Information Technology Act, 2000
Digital Signature and Electronic Signature: Sections 3 and 3A IT Act
Signatures are the hinge of the IT Act: Section 5 gives an electronic signature the same force as a handwritten one, but only if it is a signature the Act recognises. Section 3 recognises the digital signature, built on asymmetric cryptography; Section 3A, added in 2008, recognises any reliable electronic signature listed in the Second Schedule, including Aadhaar e-Sign. This note explains the technology and the law together: how digital signatures work, what the reliability test requires, how e-Sign operates, how electronic signatures differ from scanned images, typed names and OTPs, what legal effect they have, and how their forgery and misuse are punished.
1. A Seal Only You Can Press, a Lens Anyone Can Use
Imagine a wax seal that only you can press, because only you hold the stamp, and a special lens that anyone can use to check the seal is yours and the envelope unopened. A digital signature works like this: the private key is the stamp, the public key is the lens, and the hash is a fingerprint of the letter inside. If a single word changes, the fingerprint no longer matches, and the lens shows it.
2. Section 3: Authentication of Electronic Records
Section 3, Information Technology Act, 2000 (1) Subject to the provisions of this section any subscriber may authenticate an electronic record by affixing his digital signature. (2) The authentication of the electronic record shall be effected by the use of asymmetric crypto system and hash function which envelop and transform the initial electronic record into another electronic record. Explanation. For the purposes of this sub-section, 'hash function' means an algorithm mapping or translation of one sequence of bits into another, generally smaller, set known as 'hash result' such that an electronic record yields the same hash result every time the algorithm is executed with the same electronic record as its input making it computationally infeasible (a) to derive or reconstruct the original electronic record from the hash result produced by the algorithm; (b) that two electronic records can produce the same hash result using the algorithm. (3) Any person by the use of a public key of the subscriber can verify the electronic record. (4) The private key and the public key are unique to the subscriber and constitute a functioning key pair. |
- Asymmetric crypto system (s.2(1)(f)). A secure key pair: a private key to create a digital signature and a public key to verify it. What one key locks, only the other can open.
- Hash function. A one-way mathematical fingerprint: the same record always gives the same hash; the record cannot be rebuilt from the hash; and two different records should not give the same hash.
- Private key (s.2(1)(zc)). Kept secret by the subscriber, usually on a secure token; used to sign.
- Public key (s.2(1)(zd)). Published in the Digital Signature Certificate issued by a Certifying Authority; used by anyone to verify.
- Key pair (s.2(1)(x); s.3(4)). Mathematically related and unique to the subscriber.
3. The Digital Signature Process
Figure 1: Creating a digital signature
Figure 2: Verifying a digital signature
- Integrity. Because any change to the record changes its hash, a successful verification proves the record has not been altered since signing (the second limb of 'verify' in s.2(1)(zh))
- Authentication. Because only the subscriber's private key could have produced a signature that the public key opens, verification proves who signed (the first limb of 'verify')
- Non-repudiation. Since only the subscriber controls the private key, the subscriber cannot easily deny signing, which is why Section 42 makes the subscriber responsible for keeping the key secure.
- The certificate. A Digital Signature Certificate issued by a licensed Certifying Authority binds the public key to the subscriber's identity, and the Controller, as root, certifies the Certifying Authorities (see Topic 36)
4. Section 3A: Electronic Signature
Section 3A, Information Technology Act, 2000 (substance) (1) Notwithstanding anything contained in section 3, but subject to sub-section (2), a subscriber may authenticate any electronic record by such electronic signature or electronic authentication technique which (a) is considered reliable; and (b) may be specified in the Second Schedule. (2) An electronic signature or electronic authentication technique shall be considered reliable if (a) the signature creation data or the authentication data are, within the context in which they are used, linked to the signatory or, as the case may be, the authenticator and to no other person; (b) the signature creation data or the authentication data were, at the time of signing, under the control of the signatory or the authenticator and of no other person; (c) any alteration to the electronic signature made after affixing such signature is detectable; (d) any alteration to the information made after its authentication by electronic signature is detectable; and (e) it fulfils such other conditions as may be prescribed. (3) The Central Government may prescribe the procedure for ascertaining whether an electronic signature is that of the person by whom it is purported to have been affixed or authenticated. (4) The Central Government may, by notification, add to or omit from the Second Schedule any electronic signature or authentication technique, provided it is reliable. (5) Every such notification shall be laid before each House of Parliament. |
Figure 3: The five conditions of reliability
- Two requirements. The technique must be reliable under Section 3A(2) and specified in the Second Schedule. A reliable technique not yet listed is not an electronic signature under the Act.
- Electronic authentication technique. The Act recognises both signatures and authentication techniques, allowing methods that authenticate a person or record without a traditional signature form.
