Evidence Law: Indian Evidence Act, 1872 / Bharatiya Sakshya Adhiniyam, 2023 (BSA)

Electronic Signature and Digital Signature under the Bharatiya Sakshya Adhiniyam, 2023: Meaning, Proof and Presumptions

A handwritten signature does two things at once: it identifies the person who made it, and it ties him to the document he made it on. An electronic signature does both far better, because a properly implemented one also detects any subsequent alteration of the document โ€” something no pen can do. The Adhiniyam devotes a scattered but complete set of provisions to proving such signatures, and the presumptions attaching to the secure ones are among the strongest in the statute.

1. Two Expressions, Not One

The Adhiniyam does not define either expression. Section 2(2) provides that words and expressions used but not defined in the Adhiniyam, and defined in the Information Technology Act, 2000, the Bharatiya Nagarik Suraksha Sanhita, 2023 and the Bharatiya Nyaya Sanhita, 2023, have the meanings assigned to them in those enactments. The definitions therefore come from the Information Technology Act.

Digital signature is the narrower expression. It means authentication of an electronic record by a subscriber by means of an electronic method or procedure in accordance with Section 3 of the Information Technology Act, which prescribes authentication by an asymmetric crypto system and hash function.

Electronic signature is the wider expression, introduced by amendment in 2008. It means authentication of an electronic record by a subscriber by means of the electronic technique specified in the Second Schedule to that Act, and includes a digital signature.

Digital signature

Electronic signature

Provision

Section 3, Information Technology Act, 2000

Section 3A, Information Technology Act, 2000

Technique

Asymmetric crypto system and hash function

Any technique specified in the Second Schedule, and includes a digital signature

Relationship

A species

The genus

Examples

A signature affixed using a private key and a Digital Signature Certificate

A digital signature; and authentication techniques the Second Schedule prescribes, such as those based on electronic identity verification with a one-time password

โš  Every digital signature is an electronic signature; not every electronic signature is digital

The relationship is one of genus and species, and it matters because the Adhiniyam uses both expressions. Section 41(2) and Section 66 speak of an electronic signature โ€” the wider category. Section 73 speaks of a digital signature โ€” the narrower one. A provision framed around digital signatures does not automatically apply to every electronic signature, and the distinction should be checked rather than assumed.

2. How a Digital Signature Works

It is worth understanding the mechanism, because the evidentiary consequences follow directly from it and are otherwise difficult to explain.

A subscriber holds a pair of mathematically related keys โ€” a private key, which he alone controls, and a public key, which is published. To sign, the system computes a hash of the document and encrypts that hash with the private key; the encrypted hash is the signature and is attached to the document.

To verify, anybody decrypts the signature with the published public key, recovering the hash as it was at signing, and independently computes the hash of the document as received. If the two match, two things follow at once: the signature was created with the private key corresponding to that public key, and the document has not been altered since, because any alteration would change the computed hash.

The link between the public key and a person is supplied by a Digital Signature Certificate or Electronic Signature Certificate, issued by a Certifying Authority licensed by the Controller of Certifying Authorities under the Information Technology Act. The certificate is what converts a mathematical relationship into a statement about a person.

Two evidentiary consequences follow, and they are the reason the presumptions are as strong as they are. A digital signature establishes authentication โ€” the signature was made with a key associated with an identified subscriber. And it establishes integrity โ€” the document is unaltered since signing, which is something a handwritten signature can never show.

3. Proof โ€” Section 66

Section 66, BSA โ€” Proof as to electronic signature

Except in the case of a secure electronic signature, if the electronic signature of any subscriber is alleged to have been affixed to an electronic record, the fact that such electronic signature is the electronic signature of the subscriber must be proved.

Section 66 corresponds to Section 67A of the Indian Evidence Act. It states the ordinary rule and carves out the exception in the same breath.

The ordinary rule is that an electronic signature must be proved like any other signature. Its being electronic confers no advantage: the party alleging it must establish that it is the signature of the person alleged, and Section 65, which requires proof of the signature and handwriting of a person alleged to have signed a document, has its counterpart here.

The exception is for a secure electronic signature, and it is the whole point of the section. Where a signature is secure within the meaning of the Information Technology Act, the presumptions in Sections 86 and 87 do the work, and separate proof is not required.

4. Secure Electronic Signatures and the Presumptions

Three sections in the presumption group deal with electronic signatures, and together they make a secure signature very difficult to displace.

Sections 85, 86 and 87, BSA

Section 85 โ€” where an electronic record purports to be an agreement containing the electronic signature of the parties, the Court shall presume that the agreement was concluded by affixing the electronic signature of the parties.

