Tuesday, December 22, 2020

Demystifying Digital signatures and electronic signatures

With the advancement in technology, the usage of the digital signature in place of the conventional signature has widely increased. The Information Technology Act, 2000 talks widely about the concept of Digital Signature, the authorities who have been given the power of issuing the digital signature certificate and the circumstances which require affixation of the digital signature. Digital signatures are recognized by IT Act 2000, as a valid means of authentication of any electronic record by a subscriber by means of an electronic method or procedure. The digital signatures cryptographically bind the electronic identity to the electronic document and provide it with authentication, integrity and non-repudiation.


In ITAA -2008, section 3 which was originally “Digital Signature” was renamed as “Digital Signature and Electronic Signatures” The Act now includes digital signature as one of the modes of signatures and is far broader in ambit covering biometrics and other forms of creating electronic signatures. Electronic signatures hence allow a subscriber to authenticate any electronic record by such electronic signatures or electronic authentication techniques. The key differences between Electronic and Digital signatures are enumerated below

Electronic Signature

·         Defined under Section 2(1) (ta) of the Information Technology Act, 2000.

·         It is technologically neutral

·         It can be created by using various available technologies - signature picture, It can be in the form of a name typed at the end of an email, a digital version of a handwritten signature in the form of an attachment, a code or even a fingerprint

·         It is less authentic and is easily vulnerable to tampering.

·         It is verified through the signer’s identity.

Digital Signature

·         Defined under Section 2(1)(p) of the Information Technology Act, 2000.

·         Follows a technology-specific approach such as usage of hash functions

·         It involves the usage of Cryptographic system of constructing the signature with a two-way protection system. It uses public key cryptography system to sign up for a message which requires a pair of keys -public and private

·         It has more authenticity and is more secure and highly reliable.

·         It has a certificate-based digital verification.

No comments:

Post a Comment

The Priority Gap: When Patchability Does Not Equal Protection

Vulnerability management often fails at the point where security mandates collide with IT operations, creating a Priority Gap between vulne...