must meet its burden before compelling a person to decrypt a message.75 If such a rule is not adopted, the government could point to any encrypted document it discovers and compel the purported author, under the penalty of perjury or contempt, to decrypt the document or provide the private key for such decryption. Such prosecutorial power could facilitate oppressive intrusion into every American’s life. Despite the good intentions of those involved today,76 and even though such intrusion could sometimes ensnare the guilty,77 any such action must be struck down as unconstitutional.

(2) The Standard of Proof Must Be Clear and Convincing Evidence

Taking up a challenge offered by Professor Lance Cole,78 I eschew the D.C. Circuit’s “reasonable particularity” test79 to posit that the government’s burden here must demand that the government establish proof by clear and convincing evidence on each prong.80 The D.C. Circuit’s use of the standard given when a police officer decides to commit a pat down for weapons during a Terry stop81 is widely inapposite to this situation. In Terry, the Court considered a situation where an officer justifiably “believ[ed] that the individual whose suspicious behavior he is investigating at close range is armed and presently dangerous to the officer or to others,”82 when the Court held that “it would appear to be clearly unreasonable to deny the officer the power to take necessary measures to determine whether the person is in fact carrying a weapon and to neutralize the threat of physical harm.”83 Conversely, in compelled production situations, the police will be investigating at long range, not at close range. Also, the persons targeted by these subpoenas may not even be engaged in any suspicious behavior. Finally, a litigant who has gone to court to quash a subpoena cannot be automatically considered an armed and dangerous threat. There will be no exigency in these cases comparable to the dangers faced by police during a Terry stop situation. Yet, even if there was some exigency, it would only be proper for the court to approve of a “limited search of the outer clothing for weapons.” 84 This pat down “constitutes a severe, though brief, intrusion upon cherished personal security, and it must surely be an annoying, frightening, and perhaps humiliating experience,”85 but it would not be as broad as the intrusion that would occur if the government, upon meeting the mere “reasonable particularity test” could force any person to produce a broad range of documents, heretofore unknown of by the government, without a grant of immunity and then prosecute the person based upon any potential law violations uncovered through these disclosures.

While any subjective ranking of immutable constitutional rights could be questioned, a person’s interest in avoiding compelled self-incrimination must be at least as important as the right to avoid pretrial detention. Thus, the clear and convincing standard is appropriate because the Fifth Amendment interest against self incrimination at stake is comparable to that in pre-trial detention cases where the government, to overcome the Fifth Amendment due process liberty interest, must demonstrate a sufficiently compelling governmental need by clear and convincing evidence.86 Similarly, the Fifth Amendment privilege against compelled self-incrimination can be compared to the Sixth Amendment right to counsel.87 If the standard of proof here was less demanding than clear and convincing, the presumption of innocence and privilege against self-incrimination could be overridden by a governmental fishing expedition.88

(B) Applying the Fisher Test

(1) Proving that a Documents Exists

The first prong of the Fisher test is whether the compelled testimony will concede that a potentially incriminating document exists. A prosecutor’s bare assertion that a document exists cannot establish a document’s existence as a matter of law. Mr. Reitinger’s claim that whenever law enforcement has seized a potentially encrypted document, the existence of this document is “a foregone conclusion” undoubtedly “misreads Fisher and ignores [the Court’s] subsequent decision in United States v. Doe.”89 The Fisher Court forced a taxpayer’s lawyer to produce the workpapers of the client’s accountant. The Court held that the existence of the tax documents was “a foregone conclusion” because “the Government already knew that the documents were in the attorneys’ possession and could independently confirm their existence and authenticity through the accountants who created them.”90 The Fisher Court did not compel decryption of documents the government could not otherwise use against her in a criminal trial. Notably, the Fisher Court focused on a narrow subpoena of business records that did not involve the production of any personal documents.91 The point in Fisher, reiterated in Doe and Hubbell, is that the government must “independently confirm the existence and authenticity” of targeted documents before it can compel production.92

Undoubtedly, the government will sometimes independently prove the existence of encrypted documents. For example, the government often obtains, via a search warrant or otherwise, a defendant’s hard drive either encrypted in its entirety or containing certain encrypted folders or documents. A court may be convinced that encrypted documents exist that can be accessed only with a private key.But there is one important corollary to the principle requiring proof of the existence of the documents the government seeks to access: unless the government had the defendant under intrusive surveillance,93 it cannot prove that it has seized every single document that can be decrypted with this private key.

