Evidence Law: Indian Evidence Act, 1872 / Bharatiya Sakshya Adhiniyam, 2023 (BSA)

Proof of Electronic Signature under Section 66 of the Bharatiya Sakshya Adhiniyam, 2023: The Secure Signature Exception

Section 66 is one sentence long and its entire operation turns on five words. An electronic signature must be proved — except in the case of a secure electronic signature. Whether a signature is secure therefore decides whether a party must prove it or may rely on presumptions that are among the strongest in the statute, and establishing the security of a signature is the first step rather than an afterthought.

1. The Provision

Section 66, BSA — Proof as to electronic signature

Except in the case of a secure electronic signature, if the electronic signature of any subscriber is alleged to have been affixed to an electronic record, the fact that such electronic signature is the electronic signature of the subscriber must be proved.

Section 66 corresponds to Section 67A of the Indian Evidence Act, inserted by the Information Technology Act, 2000, and is carried forward unchanged.

It is the electronic counterpart of Section 65, which requires the signature or handwriting of a person alleged to have signed a document to be proved. The rule is the same; what is different is the exception, which has no counterpart in the world of pen and paper.

Three expressions in the section are defined elsewhere. Section 2(2) of the Adhiniyam provides that words used but not defined in it, and defined in the Information Technology Act, 2000, the Bharatiya Nagarik Suraksha Sanhita, 2023 and the Bharatiya Nyaya Sanhita, 2023, have the meanings assigned to them in those enactments. Electronic signature, secure electronic signature and subscriber all take their meanings from the Information Technology Act.

2. Electronic Signature and Digital Signature

The section uses the wider of the two expressions, and the distinction should be checked rather than assumed.

Digital signature means authentication of an electronic record by a subscriber by means of an electronic method or procedure in accordance with Section 3 of the Information Technology Act — that is, by an asymmetric crypto system and hash function.

Electronic signature means authentication by means of the electronic technique specified in the Second Schedule to that Act, and includes a digital signature. It is the genus; the digital signature is a species of it.

Section 66 speaks of an electronic signature and so covers both. Section 73, by contrast, speaks of a digital signature and is framed around public-key verification; it does not fit a signature effected by some other technique in the Second Schedule, for which there may be no public key to apply.

3. What Makes a Signature Secure

The exception depends entirely on this, and it is a question of fact to be established.

Section 15, Information Technology Act, 2000 — Secure electronic signature

An electronic signature shall be deemed to be a secure electronic signature if — (i) the signature creation data, at the time of affixing signature, was under the exclusive control of the signatory and no other person; and (ii) the signature creation data was stored and affixed in such exclusive manner as may be prescribed.

Section 14, Information Technology Act, 2000 — Secure electronic record

Where any security procedure has been applied to an electronic record at a specific point of time, then such record shall be deemed to be a secure electronic record from such point of time to the time of verification.

Two elements are therefore required for a secure electronic signature. The signature creation data — in a digital signature, the private key — must have been under the exclusive control of the signatory at the moment of affixing. And it must have been stored and affixed in the exclusive manner prescribed.

⚠ Exclusive control is the whole of the requirement

Where the private key or credential was stored on a shared computer, where the passphrase was known to an assistant, or where a signing token was kept in an office drawer, the signature creation data was not under the exclusive control of the signatory, and the signature was not secure. The presumptions then fall away and Section 66 requires the signature to be proved in the ordinary way. This is the point at which most challenges to electronic signatures begin, and it is a question of fact on which evidence is led.

4. The Presumptions Where the Signature Is Secure

Where the exception applies, three provisions in the presumption group do the work of proof.

Sections 85, 86 and 87, BSA

Section 85 — where an electronic record purports to be an agreement containing the electronic signature of the parties, the Court shall presume that the agreement was concluded by affixing the electronic signature of the parties.

Section 86 — in any proceeding involving a secure electronic record, the Court shall presume, unless the contrary is proved, that the secure electronic record has not been altered since the specific point of time to which the secure status relates; and in any proceeding involving a secure electronic signature, the Court shall presume, unless the contrary is proved, that the secure electronic signature is affixed by the subscriber with the intention of signing or approving the electronic record.

Section 87 — the Court shall presume, unless the contrary is proved, that the information listed in an Electronic Signature Certificate is correct, except for information specified as subscriber information which has not been verified, where the certificate was accepted by the subscriber.