Section 86 โ€” in any proceeding involving a secure electronic record, the Court shall presume, unless the contrary is proved, that the secure electronic record has not been altered since the specific point of time to which the secure status relates; and in any proceeding involving a secure electronic signature, the Court shall presume, unless the contrary is proved, that the secure electronic signature is affixed by the subscriber with the intention of signing or approving the electronic record.

Section 87 โ€” the Court shall presume, unless the contrary is proved, that the information listed in an Electronic Signature Certificate is correct, except for information specified as subscriber information which has not been verified, where the certificate was accepted by the subscriber.

These correspond to Sections 85A, 85B and 85C of the Indian Evidence Act.

The strength of the scheme lies in the words shall presume. Under Section 2(1)(l), where a fact is directed to be presumed, the court shall regard it as proved unless and until it is disproved. The burden therefore lies on the party challenging the signature, and it is not enough for him to raise a doubt โ€” he must disprove.

โš  The presumptions attach to secure signatures, not to all

Section 86 operates on a secure electronic record and a secure electronic signature, and those are defined terms in the Information Technology Act, depending on the security procedures applied. A signature that is electronic but not secure does not attract the presumption, and Section 66 then requires it to be proved. Establishing that a signature was secure is therefore the first step, not an afterthought, and it ordinarily requires evidence about the technique used and the certificate under which it was affixed.

Section 86 also carries a second limb of considerable importance. The presumption about a secure electronic record is that it has not been altered since the point of time to which the secure status relates. This is an integrity presumption and it has no counterpart for paper documents at all.

5. The Opinion of the Certifying Authority

Section 41(2), BSA โ€” Opinion as to electronic signature

When the Court has to form an opinion as to the electronic signature of any person, the opinion of the Certifying Authority which has issued the Electronic Signature Certificate is a relevant fact.

Section 41(2) corresponds to Section 47A of the Indian Evidence Act, and it sits alongside Section 41(1), which admits the opinion of a person acquainted with a person's handwriting.

The parallel is instructive and the difference is the point. A handwriting opinion under Section 41(1) rests on familiarity โ€” the witness has seen the person write, or has corresponded with him, or has had his documents habitually submitted. An opinion under Section 41(2) rests on institutional knowledge: the Certifying Authority issued the credential, holds the records of its issue and use, and can say what it certified and to whom.

This is a category of opinion with no counterpart in the world of paper. There is no body that issues handwriting and can be asked about it. The provision reflects the fact that an electronic signature depends on an institution in a way that a handwritten one does not.

6. Verification โ€” Section 73

Section 73, BSA โ€” Proof as to verification of digital signature

In order to ascertain whether a digital signature is that of the person by whom it purports to have been affixed, the Court may direct โ€” (a) that person or the Controller or the Certifying Authority to produce the Digital Signature Certificate; (b) any other person to apply the public key listed in the Digital Signature Certificate and verify the digital signature purported to have been affixed by that person.

Section 73 corresponds to Section 73A of the Indian Evidence Act, and it is the electronic counterpart of Section 72, under which the court may compare a disputed signature with one admitted or proved to be genuine and may direct a person present in court to write.

The comparison between the two provisions repays attention. Under Section 72 the court compares โ€” an exercise of judgment, which State (Delhi Administration) v. Pali Ram, (1979) 2 SCC 158 cautions it should be slow to undertake alone. Under Section 73 the court directs a verification, which is a computation. The public key is applied, the hashes either match or they do not, and there is no judgment to exercise.

This is the practical superiority of a digital signature over a handwritten one in litigation. A disputed handwritten signature produces a contest between experts with no certain outcome; a disputed digital signature produces a verification with a definite answer.

โš  Section 73 speaks of a digital signature

The section uses the narrower expression and is framed around the mechanism of public-key verification โ€” the production of the Digital Signature Certificate and the application of the public key. It does not fit an electronic signature effected by some other technique in the Second Schedule, for which there may be no public key to apply. For such signatures the routes are Section 41(2), the opinion of the Certifying Authority, and ordinary proof under Section 66.

7. The Five-Year Presumption

Section 93, BSA โ€” Presumption as to electronic records five years old

Where any electronic record, purporting or proved to be five years old, is produced from any custody which the Court in the particular case considers proper, the Court may presume that the electronic signature which purports to be the electronic signature of any particular person was so affixed by him or any person authorised by him in this behalf.

Section 93 corresponds to Section 90A of the Indian Evidence Act, and it is the electronic counterpart of Section 92, the thirty-year presumption for ordinary documents.

