Information Technology Act Section 3 — Authentication of electronic records

CHAPTER II 2[DIGITAL SIGNATURE AND ELECTRONIC SIGNATURE]

Cyber Law

Summary

Sub-section (1) allows any subscriber to authenticate an electronic record by attaching their digital signature to it, as long as the conditions in this section are met.

Sub-section (2) explains how authentication works: it is done using an asymmetric crypto system and a hash function, which together transform the original electronic record into a different electronic record. The explanation clarifies that a hash function is an algorithm that maps or converts one sequence of bits into another, usually smaller, set of bits called a hash result. The same electronic record always produces the same hash result every time the algorithm runs with that record as input. It is practically impossible, using this algorithm, to derive or recreate the original electronic record from the hash result, and it is also practically impossible for two different electronic records to produce the same hash result.

Sub-section (3) states that any person can verify the electronic record by using the subscriber's public key.

Sub-section (4) says that the private key and the public key are unique to the subscriber and together form a working key pair.

Official Text

(1) Subject to the provisions of this section any subscriber may authenticate an electronic record by affixing his digital signature.

(2) The authentication of the electronic record shall be effected by the use of asymmetric crypto system and hash function which envelop and transform the initial electronic record into another electronic record.

Explanation.–For the purposes of this sub-section, ―hash function‖ means an algorithm mapping or translation of one sequence of bits into another, generally smaller, set known as ―hash result‖ such that an electronic record yields the same hash result every time the algorithm is executed with the same electronic record as its input making it computationally infeasible–

(a) to derive or reconstruct the original electronic record from the hash result produced by the algorithm;

(b) that two electronic records can produce the same hash result using the algorithm.

(3) Any person by the use of a public key of the subscriber can verify the electronic record.

(4) The private key and the public key are unique to the subscriber and constitute a functioning key pair.