munotes®

Secure Electronic Records, Secure Signatures and Security Procedures

Chapter Eighteen

Syllabus topic 1.3, closing MU's range at section 16

Pages 78 to 82 of 462

In one line

Three short sections that create a higher grade of electronic record and signature, and the reason they exist is what a court will presume about them.

In the words a student can write in an exam: section 14 provides that where a security procedure has been applied to an electronic record at a specific point of time, that record is deemed to be a secure electronic record from that point until the time of verification. Section 15, as substituted by the 2008 amendment, provides that an electronic signature is deemed a secure electronic signature if the signature creation data were, at the time of affixing, under the exclusive control of the signatory and no other person, and were stored and affixed in such exclusive manner as may be prescribed. Section 16 empowers the Central Government to prescribe the security procedures and practices for the purposes of sections 14 and 15, having regard to the commercial circumstances, the nature of the transactions and other relevant factors.

These three sections close MU's printed range at section 16.

Why a second grade of record and signature

Sections 4 and 5 recognised electronic records and electronic signatures generally. That solves the problem of admissibility and form. It does not solve the problem of proof.

A party who produces an email in court still has to persuade the court that it is genuine, that it has not been altered, and that the person it appears to come from actually sent it. In a paper world that work is done by handwriting, letterheads and witnesses. In an electronic world it has to be done by technology.

So the Act creates a higher category. A record or signature that meets the statutory security conditions is "secure", and being secure carries evidentiary consequences under the Indian Evidence Act, which was amended by this Act's own Schedule. In broad terms the law presumes, in respect of a secure electronic record, that it has not been altered since the point of time to which the secure status relates; and in respect of a secure electronic signature, that it was affixed by the subscriber with the intention of signing or approving the record.

That presumption is the whole point of sections 14 to 16. Everything else in them is machinery.

Section 14: secure electronic record

"Where any security procedure has been applied to an electronic record at a specific point of time, then such record shall be deemed to be a secure electronic record from such point of time to the time of verification."

Three features:

  1. It is time bounded at both ends. The record is secure from the point at which the procedure was applied, and only to the time of verification. It is not a permanent quality of the file. This is a sensible design: what the procedure demonstrates is that the record has not changed between those two moments.
  2. It depends entirely on the security procedure. The section supplies no test of its own; it points to section 16.
  3. It says nothing about who created the record. Authorship is section 11's job, and integrity is section 14's. The two must not be confused.
munotes.in78

Secure Electronic Records, Secure Signatures and Security Procedures

Section 15: secure electronic signature

The section as it now stands was substituted by the 2008 amendment, and reads:

"An electronic signature shall be deemed to be a secure electronic signature if:

(i) the signature creation data, at the time of affixing signature, was under the exclusive control of signatory and no other person; and

(ii) the signature creation data was stored and affixed in such exclusive manner as may be prescribed.

Explanation: In case of digital signature, the 'signature creation data' means the private key of the subscriber."

Two conditions, and both must be met.

(i) Exclusive control at the moment of signing. The test is control, and it is expressed twice over for emphasis: under the exclusive control of the signatory and no other person. A private key kept on a shared machine, or a one time password read out to a colleague, defeats it.

(ii) Stored and affixed in the prescribed exclusive manner. The manner is left to rules, which links to section 16.

The Explanation is worth memorising because it makes the abstraction concrete: for a digital signature, the signature creation data is the subscriber's private key. So condition (i) reduces to a familiar proposition: the private key must have been under the exclusive control of the signatory when the signature was affixed.

Note what changed in 2008. The original section 15 was written in terms of a secure digital signature and set out a list of conditions, including that the signature was unique to the subscriber, capable of identifying him, created in a manner under his exclusive control, and linked to the record so that any change would invalidate it. The substituted section is shorter, is written in terms of electronic signature, and pushes the detail into rules. The change is part of the same technology neutrality that produced section 3A.

Section 16: security procedures and practices

"The Central Government may, for the purposes of sections 14 and 15, prescribe the security procedures and practices:

Provided that in prescribing such security procedures and practices, the Central Government shall have regard to the commercial circumstances, nature of transactions and such other related factors as it may consider appropriate."

Two points.

The section is empowering, not defining. Neither section 14 nor section 15 can operate until something is prescribed under section 16, because both depend on a prescribed procedure or manner.

munotes.in79

Secure Electronic Records, Secure Signatures and Security Procedures

The proviso is a direction on how the power is to be exercised. The Government must have regard to commercial circumstances and the nature of transactions. That is a proportionality instruction: the security demanded of a high value transfer between banks need not be demanded of a low value retail purchase. It also means the standard is capable of moving as technology and commercial practice move, without amending the Act.

