Authentication of Electronic Records: Section 3
Chapter Twenty-Eight
Syllabus topic 2.1, "Digital Signatures and Certificates"
Pages 155 to 159 of 948
In one line
Section 3 is four sub-sections that put the mathematics of the last two chapters into statutory form and make a digital signature an act with legal effect.
In the wording a student can write in an exam: section 3 of the Information Technology Act, 2000 provides that a subscriber may authenticate an electronic record by affixing his digital signature, that the authentication shall be effected by the use of an asymmetric crypto system and hash function which envelop and transform the initial electronic record into another electronic record, that any person may verify the electronic record by the use of the public key of the subscriber, and that the private key and the public key are unique to the subscriber and constitute a functioning key pair.
Why the section is drafted this way
Because the Act of 2000 recognised one technology and had to describe it. Section 5 accepts only a signature affixed in the prescribed manner, so the statute has to say what the manner is. Section 3 says it.
And because the section had to make an act of mathematics into an act in law. Computing a value is not, in itself, a legal act. Section 3(1) makes it one: a subscriber may authenticate an electronic record by affixing his digital signature. Authentication is the legal operation; the rest of the section is how it is done.
Section 3(1): who may do it and to what
"Subject to the provisions of this section any subscriber may authenticate an electronic record by affixing his digital signature."
Three limitations are in that sentence.
Only a subscriber. Section 2(1)(zg) defines a subscriber as a person in whose name the electronic signature Certificate is issued. So the person must hold a certificate, which means a Certifying Authority must have satisfied itself of the person's identity and issued one. Chapter 320 works the issue.
Only an electronic record, as section 2(1)(t) defines it.
Subject to the provisions of this section, which are the three that follow.
Section 3(2): how it is done
"The authentication of the electronic record shall be effected by the use of asymmetric crypto system and hash function which envelop and transform the initial electronic record into another electronic record."
Two techniques are named and both are mandatory. The asymmetric crypto system, defined in section 2(1)(f), and the hash function, defined in the Explanation to this sub-section. Chapters 260 and 270 work them.
The words "envelop and transform the initial electronic record into another electronic record" describe the result. The signature is itself an electronic record, produced from the first one. It is not a mark placed on the document; it is a second record derived from the first.
The rest of this chapter
Module one is free. The rest of this chapter comes with the LL.M. Intellectual Property and Information Technology Semester 3 notes.
You are reading a chapter from a later module. Everything in module one of every subject stays free, and so does every question paper and the syllabus.
Notes + Solved papers: ₹798 Already bought it? Sign in
Or notes only: ₹499
Or solved papers only: ₹499
Free either way: question papers, the syllabus, and module one of every subject.
The rest of this subject
These notes are cut from the University's printed syllabus. Open the syllabus itself, or the past papers, for the same subject.