- Secure electronic signature (s.15). A stricter category: the signature creation data must be under the signatory's exclusive control at the time of signing and stored and affixed in the prescribed manner; secure signatures carry stronger presumptions (s.86 BSA)
5. The Second Schedule and Aadhaar e-Sign
- The Rules of 2015. The Electronic Signature or Electronic Authentication Technique and Procedure Rules, 2015, notified on 28 January 2015, added e-authentication using Aadhaar or other e-KYC services to the Second Schedule.
- Framework. The Controller of Certifying Authorities issues e-authentication guidelines and eSign API specifications, revised from time to time, including in 2019. Licensed Certifying Authorities operate as eSign service providers, and application service providers integrate e-Sign into their platforms.
- After the Aadhaar judgment. After the 2018 Aadhaar judgment limited private use of Aadhaar authentication, e-Sign continued through licensed Certifying Authorities, and the guidelines provide for Aadhaar and other permitted e-KYC modes.
Figure 4: How an e-Sign is created
- Under the hood. e-Sign is itself a digital signature: after e-KYC, the eSign service provider generates a one-time key pair, issues a short-lived certificate in the signer's name and signs the document's hash, then discards the private key. The signer needs no token.
- Where used. Account opening, loan documents, insurance proposals, tax and government filings and HR documents; subject to the First Schedule exclusions.
6. Comparisons
Figure 5: Signing methods compared
- Digital signature and electronic signature. Every digital signature is an electronic signature, but electronic signature is the wider, technology-neutral category (s.2(1)(ta))
- Electronic signature and scanned signature. A scanned image of a handwritten signature has no cryptographic link to the document and can be copied onto anything; it is not a Second Schedule technique, so it is not an electronic signature under the Act.
- Electronic signature and typed name. A typed name shows intent but is not linked to the signatory in the manner Section 3A(2) requires; it may evidence assent to a contract but cannot satisfy Section 5.
- Electronic signature and OTP. An OTP authenticates a user for a session or action; on its own it is not a statutory signature. When an Aadhaar OTP is used within e-Sign, the OTP is only the identity step, and the signature is the digital signature the eSign service provider creates.
7. Legal Validity of Electronic Signatures
- Equivalence (s.5). A legal requirement of signature is satisfied by an electronic signature affixed in the prescribed manner.
- Contracts (s.10A). Contracts are not unenforceable because they were formed electronically.
- Proof. Except for secure electronic signatures, the fact that an electronic signature is that of the subscriber must be proved (s.66 BSA); the court may direct verification using the public key (s.73 BSA); and the opinion of the Certifying Authority is relevant (s.41(2) BSA)
- Presumptions. Electronic agreements bearing electronic signatures are presumed concluded by affixing them (s.85 BSA); secure records and signatures are presumed unaltered and affixed with intent to sign (s.86 BSA); and information in a certificate is presumed correct (s.87 BSA)
- Limits. No electronic signature can validate a document in the First Schedule, such as a will or trust deed.
8. Forgery and Misuse of Electronic Signatures
Figure 6: Misuse of electronic signatures and the provisions that apply
- Identity theft. Fraudulent or dishonest use of another's electronic signature, password or unique identification feature is punishable under Section 66C with up to three years and fine up to ₹1 lakh.
- Forgery. Making a false electronic record, or affixing an electronic signature with intent to cause it to be believed that it was affixed by or with the authority of another, is making a false document and forgery under Sections 335 and 336 of the BNS.
- Certificates. Misrepresentation to obtain a certificate (s.71), publishing a false certificate (s.73) and publication for a fraudulent purpose (s.74) are offences.
- Subscriber's duty. A subscriber must take reasonable care to retain control of the private key, report compromise to the Certifying Authority without delay, and remains liable until then (s.42). The Certifying Authority must suspend or revoke a compromised certificate (ss.37 and 38)
⚠ Exam trap A signature must be both reliable and listed in the Second Schedule to count under Section 3A. Scanned signatures, typed names and OTPs, however convenient, are not electronic signatures under the Act. And remember the distinction between an electronic signature (s.3A) and a secure electronic signature (s.15), which attracts stronger presumptions. |
9. Quick Revision and Memory Aids
- 'Seal only you can press, lens anyone can use'. Private and public keys.
- 'Same in, same out; no way back; no twins'. The three properties of a hash function.
- 'Who and whether'. Authentication and integrity, the two limbs of 'verify'.
- 'Linked, controlled, signature-evident, content-evident, prescribed'. Section 3A(2)
- 'Reliable plus listed'. The two requirements of Section 3A.
- '28 January 2015'. Aadhaar e-KYC added to the Second Schedule.
- '66C steals, 335 and 336 forge'. Misuse and forgery.
10. Frequently Asked Questions
How does a digital signature ensure integrity and authentication?
The record's hash is signed with the subscriber's private key. The recipient recomputes the hash and opens the signature with the public key; if the two hashes match, the record is unaltered (integrity) and was signed with the subscriber's private key (authentication).
11. Related Topics
- Topic 6: Legal Recognition. Sections 4, 5 and 10A.
- Topic 13: Technology-Neutral Approach. Why Section 3A was added.