munotes®

What a Digital Signature Is

Get access to whole semester resourcesSemester Pass

Chapter Five

Syllabus topic 2, "Application and Registration procedure of Digital Signature."

Pages 9 to 10 of 80

In one line

A digital signature is the authentication of an electronic record by the person who owns a private key, in a way that anybody holding the matching public key can verify and nobody without the private key can forge.

What the Act says

Section 3 of the Information Technology Act, 2000:

(1) Subject to the provisions of this section any subscriber may authenticate an electronic record by affixing his digital signature.

(2) The authentication of the electronic record shall be effected by the use of asymmetric crypto system and hash function which envelop and transform the initial electronic record into another electronic record.

(3) Any person by the use of a public key of the subscriber can verify the electronic record.

(4) The private key and the public key are unique to the subscriber and constitute a functioning key pair.

Four sub-sections, and each one is a fact worth stating.

Sub-section (2) names the two techniques: an asymmetric crypto system and a hash function. Section 3's own Explanation defines the hash function as an algorithm producing a smaller "hash result" that is the same every time for the same record, and from which it is computationally infeasible to reconstruct the record or to find two records with the same result.

Sub-section (3) is what makes the signature useful to anybody else: the public key verifies, and anybody may hold it.

Sub-section (4) is the whole security of the thing: the key pair is unique to the subscriber.

The three things it gives, and they are separate

Authentication. The record came from the holder of that private key.

Integrity. The record has not been altered since it was signed. Change one character and the hash result changes, and verification fails.

Non-repudiation. The signer cannot later deny signing, because nobody else has the private key.

A scanned image of a handwritten signature gives none of the three. It can be copied off one document and pasted onto another, it says nothing about whether the document changed, and it can be denied. That is the single most useful contrast in an answer.

Digital signature and electronic signature

The Act uses both, and the difference is examinable.

Section 2(1)(p) defines a digital signature as authentication of an electronic record by a subscriber by means of an electronic method or procedure in accordance with section 3.

Section 3A, inserted in 2009, added the electronic signature: a subscriber may authenticate an electronic record by any electronic signature or authentication technique that is considered reliable and is specified in the Second Schedule. Section 3A(2) sets out when a technique is reliable.

Section 2(1)(ta) then defines "electronic signature" to include the digital signature.

munotes.in9

What a Digital Signature Is

So the relationship is one of genus and species. Every digital signature is an electronic signature; not every electronic signature is a digital signature. Aadhaar e-KYC signing, listed in the Second Schedule, is an electronic signature and is not a digital signature under section 3.

Legal recognition

Section 5, legal recognition of electronic signatures, is the provision that makes any of this worth doing: where a law requires information to be authenticated by the signature of a person, that requirement is satisfied if the information is authenticated by an electronic signature affixed in the prescribed manner.

Section 15 adds the idea of a secure electronic signature, which carries a stronger presumption.

Together they are the reason a company can file its return without a piece of paper.

Where an accountant meets it

Every one of these needs a digital signature or an equivalent:

  • Income-tax return of a firm or a company that is required to be audited.
  • Tax audit report, filed by the chartered accountant with the accountant's own certificate.
  • GST registration and returns, where the applicant is a company or a limited liability partnership.
  • Company filings with the Registrar of Companies, all of them.
  • e-Tendering with any government department.
  • Import and export documentation, and the Directorate General of Foreign Trade's own portal.
  • Trademark and patent filings.

The three classes, and why only one of them matters now

Certificates were issued in three classes. Class 1 and Class 2 were discontinued from 1 January 2021 by the Controller of Certifying Authorities, and Class 3 is the only class now issued.

ClassAssuranceStatus
Class 1Name and email verified against a databaseDiscontinued
Class 2Identity verified against a trusted databaseDiscontinued
Class 3Identity verified by physical or video presence before the Registration AuthorityThe only class issued now

A Class 3 certificate comes in two kinds: signature only, and signature and encryption combined. A firm filing returns needs the first; a firm bidding in e-tenders usually needs both.

The two things inside the certificate

A Digital Signature Certificate is a file, and it holds:

  • the subscriber's name and details, verified by the Certifying Authority;
  • the public key of the subscriber;
  • the Certifying Authority's own signature over both;
  • the validity period, one, two or three years.

The private key is not in the certificate. It sits in a USB cryptographic token, and it never leaves it. That is the point of the token, and the next chapter takes up how one is obtained.

munotes.in10

The rest of this subject

These notes are cut from the University's printed syllabus. Open the syllabus itself, or the past papers, for the same subject.

Report or request
Done!