While claiming that production can be compelled from someone with access to an encrypted document, Mr. Reitinger argued that “production of keys is, for the most part, equivalent to the act of producing the decrypted document.”94 Mr. Reitinger later explained that while “a key has no substantive meaning at all,” he conceded that “act-of-production immunity should be necessary . . . only because possession of the key tends to demonstrate a connection between the possessor of the key and the underlying document.”95 It is for this implied connection between the possessor and the underlying document that production of private keys cannot be compelled. Because existence must be proven before testimony can be compelled, the privilege can only be overcome regarding documents whose existence has been proven. But compelling production of a private key would facilitate decryption of any and all communications encrypted with this private key, even those documents whose existence has not been proven. A person will likely often use one public/private key set to encrypt all her communications.96 Therefore, compelling private key disclosure can never be equivalent to compelled document decryption.97 Compelling private key production will always be a greater intrusion than compelled document decryption.98 Private key production would give the government access both to documents whose existence were proven99 and provide access (while authenticating) documents the government did not know about.100

(2) Proving Possession, Location or Control: Rejecting the “Manna from Heaven” Approach101

The second prong of the Fisher test is whether the compelled testimony concedes possession, location, or control of a potentially incriminating encrypted document or private key to decode the document. The government must bear the burden of independently proving this prong. If it does not, in the absence of use and derivative-use immunity, compelled testimony would infringe on the privilege against self-incrimination. In Fisher, the Court approved compelled production of tax records because possession, location, or control over these documents was proven because it was not disputed that the accountants who created the records were available to testify.102

It does not logically follow that a person with possession or control of certain encrypted documents, even where access to these documents has been proven, is the only one with the private key to decrypt these documents.103 It will be difficult for the government to prove that each document it seeks has been possessed, located, or controlled by the person from whom decryption is demanded. Besides surveillance or independent testimony, for example from an informant, the only way the government could meet this prong would be to force a person to answer whether she has accessed the documents or whether she alone has the private key to decrypt these documents,104 two questions that implicate the Fifth Amendment by forcing a person to authenticate possible evidence against her.

Fisher is also distinguishable from this compelled decryption case for other important reasons. The Fisher Court explained that the applicability of the privilege against self-incrimination will “depend on the facts and circumstances of particular cases or classes thereof.”105 First, Fisher involved the disclosure of tax papers which had been prepared by someone else, not private papers.106 The special nature of private papers has been long recognized by the Court,107 a recognition that must not be diminished simply because these private papers are stored in a computer. Second, and most importantly for this article, it is uncontested that decrypting a document and bringing it in under compulsion will communicate incriminating facts by conceding “possession, location, or control of a document.”108 Mr. Reitinger agreed that the potential for government exploitation of compelled self-incrimination was so explicitly present that there may be no option other than providing act-of-production immunity for these disclosures.109

Where act-of-production immunity is provided, it was believed that a person’s Fifth Amendment rights could be protected by treating this evidence produced under compulsion as if it had “magically appeared in grand jury room.”110 This is the “manna from heaven” treatment of compelled disclosure.111 This “long advocated government position”112 was soundly rejected in Hubbell.113 The Court told the prosecution that the Fifth Amendment’s privilege against self-incrimination meant that the government could not compel Mr. Hubbell to produce documents, under a grant of immunity, and then prosecute him based upon these disclosures.114 The Court criticized the government’s “anemic view of respondent’s act of production as a mere physical act that is principally non-testimonial in character and can be entirely divorced from its ‘implicit’ testimonial aspect.”115 In sum, the Hubbell Court held the “manna from heaven” approach inappropriate.116

The Hubbell Court cited a part of Doe which Mr. Reitinger dismissed as dicta,117 when holding that “[t]he assembly of those documents was like telling an inquisitor the combination to a wall safe, not like being forced to surrender the key to a strongbox.”118 Hubbell held where a person asserts the privilege but is compelled after a grant of use and derivative-use immunity, no indictment derived from this information can survive.119 Analogous to Hubbell, compelled decryption may occur only after a grant of use and derivative-use immunity, such as provided for in 18 U.S.C. §6002.120 Unless the government makes a narrow request for certain documents,121 and meets the Fisher test, immunity must be granted. Using the Hubbell analysis, it appears that compelling a person to decrypt documents whose contents are unknown to the government is like the constitutionally impermissible act of compelling a person to provide “a combination to a wall safe.”122 Compelled disclosure of a private key is like forcing a person to provide combinations to multiple wall safes she has used in the past, even those the government is unaware of, and to future wall safes (namely, those created whenever someone uses her public key). The wall safe analogy is impenetrable when considering compelled production of a memorized private key.123

(3) Proving Lack of Authentication: Facing the Cruel Trilemma of Self-accusation, Perjury or Contempt

The third prong of the Fisher test is whether compelled testimony will help authenticate a potentially incriminating document or the private key to decrypt this document. Therefore, the government cannot rely on non-immunized compelled decryption of a document to authenticate itself because it bears the burden of independently authenticating a document to avoid infringing on the privilege against self-incrimination. Mr. Reitinger recognized that “the government could use possession of the key to prove the possession or authenticity of the underlying document.”124 But he mistakenly claimed that authentication of a key, and thus authentication of the document it decodes “is a foregone conclusion” and can always be relied upon because proof of “possession of the key, combined with the fact that the key does decrypt the [encrypted document], establishes that … [this is the] key to the document.”125 Such a position simply eviscerates the privilege against self-incrimination by removing the government’s burden to independently verify the authentication of the document.

