Information Technology Act, 2000

IT Security Procedure Rules 2004: Secure Digital Signature and Record

The Act draws a line between a valid digital signature and a secure one: every valid signature authenticates, but only a secure one earns the evidentiary presumptions that shift the burden to a challenger. Sections 14 to 16 set up the idea, and the Security Procedure Rules 2004 fill in what secure actually means, a private key held in a hardware token under the signatory's sole control. Topics 42 and 100 built the signature and evidence law; this note, as asked, covers the 2004 Rules on their own.

1. The Section 14 to 16 Scheme

Secure record, secure signature, prescribed procedure

Figure 1: Secure record, secure signature, prescribed procedure

  • Secure electronic record, Section 14. Where a security procedure has been applied to an electronic record at a specific point in time, the record is a secure electronic record from that time to the time of verification, a status fixed by procedure, not by mere existence.
  • Secure digital signature, Section 15. A digital signature is a secure digital signature if, by application of the prescribed security procedure, it was at the time affixed unique to the signatory, capable of identifying him, created in a manner or using means under his exclusive control, and linked to the record so that any alteration is detectable (Topic 42)
  • The prescribed procedure, Section 16. The Central Government prescribes the security procedure, taking into account the commercial circumstances, the nature of the transaction and the state of technology; the Security Procedure Rules 2004 are what it prescribed.

2. What the 2004 Rules Fix

  • The secure digital signature procedure. The 2004 Rules fix that a secure digital signature is one created by a smart card or a hardware security token holding the signatory's private key, using an asymmetric crypto system and a hash function to the stated standards, so the key never leaves the signatory's tamper-resistant control.
  • The hardware anchor. The defining requirement is exclusive control through hardware: a private key held in a token the signatory alone possesses and activates is what raises an ordinary digital signature to a secure one, the practical content of s.15's exclusive-control condition.
  • Secure electronic record. The Rules likewise supply the security procedure by which a record attains secure status under s.14, tying integrity to a verifiable procedure applied at a point in time.

3. Why Secure Status Matters

Ordinary against secure, and the evidentiary pay-off

Figure 2: Ordinary against secure, and the evidentiary pay-off

  • Ordinary against secure. Any valid digital signature authenticates a record; a secure one additionally earns the statutory presumptions, so the distinction is not about validity but about the evidentiary advantage at trial.
  • The presumptions. For a secure digital signature the evidence law presumes that it was affixed by the subscriber with the intention of signing the record, and, with the secure electronic record, that the record has not been altered, the s.85B-line presumptions carried into the BSA, which shift the burden to the party challenging it (Topics 42, 100)
  • The practical lesson. The security of a signature is a matter of how the key is held: hardware-token custody turns compliance into an evidentiary shield, while a key held insecurely leaves even a valid signature to be proved the hard way.

⚠ Exam trap

Keep the s.14 to 16 roles straight: s.14 secure electronic record, s.15 secure digital signature with its four conditions, s.16 the power to prescribe the procedure, and the Security Procedure Rules 2004 as what was prescribed, anchoring the private key in a smart card or hardware token. State the pay-off precisely: secure status is not about validity but about the presumptions, intention to sign and non-alteration, that shift the burden to the challenger, so the whole point of a secure signature is evidentiary.

4. Frequently Asked Questions

What makes a digital signature secure under the IT Act?

Section 15 provides that a digital signature is secure if, by application of the prescribed security procedure, it was at the time of affixing unique to the signatory, capable of identifying him, created in a manner under his exclusive control, and linked to the record so that any alteration is detectable. The Security Procedure Rules 2004, prescribed under Section 16, fix that procedure: the signature must be created using a smart card or hardware security token holding the private key, with an asymmetric crypto system and hash function, so the key stays in the signatory's exclusive control. Secure status earns the evidentiary presumptions of intention to sign and non-alteration.

5. Related Topics

  • Topic 42: Validity and Misuse of Signatures. The secure-signature presumptions in evidence.
  • Topic 100: Hash Value vs Digital Signature. The cryptography beneath the signature.