Information Technology Act, 2000
CCA, e-Authentication and eSign: The Digital Trust Ecosystem Explained
Behind every legally effective electronic signature sits a trust machine: a Controller at the apex, a chain of Certifying Authorities beneath, and, for the ordinary user, the eSign service that issues a signature in seconds after an Aadhaar or e-KYC check. The CCA's e-authentication guidelines are what make that instant signature reliable in law. Topics 49 to 52 built the CCA and certificate sections; this note, as asked, covers the e-authentication and eSign ecosystem in depth.
1. The Trust Stack
Figure 1: Controller, chain, service and guidelines
- The Controller. The Controller of Certifying Authorities licenses and supervises the Certifying Authorities, lays down standards, and holds the Root Certifying Authority of India (RCAI) at the apex of the national trust hierarchy, the ss.17 to 20 office (Topic 49)
- The trust chain. RCAI signs the certificates of the licensed Certifying Authorities; each CA signs the subscriber's Digital Signature Certificate; a verifier climbs the chain, subscriber to CA to RCAI, to confirm a signature, the ss.35 to 39 certificate scheme in operation (Topics 50, 51)
- The eSign online service. An online electronic signature service that lets a user sign without holding a long-term certificate or token: the user authenticates through Aadhaar or other e-KYC, and a licensed CA, acting as an eSign service provider, issues a one-time key pair, certifies it and signs the record on the spot (Topics 41, 129)
- The e-authentication guidelines. The CCA's e-authentication technique and procedure guidelines fix how this is done reliably: one-time key generation, a short-lived certificate, e-KYC authentication and audit logging, the technical content of the Second Schedule technique (Topic 129)
2. The eSign Specification
Figure 2: What the CCA guidelines fix
- One-time key pair. A key pair is generated afresh for each transaction, used once for the single signing and not retained by the signer, so there is no long-lived private key for the user to guard or lose.
- Short-lived certificate. The Digital Signature Certificate issued for the signing is short-validity, on the order of thirty minutes, long enough to sign and verify and no longer, which bounds the window of misuse.
- e-KYC authentication. The signer is authenticated by Aadhaar or other e-KYC, through OTP or biometric verification, binding the one-time signature to a verified identity, the step that supplies the s.3B linkage and control conditions (Topic 129)
- Audit logs. The eSign service provider and the CA retain audit logs of the authentication and issuance for the period the guidelines prescribe, in the order of seven years, so a signature can be reconstructed and proved long after the key has expired.
- The legal effect. Because the technique is a notified Second Schedule technique meeting the s.3B reliability conditions, an eSign signature is a valid electronic signature with the same legal recognition under s.5 as a token-based digital signature (Topics 129, 132)
⚠ Exam trap Describe the trust chain in order, RCAI signs the CA, the CA signs the subscriber's DSC, verification climbs back up, with the Controller holding RCAI at the apex. For eSign, quote the four features the CCA guidelines fix, a one-time key pair not retained, a short-lived certificate of about thirty minutes, Aadhaar or other e-KYC authentication, and audit logs kept around seven years, and tie its legal validity to the Second Schedule technique meeting the s.3B reliability conditions, so eSign is a full electronic signature under s.5, not a lesser substitute. |
3. Frequently Asked Questions
What is the eSign service and how does it work?
eSign is an online electronic signature service that lets a user sign a document without holding a long-term key or hardware token. The user authenticates through Aadhaar or other e-KYC by OTP or biometric verification, and a licensed Certifying Authority acting as an eSign service provider generates a one-time key pair, issues a short-validity certificate of around thirty minutes, signs the record, and retains audit logs for the period the CCA guidelines prescribe. Because the e-authentication technique is notified in the Second Schedule and meets the Section 3B reliability conditions, the resulting signature is a valid electronic signature with full legal recognition under Section 5.
4. Related Topics
- Topic 49: Controller of Certifying Authorities. The CCA and the trust hierarchy.
- Topic 129: Section 3B and the Second Schedule. The reliability basis of eSign.