Compelled testimony cannot be the sole source to verify the authenticity of that same compelled testimony or else the Fifth Amendment would only protect the innocent.126 The privilege against self-incrimination protects the innocent and guilty alike.127 The presumption of innocence is a founding principle of the rule of law in the United States.128 Just as the Fourth Amendment does not exclude illegally gained evidence against only the factually innocent,129 the Fifth Amendment’s privilege must extend to all those accused of crime, 130 especially while the presumption of innocence remains sacrosanct.131 The privilege against self-incrimination has long prevented the government from asking a person about the “existence of sources of potentially incriminating information.”132 The Kastigar Court held that the privilege “protects against any disclosures that the witness reasonably believes could be used in a criminal prosecution or could lead to other evidence that might be so used.”133 The Reiner Court reiterated that the privilege “extends not only ‘to answers that would in themselves support a conviction . . . but likewise embraces those which would furnish a link in the chain of evidence needed to prosecute the claimant.’”134 The Court added that “[i]t need only be evident from the implications of the question, in the setting in which it is asked, that a responsive answer to the question or an explanation of why it cannot be answered might be dangerous because injurious disclosure could result.”135 The questions ‘decrypt these documents for us’ or ‘produce a private key to decrypt these documents’ infringes on the privilege unless the third prong has been established by proof that this compelled decryption or private key production will not help authenticate the produced document or private key. The government may counter that authentication is near impossible without access to a decrypted message. Therefore, where the government establishes the first two Fisher prongs, it can proffer in camera (possibly ex parte), the independent proof of authentication it has. The court will then review the document in question136 to determine if it has been independently authenticated and thus whether immunity is required for compelled decryption.

(4) Disclosing by Word or Deed

Compelled testimony about a private key or the existence of incriminating evidence such as decrypted documents, even where it has met the three-prong Fisher test, must involve act-of-production immunity or else the person questioned would impermissibly face “the cruel trilemma of self-accusation, perjury or contempt.”137 Unless the government provided act-of-production immunity, a person compelled to provide this information would face this trilemma because such a disclosure would allow the government to introduce the evidence that this person produced this document at such and such a time upon a request from the government.

The Court, in both Doe and Hubbell, asserted that a suspect cannot “be compelled to reveal the combination to his wall safe -- by word or deed.”138 The government cannot avoid this prohibition by not requesting entry into the safe but by non-specifically requesting any and all contents of the safe. Nor could the government avoid this prohibition by simply seeking all combinations to any safes in a person’s possession.139 The private key to decode a message is analogous to the combination to a wall safe. Therefore, if the government cannot either secure or break the password required to translate encrypted documents, it cannot simply request all encrypted documents in a person’s possession unless it provides use and derivative-use immunity.140 Since the government cannot force a non-immunized141 suspect to disclose the combination to a wall safe, it cannot compel a person to disclose all of her encrypted messages.

Compelling production of a memorized private key can never be permissible. Such an act is particularly analogous to the forbidden act of compelling production of “the combination to a wall safe.”142 Mr. Reitinger recognized that “memorized passwords might defeat the government’s subpoena power,” but quickly dismissed this proposition. He believed that private keys small enough to be memorized could now be broken by brute force attacks.143 He thought that a person could be compelled to turn over their private key or decrypt documents, with the government only providing act-of-production immunity, because keys “too long to be memorized” would be “stored on a computer, in encrypted form for security.”144 Production of the key could be compelled because “the plaintext of a key stored in encrypted form in hardware or software is itself a document subject to subpoena.”145 But, he failed to note that even a stored private key can only be compelled after satisfaction of the three-prong Fisher test.146

Even where the government can independently confirm “the existence, possession, and authenticity of the subpoenaed documents”147 by clear and convincing evidence,148 Mr. Reitinger’s own analysis demonstrates that the government cannot compel disclosure of memorized public keys without providing use and derivative-use immunity. Memorized public keys may proliferate due to a combination of biometric security procedures with memorized passwords. Biometric identifiers may even soon serve as a private key itself. These methods provide security to any person who seeks privacy for private keys and encrypted documents.149 In either situation, the password created can only be disclosed if a person is compelled to orally state a memorized word while providing her palm print, iris scan, and/or DNA sample. Therefore, to gain access to encrypted information, the government must compel specific oral testimony before a grand or petit jury, along with other actions.150 A person can be compelled to talk, get fingerprinted, or provide a DNA sample, but not compelled to recite from memory something she has an expectation of privacy in.151 Compelled production of memorized, private keys and documents encrypted in such a manner would be impermissible without the granting of use and derivative-use immunity.152

V. Conclusion

Why can the government compel a suspect to hand over a physical key to a strongbox,153 but it cannot compel a suspect to recite, from memory, a private key to gain access to a virtual strongbox?154 The Fifth Amendment’s privilege against self-incrimination guarantees “personal control over the production of cognitive evidence, free of official coercion.”155 Unless this constitutional principle is altered, the government must rely on other methods of crime control. For example, the police have “untrammeled authority to unleash informants on the population.”156 These “human bug[s]”157 are more likely to put the government in a position to prevent crimes, not just punish them after the fact through compelled testimony. The innocent should not need to live in fear of compelled privacy violations.158 Removing the privilege against self-incrimination is not and cannot be the government’s best solution to deter and punish crime.159



