Information Technology Act, 2000
eSign Rules 2015: Electronic Signature Technique and Procedure Framework
Section 3A of the IT Act promised that any reliable electronic signature could be recognised, but only once it was added to the Second Schedule. For seven years after 2008 the Schedule was empty and the digital signature on a USB token was the only practical option. The Electronic Signature or Electronic Authentication Technique and Procedure Rules, 2015 filled that gap by adding eSign, a signature created online after e-KYC. Topic 37 explained how eSign works as a signature. This note studies the legal framework that surrounds it: the parent power, the Rules of 2015 and their companions, the Aadhaar framework of 2016, the widening to other e-KYC in 2019, and the CCA guidelines that govern day-to-day operation.
1. A Hotel Key Card, Not a House Key
A house key is cut once, carried for years and must be reported if lost. A hotel key card is issued at the desk after checking your ID, works for one stay, and is wiped when you leave, so losing it later matters little. The token DSC is the house key. eSign is the key card: identity is checked by e-KYC, a key pair is created for one signature, the certificate lives for at most 30 minutes, and the private key is destroyed after use.
Figure 1: Token DSC and eSign compared
2. The Parent Power
- Section 3A(1). A subscriber may authenticate an electronic record by an electronic signature or authentication technique that is reliable and specified in the Second Schedule.
- Section 3A(3) and (4). The Central Government may prescribe the procedure for ascertaining whether a signature is that of the person by whom it is purported to have been affixed, and may by notification add or omit any technique and procedure in the Second Schedule, provided it is reliable.
- Section 3A(5). Every such notification must be laid before each House of Parliament.
- Sections 10 and 87. Power to make rules on the type, manner and format of electronic signatures and on the standards Certifying Authorities must follow.
Figure 2: The layered legal framework of eSign
3. The Rules of 2015
Electronic Signature or Electronic Authentication Technique and Procedure Rules, 2015 (G.S.R. 61(E), 27 January 2015) (substance) Rule 1: short title; in force on publication in the Official Gazette. Rule 2: in the Second Schedule, the following entry is inserted. Description: e-authentication technique using Aadhaar e-KYC services. Procedure: authentication of an electronic record by e-authentication technique, which applies hash and asymmetric crypto system techniques and results in issue of a Digital Signature Certificate; a trusted third party service generates the key pair and stores it on a hardware security module; the Certifying Authority issues the certificate on the basis of e-authentication, the Aadhaar e-KYC verified particulars and the electronic consent of the applicant; and the service complies with the standards in the Information Technology (Certifying Authorities) Rules, 2000. |
- Made under. Section 3A(4), read with the power to add techniques to the Second Schedule.
- Key idea. Identity is established by e-KYC instead of paper verification, and the keys are held by a trusted service instead of the user.
- Companion notification. G.S.R. 62(E) of the same date amended the Information Technology (Certifying Authorities) Rules, 2000 to insert Form C, the electronic application for a certificate on the basis of Aadhaar e-KYC.
- Why it is still a digital signature. The output is a hash signed with a private key and backed by a CA certificate. The novelty lies in how identity is verified and where the key sits, not in the cryptography.
4. The Digital Signature (End Entity) Rules, 2015
- Notification. G.S.R. 660(E), published on 25 August 2015, under Section 87.
- Creation. Signing applies a hash function and the signatory's private key; date and time form part of the signature; counter and parallel signatures are permitted.
- Verification. A fresh hash is computed and matched; the certificate chain is traced to the Controller's self-signed root; revocation lists are checked unless the certificate is valid for less than an hour, which covers eSign.
- Long-term validation. Time stamps, nested where needed, keep a signature verifiable after the certificate expires.
- Standards. SHA-2 hashing, RSA keys of 2048 to 4096 bits, and CAdES, PAdES and XML signature formats.
5. How the Framework Operates
Figure 3: The participants in eSign
Figure 4: One eSign transaction, step by step
Figure 5: Safeguards required by the CCA Guidelines
- ESP. Only a licensed Certifying Authority may act as an eSign Service Provider, so every eSign certificate traces back to the Controller's Root CA.
- ASP. An application such as a bank, a government portal or a contract platform must be approved by an ESP and sign an undertaking with it. It sends only the document hash, not the document.
- Assurance levels. Certificates are issued only as e-KYC class certificates, single factor or multi-factor, depending on how the user authenticated.
6. The Aadhaar Framework of 2016 and Its Aftermath
- Aadhaar Act, 2016. The Aadhaar (Targeted Delivery of Financial and Other Subsidies, Benefits and Services) Act, 2016 and the Aadhaar (Authentication) Regulations, 2016 gave statutory footing to authentication and e-KYC, on which eSign depended.
- Puttaswamy (Aadhaar), (2019) 1 SCC 1. Decided in September 2018, the Court struck down Section 57 of the Aadhaar Act, which let private entities use Aadhaar authentication on the basis of a contract. Private use now needs a legal basis.
- 2019 amendments. The Aadhaar and Other Laws (Amendment) Act, 2019 allowed authentication by entities that UIDAI finds compliant with its privacy and security standards and that are permitted under another law made by Parliament or notified in the interest of the State; and in March 2019 the Second Schedule entry was widened to read e-authentication technique using Aadhaar or other e-KYC services.
Figure 6: How the framework developed
Figure 7: e-KYC modes recognised in the CCA Guidelines
⚠ Exam trap Do not say eSign is 'Aadhaar-only'. Since 2019 the Second Schedule covers Aadhaar or other e-KYC services, and the CCA Guidelines recognise offline Aadhaar, organisational and banking e-KYC. Also remember the Rules were made under Section 3A(4), not Section 87; it is Form C that came through an amendment to the Certifying Authorities Rules. |
7. Legal Significance
- Satisfies Section 5. An eSign signature is an electronic signature under Section 3A and so meets any legal requirement of a signature, subject to the First Schedule.
- Evidence. The CA's Form C archive, the e-KYC response code embedded in the certificate and the audit logs (kept at least seven years) are the proof if a signature is denied (see Topic 42)
- Mass adoption. Tax return verification, loan agreements, insurance proposals and court e-filing now rely on eSign, which is why the 2022 First Schedule change on regulated-entity promissory notes and powers of attorney mattered.
- Criticism. Dependence on one identity system; weak consent where a user simply enters an OTP sent by a lender's agent; and the absence of statutory detail, since most controls sit in guidelines rather than in the Rules themselves.
8. Quick Revision and Memory Aids
- 'House key vs hotel key card'. Token DSC vs eSign.
- '61 adds the entry, 62 adds Form C'. The two notifications of 27 January 2015.
- '660: create, verify, keep alive'. Digital Signature (End Entity) Rules.
- 'Hash, consent, key, certificate, destroy'. The eSign steps.
- '2019: or other e-KYC'. Widening of the Second Schedule.
9. Frequently Asked Questions
What did the 2015 Rules do?
They inserted into the Second Schedule of the IT Act the first recognised electronic authentication technique, e-authentication using Aadhaar e-KYC services, with its procedure. This created the legal basis for eSign.
10. Related Topics
- Topic 37: Digital and Electronic Signatures. How digital signatures and eSign work.
- Topic 42: Validity, Forgery and Misuse. Proving and protecting electronic signatures.