The difference in period is deliberate and reflects a difference in how the two kinds of record become unprovable. A paper document becomes unprovable when its executants and attestors die, which takes decades. An electronic record becomes unprovable much faster โ€” keys expire, certificates lapse, systems are replaced, providers close, and the persons who administered them move on. Five years is a realistic estimate of how long the ordinary means of proof survive.

The section is a may presume provision, so the court has a discretion, and it is conditional on proper custody, which must be established as a fact.

8. What Cannot Be Signed Electronically

The Information Technology Act, 2000 confers legal recognition on electronic signatures generally, but its First Schedule excludes certain classes of document from the operation of the electronic-execution provisions. The exclusions matter in practice and are frequently overlooked.

  • A negotiable instrument other than a cheque.
  • A power-of-attorney.
  • A trust.
  • A will and any other testamentary disposition.
  • Any contract for the sale or conveyance of immovable property or any interest in such property.

The evidentiary consequence is direct. A document within these classes purporting to be executed by electronic signature has not been validly executed, and the presumptions in Sections 85, 86 and 87 are of no assistance โ€” they presume things about a signature, not about the validity of a transaction the law requires to be effected otherwise.

The exclusion of wills is particularly worth noting alongside Section 67, under which a document required by law to be attested may not be used in evidence until an attesting witness has been called. A will remains firmly a paper instrument requiring attestation, and no electronic route to it exists.

9. Challenging an Electronic Signature

The presumptions are strong but rebuttable, and the lines of attack are defined by what the mechanism can and cannot establish.

That the signature was not secure. The presumptions in Section 86 attach only to a secure electronic signature. Establishing that the security procedure was not applied displaces them and throws the party back on proof under Section 66.

That the private key was compromised or misused. This is the central defence and the one the mechanism cannot answer. A digital signature establishes that a signature was affixed with the private key; it does not establish that the subscriber affixed it. Where the key was stored on a shared computer, where the credentials were known to others, or where the token was in another's possession, the signature may be genuine and the person not.

That the certificate was suspended or revoked at the time of signing, or had expired. The Certifying Authority's records answer this, and Section 41(2) makes its opinion relevant.

That the document falls within the First Schedule exclusions, so that the question of the signature does not arise.

That the signature was affixed without intention to sign or approve. Section 86 presumes the intention, and displacing it requires evidence โ€” but the presumption is in terms rebuttable.

โš  The key and the person are different things

This is the electronic equivalent of the attribution problem that runs through the whole of electronic evidence. The mathematics establishes that a particular key was used. Whose hand was on the token, and who knew the passphrase, is a question of ordinary evidence, and the statutory presumptions carry the party only to the point where the key is established. Where custody of the key is genuinely in issue, the presumption in Section 86 is displaced by proof rather than by assertion, but the enquiry is a real one.

10. The Position Stated Shortly

  1. The definitions come from the Information Technology Act, 2000, incorporated by Section 2(2) of the Adhiniyam.
  2. Digital signature is a species; electronic signature is the genus, and the Adhiniyam uses both expressions in different provisions.
  3. A digital signature establishes authentication and integrity, the second being something no handwritten signature can do.
  4. Section 66 requires an electronic signature to be proved, except where it is secure, in which case the presumptions operate.
  5. Sections 85, 86 and 87 are shall-presume provisions, so the burden of disproof lies on the challenger.
  6. Section 41(2) admits the opinion of the Certifying Authority โ€” a category with no counterpart in the world of paper.
  7. Section 73 permits verification rather than comparison, which is the practical superiority of a digital signature in litigation.
  8. The First Schedule to the IT Act excludes wills, powers of attorney, trusts, most negotiable instruments and contracts for the sale of immovable property from electronic execution.

11. Related Topics and Provisions

Topic or provision

Connection

Expert Opinion vs Opinion of a Person Acquainted with Handwriting

Section 41(1), the paper counterpart of Section 41(2)

Handwriting Expert Evidence

Section 72, comparison by the court, contrasted with verification under Section 73

Documentary Evidence โ€” General Principles

Proof of execution, and the requirements for attested documents

Hash Value and Integrity of Electronic Evidence

The hash function on which a digital signature depends

Electronic and Digital Evidence โ€” Sections 61 to 63

Admissibility of the record to which a signature is affixed

Sections 85 to 87 and 93, BSA

Presumptions as to electronic agreements, secure records and signatures, certificates, and records five years old

Sections 3, 3A, 5 and 15 and the First and Second Schedules, Information Technology Act, 2000

Definitions, legal recognition, secure signatures and the excluded classes of document