These correspond to Sections 85A, 85B and 85C of the Indian Evidence Act.

The strength of the scheme lies in the words shall presume. Under Section 2(1)(l), where the Adhiniyam directs a court to presume a fact, the court shall regard it as proved unless and until it is disproved. The burden therefore lies on the party challenging the signature, and it is not enough for him to raise a doubt — he must disprove.

Section 86 confers two distinct presumptions and the first is easily missed. The presumption about a secure record is one of integrity — that the record has not been altered since the secure status attached. No comparable presumption exists for paper documents at all, and it is the practical superiority of properly executed electronic instruments.

The presumption about a secure signature is one of intention — that it was affixed by the subscriber with the intention of signing or approving. This forecloses the argument that a signature was applied inadvertently or by some automated process without the subscriber's assent.

5. Proving a Signature That Is Not Secure

Where the signature is electronic but not secure, Section 66 requires it to be proved, and four routes are available.

5.1 The opinion of the Certifying Authority

Section 41(2), BSA — Opinion as to electronic signature

When the Court has to form an opinion as to the electronic signature of any person, the opinion of the Certifying Authority which has issued the Electronic Signature Certificate is a relevant fact.

Section 41(2) corresponds to Section 47A of the Indian Evidence Act and sits alongside Section 41(1), which admits the opinion of a person acquainted with handwriting.

The difference between the two is the point. A handwriting opinion rests on familiarity; an opinion under Section 41(2) rests on institutional knowledge. The Certifying Authority issued the credential, maintains the records of its issue, suspension and revocation, and can say what it certified, to whom, and whether the certificate was valid at the material time. There is no body that issues handwriting and can be asked about it, and this is a category of opinion with no counterpart in the world of paper.

5.2 Verification under Section 73

Section 73, BSA — Proof as to verification of digital signature

In order to ascertain whether a digital signature is that of the person by whom it purports to have been affixed, the Court may direct — (a) that person or the Controller or the Certifying Authority to produce the Digital Signature Certificate; (b) any other person to apply the public key listed in the Digital Signature Certificate and verify the digital signature purported to have been affixed by that person.

This is the electronic counterpart of Section 72, and the contrast is instructive. Under Section 72 the court compares, which is an exercise of judgment that State (Delhi Administration) v. Pali Ram, (1979) 2 SCC 158 cautions it should be slow to undertake alone. Under Section 73 the court directs a verification, which is a computation — the public key is applied, the hashes either match or they do not.

Section 73 applies to a digital signature. For an electronic signature effected by another technique, verification in this form may not be possible, and the routes are Section 41(2) and ordinary evidence.

5.3 Expert opinion

Section 39(1) makes relevant the opinion of a person specially skilled in any field, and the residuary words added by the Adhiniyam accommodate cryptography and cyber forensics without any need to argue that they are a 'science'. Where the question is whether a signature was validly generated, whether a certificate chain is intact, or whether a record has been altered since signing, an expert opinion is the route.

5.4 Ordinary evidence

Execution may also be established by the ordinary means. Evidence that the subscriber was operating the system at the time, that he acknowledged the document afterwards, that he acted upon it, or that he admitted signing it, all bear on the question, and an admission disposes of it entirely as against him.

6. The Key and the Person

This is the central limitation of the whole scheme, and it should be stated plainly because the mathematics can obscure it.

A digital signature establishes that the signature was created with a particular private key. The Electronic Signature Certificate establishes that the key was issued to a particular subscriber. Neither establishes that the subscriber affixed the signature — only that his key did.

Where the key was on a shared machine, where the credential was known to an employee, or where a signing token was accessible to others, the signature may be perfectly genuine and the person not the signatory. This is the electronic form of the attribution problem that runs through the whole of electronic evidence, and it is why exclusive control is an element of the definition of a secure signature rather than an afterthought.

The presumption in Section 86 carries a party to the point where the key is established and no further. It is expressed as operating unless the contrary is proved, and proof that the key was not under exclusive control displaces it.

7. Challenging an Electronic Signature

Five lines are available, and they should be taken in this order because each presupposes the failure of the one before.

