Encryption and the Law
Chapter Eighty-Three
Syllabus topic 3.3, "Cyber Security"
Pages 521 to 526 of 948
In one line
India has a power to prescribe modes and methods of encryption which has never been exercised, a forty-bit licence condition that predates broadband, a draft policy withdrawn within days in 2015, and a traceability rule that puts the real pressure on encryption without ever using the word.
The section
Section 84A, inserted by the Amendment Act of 2008, in full:
The Central Government may, for secure use of the electronic medium and for promotion of e-governance and e-commerce, prescribe the modes or methods for encryption.
One sentence. Note four things.
"May." The power is discretionary and, seventeen years on, unexercised. No rules have been made under section 84A.
The purposes are enabling, not restrictive. Secure use of the electronic medium, promotion of e-governance and promotion of e-commerce. Nothing about law enforcement, national security or investigation. On its face section 84A is a power to make encryption work, not a power to weaken it.
"Modes or methods." Not standards, not key lengths, not escrow. What "modes or methods" covers is undefined.
And there is no offence. Nothing in the Act punishes using an encryption method other than a prescribed one, because nothing has been prescribed.
Where encryption law actually lives
Since the Act is silent, four other instruments do the work.
The Department of Telecommunications licence conditions. The Internet Service Provider licence has long limited individuals, groups and organisations to encryption of up to forty bits in symmetric key algorithms or their equivalent, with anything stronger requiring the permission of the licensor and the deposit of the decryption key. The licensee itself may not deploy bulk encryption on its network.
Why that number is absurd today. Forty-bit symmetric encryption was breakable by ordinary computers in the 1990s. Every banking session, every messaging application and every website served over the secure hypertext transfer protocol uses very much more. The condition is honoured by nobody and enforced against nobody, and it is the standing example of a rule that has been overtaken by the technology it regulates. It also sits inside a licence rather than in a statute, which is why it never had to survive a challenge.
Sectoral regulators requiring strong encryption. The Reserve Bank of India requires at least 128-bit encryption for internet banking, and the Securities and Exchange Board of India requires strong encryption for market systems. So one arm of the State caps encryption at forty bits by licence while another mandates 128 bits by direction, and both are binding on the same bank.
Rule 8 of the SPDI Rules 2011, which makes the ISO 27001 standard the benchmark for reasonable security practices, and that standard requires cryptographic controls. Chapter 230.
And rule 13(3) of the interception rules 2009, which is the only place in Indian law that squarely addresses what a service provider must do about a key it does not hold: a decryption direction to an intermediary is limited to the extent the information is encrypted by the intermediary or the intermediary has control over the decryption key. Chapter 800.
The rest of this chapter
Module one is free. The rest of this chapter comes with the LL.M. Intellectual Property and Information Technology Semester 3 notes.
You are reading a chapter from a later module. Everything in module one of every subject stays free, and so does every question paper and the syllabus.
Notes + Solved papers: ₹798 Already bought it? Sign in
Or notes only: ₹499
Or solved papers only: ₹499
Free either way: question papers, the syllabus, and module one of every subject.
The rest of this subject
These notes are cut from the University's printed syllabus. Open the syllabus itself, or the past papers, for the same subject.