Information Technology Act, 2000
Section 3B IT Act: Electronic Signature Techniques and Reliability
The 2008 Amendment made the Act technology-neutral for signatures: s.3 kept the digital signature, s.3A opened the door to any electronic signature technique the Second Schedule names, and s.3B supplied the test that decides whether such a technique is reliable enough to count. Topic 37 introduced the signature sections together; this note, as asked, covers s.3B and the Second Schedule on their own.
1. The Three Sections in Line
Figure 1: How 3, 3A, 3B and the Schedule connect
- Section 3. Authentication of an electronic record by affixing a digital signature, created by an asymmetric crypto system and hash function that envelop and transform the record, the original 2000 scheme (Topic 37)
- Section 3A. Electronic signature: a subscriber may authenticate a record by an electronic signature or electronic authentication technique that is considered reliable and is specified in the Second Schedule, the technology-neutral widening of 2008; digital signature becomes one species of the wider electronic signature.
- Section 3B. The reliability test: it defines when an electronic signature or authentication technique is considered reliable, and empowers the Central Government to prescribe the procedure for ascertaining it, the gatekeeper between s.3A's openness and actual legal effect.
2. The Reliability Conditions
Figure 2: The five conditions of Section 3B
Section 3B, Information Technology Act, 2000 (substance) (1) For the purposes of this Act an electronic signature or electronic authentication technique shall be considered reliable if: (a) the signature creation data or the authentication data are, within the context in which they are used, linked to the signatory or, as the case may be, the authenticator and to no other person; (b) the signature creation data or the authentication data were, at the time of signing, under the control of the signatory or, as the case may be, the authenticator and of no other person; (c) any alteration to the electronic signature made after affixing such signature is detectable; (d) any alteration to the information made after its authentication by electronic signature is detectable; and (e) it fulfils such other conditions as may be prescribed. (2) The Central Government may prescribe the procedure for the purpose of ascertaining whether an electronic signature is that of the person by whom it is purported to have been affixed or authenticated. |
- Linkage and control. The first two conditions fix identity and exclusivity: the signature-creation or authentication data must be linked to the signatory and to no one else, and must have been under that person's sole control at the time of signing, the integrity of the binding between signature and person.
- Dual detectability. The next two fix tamper-evidence: any alteration to the signature after affixing, and any alteration to the information after authentication, must be detectable, so both the seal and the sealed content are protected.
- The residual power. The fifth condition and sub-section (2) leave room for prescribed conditions and an ascertaining procedure, the hook under which the Central Government notifies techniques and their safeguards.
3. The Second Schedule
- What it carries. The Second Schedule lists the electronic signature or electronic authentication techniques that qualify under s.3A, the live entry being e-authentication technique using Aadhaar or other e-KYC services, notified by G.S.R. 61(E) and 62(E) dated 27 January 2015 and widened in March 2019 from Aadhaar alone to Aadhaar or other e-KYC (Topics 37, 41)
- The amendment power. The Central Government may, by notification, add to or alter the Second Schedule, subject to the laying procedure, so new reliable techniques can enter without amending the Act, the mechanism of technology-neutrality in practice.
- The eSign link. The notified e-authentication technique is the legal basis of the eSign online service, where a licensed Certifying Authority issues a one-time key pair after Aadhaar or e-KYC authentication and signs the record (Topic 135)
⚠ Exam trap Keep the three sections distinct: s.3 is the digital signature, s.3A opens the field to any Second Schedule technique that is reliable, and s.3B is the reliability test, not a signature type. Quote the four core conditions as two pairs, linkage and control, then detectability of the signature and of the information, with the prescribed-condition residue fifth. And name the Second Schedule's actual content, e-authentication using Aadhaar or other e-KYC, rather than treating the Schedule as empty or abstract. |
4. Frequently Asked Questions
What does Section 3B of the IT Act provide?
It lays down when an electronic signature or electronic authentication technique is considered reliable: the signature-creation or authentication data must be linked to the signatory and to no other person and under his sole control at the time of signing, any alteration to the signature and to the information after authentication must be detectable, and it must fulfil any further prescribed conditions. Section 3B(2) empowers the Central Government to prescribe the procedure for ascertaining that a signature is genuinely that of the person who purportedly affixed it, making reliability the gateway between Section 3A's openness and legal effect.
5. Related Topics
- Topic 37: Sections 3 and 3A. Digital and electronic signatures together.
- Topic 135: CCA and eSign. The e-authentication technique in operation.