  1. That the document could not be signed electronically at all. The First Schedule to the Information Technology Act excludes from electronic execution a negotiable instrument other than a cheque, a power-of-attorney, a trust, a will and any other testamentary disposition, and any contract for the sale or conveyance of immovable property or any interest in such property. Where the document is within these classes, the presumptions are irrelevant because the transaction was not validly effected.
  2. That the signature was not secure, the signature creation data not having been under the exclusive control of the signatory. This displaces Sections 86 and 87 and revives the requirement of proof under Section 66.
  3. That the certificate was not valid at the material time — expired, suspended or revoked. The Certifying Authority's records answer this, and Section 41(2) makes its opinion relevant.
  4. That the key was compromised or misused, so that the signature is genuine but the signatory is not the subscriber.
  5. That it was affixed without intention to sign or approve. Section 86 presumes the intention, but the presumption is in terms rebuttable.

⚠ The First Schedule exclusions are checked first, not last

A great deal of argument about the security of a signature is wasted where the document is one the law does not permit to be executed electronically at all. A will, a power of attorney, a trust deed and an agreement for the sale of immovable property remain paper instruments, and a will additionally requires an attesting witness under Section 67 whether or not it is registered. The status of the document should be established before anything is said about the signature.

8. Two Further Provisions

Section 93 supplies a presumption for older records. Where an electronic record purporting or proved to be five years old is produced from proper custody, the court may presume that the electronic signature which purports to be that of a particular person was so affixed by him or by a person authorised by him. This is the electronic counterpart of the thirty-year presumption in Section 92, and the shorter period reflects how quickly the ordinary means of proving an electronic record cease to be available — keys expire, certificates lapse, systems are replaced.

Section 63 and the certificate address a different question entirely and should not be confused with Section 66. Section 63 governs the admissibility of the electronic record to which the signature is affixed; Section 66 governs proof of the signature. A record may be perfectly admissible with its certificate in order, and its signature entirely unproved; or the signature may be secure and presumed, and the record inadmissible for want of a certificate. Both must be satisfied.

9. Section 65 and Section 66 Compared

Section 65 — handwriting

Section 66 — electronic signature

Rule

The signature or handwriting must be proved

The electronic signature must be proved

Exception

None in the section itself

Secure electronic signature — the presumptions operate instead

Opinion route

Section 41(1) — a person acquainted with the handwriting

Section 41(2) — the Certifying Authority which issued the certificate

Court's own power

Section 72 — comparison, an exercise of judgment

Section 73 — verification, a computation

Presumption with age

Section 92 — thirty years, from proper custody

Section 93 — five years, from proper custody

Integrity of the document

No presumption; alteration must be detected by examination

Section 86 presumes a secure record has not been altered

10. The Position Stated Shortly

  1. Section 66 is the electronic counterpart of Section 65, and requires an electronic signature to be proved.
  2. The exception is for a secure electronic signature, which turns on the signature creation data having been under the exclusive control of the signatory.
  3. Whether a signature is secure is a question of fact and is the first thing to establish, not an assumption.
  4. Where it is secure, Sections 85, 86 and 87 operate, and they are shall-presume provisions so the burden of disproof lies on the challenger.
  5. Section 86 presumes integrity as well as intention — that a secure record has not been altered, which has no counterpart for paper.
  6. Where it is not secure, four routes exist — the Certifying Authority's opinion under Section 41(2), verification under Section 73, expert opinion under Section 39(1), and ordinary evidence.
  7. The key is not the person. The scheme establishes that a key was used, and exclusive control is what connects the key to the subscriber.
  8. The First Schedule exclusions should be checked first — wills, powers of attorney, trusts, most negotiable instruments and contracts for the sale of immovable property cannot be executed electronically at all.

11. Related Topics and Provisions

Topic or provision

Connection

Electronic Signature and Digital Signature

The mechanism, the certificate framework and the presumptions in full

Proof of Signature and Handwriting — Section 65

The counterpart for paper documents

Proof of Documents — Sections 64 to 73

The block as a whole

Electronic and Digital Evidence — Sections 61 to 63

Admissibility of the record to which the signature is affixed

Sections 85 to 87 and 93, BSA

Presumptions as to agreements, secure records and signatures, certificates, and records five years old

Sections 41(2) and 73, BSA

The Certifying Authority's opinion, and verification of a digital signature

Sections 14, 15 and the First and Second Schedules, Information Technology Act, 2000

Secure records and signatures, and the excluded classes of document