munotes®

The Duties of a Subscriber

Chapter Thirty-Four

Syllabus topic 2.1, "Digital Signatures and Certificates"

Pages 190 to 195 of 948

In one line

Chapter VIII puts three duties on the person the certificate names: generate the key properly, accept the certificate knowing what acceptance means, and keep the private key to yourself.

In the wording a student can write in an exam: sections 40 to 42 of the Information Technology Act, 2000 require a subscriber who has accepted a Digital Signature Certificate to generate the key pair by applying the security procedure, provide that a subscriber is deemed to have accepted a certificate by publishing it or authorising its publication or otherwise demonstrating approval and that by accepting it he certifies three matters to all who reasonably rely on it, and require every subscriber to exercise reasonable care to retain control of the private key and to communicate any compromise to the Certifying Authority without delay, the Explanation declaring that the subscriber shall be liable until he has so informed the Certifying Authority.

Why the subscriber has duties at all

Because the whole system rests on one person keeping one number secret.

The mathematics is sound and the certificate is reliable, and neither helps if the private key has been copied. Chapter 260 explains why: anybody with the key can produce signatures that verify perfectly. The only defence is that the key never leaves the subscriber's control, and the only person who can secure that is the subscriber.

So Chapter VIII is where the Act allocates the risk, and it allocates almost all of it to the subscriber.

Section 40: generating the key pair

"Where any Digital Signature Certificate, the public key of which corresponds to the private key of that subscriber which is to be listed in the Digital Signature Certificate, has been accepted by a subscriber, the subscriber shall generate that key pair by applying the security procedure."

The section is awkwardly drafted and its point is simple. The subscriber, and not the Certifying Authority, generates the key pair, and he does so by applying the security procedure.

Why the subscriber and not the Authority? Because if the Authority generated the pair it would have held the private key, and the subscriber could then always say that somebody else could have signed. Sole control from the moment of creation is what makes non-repudiation possible, and it is the same idea as section 15(i), worked in chapter 220.

"Security procedure" is defined in section 2(1)(zf) as the procedure prescribed under section 16 by the Central Government. Chapter 220 works section 16.

And note the tension with the Second Schedule's technique. Under the e-authentication procedure the key pair is generated and held by a trusted third party offered by the Certifying Authority, which is the opposite of what section 40 requires. The reconciliation is that section 40 speaks of a Digital Signature Certificate and the Second Schedule operates under section 3A, but the tension is real and chapter 290 states it.

munotes.in190

The rest of this chapter

Module one is free. The rest of this chapter comes with the LL.M. Intellectual Property and Information Technology Semester 3 notes.

You are reading a chapter from a later module. Everything in module one of every subject stays free, and so does every question paper and the syllabus.

Notes + Solved papers: ₹798 Already bought it? Sign in

Or notes only: ₹499
Or solved papers only: ₹499

Free either way: question papers, the syllabus, and module one of every subject.

The rest of this subject

These notes are cut from the University's printed syllabus. Open the syllabus itself, or the past papers, for the same subject.

Report or request
Done!