Section 16 was also substituted in 2008, and its marginal note in the arrangement of sections reads "Security procedure and practices" while the body reads "Security procedures and practices". The difference is immaterial and is noted only so a reader comparing the two is not puzzled.

How the three sections relate to the rest of the topic

QuestionSection
Is an electronic record recognised where writing is required?4
Is an electronic signature recognised where signature is required?5, with 3 and 3A
Whose record is it?11
When and where was it sent and received?13
Has it been altered since it was secured?14
Was the signature affixed under the signatory's exclusive control?15
What counts as adequate security?16

The pattern is worth stating in an answer: sections 4 and 5 are about admissibility of form; sections 14 to 16 are about the weight the record will carry.

A worked example

Two companies conclude a supply agreement, each affixing a digital signature issued by a licensed certifying authority, using private keys held on individual cryptographic tokens. A dispute arises and the buyer says the quantity term was altered after signature.

  • Is the record a secure electronic record? If a prescribed security procedure was applied at a specific point of time, section 14 deems it secure from that point to the time of verification. The consequence is the presumption that it has not been altered in that interval, and the burden of showing otherwise moves to the party alleging alteration.
  • Is the signature a secure electronic signature? Section 15 asks whether the signature creation data, which the Explanation tells us is the private key, was under the exclusive control of the signatory at the time of affixing, and was stored and affixed in the prescribed manner. A key on a personal token in the signatory's possession satisfies the first condition.
  • What follows? The buyer is not merely disputing a document; he is arguing against a statutory presumption, which is a much harder position.

Change one fact: the private key was kept on a shared office computer to which four employees had access. Condition (i) of section 15 fails, because the data was not under the exclusive control of the signatory and no other person. The signature may still be an electronic signature under sections 3A and 5, and the contract may still be perfectly good, but it is not secure, and the presumption is not available.

munotes.in80

Secure Electronic Records, Secure Signatures and Security Procedures

That is the practical lesson of these three sections: security is about who could have used the key, not about how sophisticated the technology is.

What it does NOT mean

"An electronic record that is not secure is inadmissible." It is not. Sections 4 and 5 recognise records and signatures generally. Security affects the presumptions, not the recognition.

"A secure electronic record can never be challenged." The presumption is rebuttable, and the secure status runs only from the application of the procedure to the time of verification.

"Section 14 tells you who made the record." It does not. Integrity is section 14; attribution is section 11.

"Section 15 still speaks of digital signatures." It was substituted in 2008 and now speaks of electronic signatures, with digital signatures dealt with in the Explanation.

Quick revision

  • Section 14: a security procedure applied at a specific point of time makes the record a secure electronic record from that point to the time of verification.
  • Section 15: an electronic signature is secure if the signature creation data was (i) under the exclusive control of the signatory and no other person at the time of affixing, and (ii) stored and affixed in the prescribed exclusive manner. Explanation: for a digital signature, the signature creation data is the private key.
  • Section 16: the Central Government prescribes the procedures and practices, having regard to commercial circumstances and the nature of transactions.
  • The purpose of all three is evidentiary: secure status attracts presumptions of integrity and of signing.
  • Sections 15 and 16 were substituted by the 2008 amendment, in force 27 October 2009.
  • Sections 14 to 16 close MU's printed range for this Act.

Test yourself

1. From when until when is a record a secure electronic record? From the point of time at which the security procedure was applied until the time of verification, section 14.

2. State the two conditions in section 15. The signature creation data must have been under the exclusive control of the signatory and no other person at the time of affixing, and must have been stored and affixed in such exclusive manner as may be prescribed.

3. What is the signature creation data in the case of a digital signature? The private key of the subscriber, by the Explanation to section 15.

4. Why does the Act create a category of secure records at all? Because recognition under sections 4 and 5 answers the question of form, not of proof. Secure status attracts statutory presumptions about integrity and about the affixing of the signature, which is what gives the record weight in evidence.

munotes.in81

Secure Electronic Records, Secure Signatures and Security Procedures

5. What must the Central Government consider when prescribing security procedures? The commercial circumstances, the nature of the transactions and such other related factors as it considers appropriate, under the proviso to section 16.

munotes.in82

The rest of this subject

These notes are cut from the University's printed syllabus. Open the syllabus itself, or the past papers, for the same subject.

Report or request
Done!