Digital Signatures and PKI Under the IT Act
Sign with the private key, verify with the public key. Here is the chain of trust that makes it legally valid in India.
A digital signature proves two things about an electronic document: who signed it, and that it hasn't changed since. A bank uses one on an e-tender bid, a regulatory filing, or a sanction letter sent by email. Under the IT Act, 2000 a properly signed electronic record has the same legal standing as a signed paper one.
PKI (public key infrastructure) is the system of licensed authorities and certificates that makes a public key trustworthy. Without it, anyone could publish a key and claim it belongs to your bank's general manager.
You save ₹300
- Full 120-question mocks
- Cyber law coverage
- Module-wise practice
One payment, no subscription · Valid for 2 months
How a Digital Signature Works
Section 3 of the IT Act says authentication is done by an asymmetric crypto system and a hash function. In practice:
- 1
Hash the document
The signer's software computes a hash, a short fingerprint of the document.
- 2
Sign with the private key
The hash is transformed using the signer's private key, which only the signer holds. The result is the digital signature.
- 3
Send document, signature and certificate
The certificate carries the signer's public key, vouched for by a Certifying Authority.
- 4
Verify with the public key
The recipient uses the public key to check the signature and recomputes the hash. If they match, the document is from that signer and unchanged. Section 3(3): any person can verify using the subscriber's public key.
The PKI Chain in India
- Controller of Certifying Authorities (CCA)
- Appointed by the Central Government under section 17. Licenses and regulates Certifying Authorities.
- Root Certifying Authority of India (RCAI)
- Operated by the CCA. Section 18(b) gives the Controller the function of certifying the public keys of the Certifying Authorities, so every Indian certificate traces back to this root.
- Certifying Authority (CA)
- A licensed body that verifies a person's identity and issues the electronic signature certificate (section 35).
- Digital Signature Certificate (DSC)
- Binds a public key to a verified person. For a token-based DSC, the private key sits in a hardware cryptographic token. CCA's certificate policy defines assurance classes, with Class 3 the highest.
- eSign
- An online electronic signature service run through licensed CAs. The signer is authenticated by e-KYC with an OTP or biometric, a short-validity certificate is issued, and the key is destroyed immediately after use. No physical token is needed.
What a Digital Signature Gives and Doesn't
Authentication
Provided?
Yes
Why
Only the holder of the private key could have produced it
Integrity
Provided?
Yes
Why
Any change to the document changes the hash and the check fails
Non-repudiation
Provided?
Yes
Why
The signer cannot credibly deny signing, provided the private key was in their control
Confidentiality
Provided?
No
Why
The document itself is not hidden. That needs encryption
| Property | Provided? | Why |
|---|---|---|
| Authentication | Yes | Only the holder of the private key could have produced it |
| Integrity | Yes | Any change to the document changes the hash and the check fails |
| Non-repudiation | Yes | The signer cannot credibly deny signing, provided the private key was in their control |
| Confidentiality | No | The document itself is not hidden. That needs encryption |
Quick practice on banking operations. No signup.
Digital Signature vs Electronic Signature
The original Act of 2000 recognised only digital signatures (asymmetric cryptography). The IT (Amendment) Act, 2008, in force from 27 October 2009, added section 3A on electronic signatures: any reliable technique specified in the Second Schedule. A digital signature is therefore one kind of electronic signature. Note what the Act still does not cover (First Schedule): negotiable instruments other than cheques, powers of attorney, trusts and wills. A September 2022 notification carved out demand promissory notes, bills of exchange and powers of attorney in favour of entities regulated by RBI, NHB, SEBI, IRDAI or PFRDA, and took contracts for the sale or conveyance of immovable property off the list. Older material still shows the pre-2022 list.
How the IIBF Exam Tests This
- check_circleWhich key signs: the sender's private key. Which key verifies: the sender's public key. Options that say 'the recipient's private key' are wrong.
- check_circleWhat a signature does not provide: confidentiality. This is the favourite 'which is NOT' question.
- check_circleWho licenses CAs: the Controller of Certifying Authorities, not RBI, CERT-In or MeitY directly.
- check_circleExcluded documents: a will or a trust cannot be executed by electronic signature under the IT Act. Most powers of attorney are also excluded, but not one in favour of an entity regulated by RBI, NHB, SEBI, IRDAI or PFRDA.
FAQs
Which section of the IT Act deals with digital signatures?expand_more
Section 3 covers authentication of electronic records by digital signature using an asymmetric crypto system and hash function. Section 3A, added in 2008, covers electronic signatures more broadly, and section 5 gives them legal recognition.
Who issues digital signature certificates in India?expand_more
Certifying Authorities licensed by the Controller of Certifying Authorities. The CCA's Root Certifying Authority of India certifies the CAs' own public keys.
Does a digital signature encrypt the document?expand_more
No. It proves who signed and that the document is unchanged. Keeping the content secret needs separate encryption.
Is Aadhaar eSign legally valid?expand_more
eSign is offered through CAs licensed by the CCA under the IT Act, using e-KYC authentication by OTP or biometric. CCA describes it as legally recognised, subject to the documents the Act excludes in its First Schedule.
Next steps
- Encryptionarrow_forward
- IT Act 2000arrow_forward
- IT Amendment 2008arrow_forward
- CERT-In & NCIIPCarrow_forward
120 questions, 2 hours, scored instantly.
