Skip to content

Jurisprudence, Interpretation and General Laws · Law relating to Information Technology

Digital Signature and Electronic Signature under the IT Act, 2000

Updated 11 October 2026 · Fact-checked

A digital signature authenticates an electronic record. The subscriber affixes it using an asymmetric crypto system and a hash function (Section 3). A Certifying Authority issues a certificate that links the public key to the subscriber. Anyone can verify the record using the subscriber's public key. Exam answers need the provision, the facts and a conclusion.

Understand Digital Signature and Electronic Signature

Paper records are signed by hand. Electronic records cannot be signed that way. The IT Act, 2000 therefore lets a subscriber authenticate an electronic record by affixing a digital signature (Section 3(1)).

The method is technical but easy to remember. The record is passed through a hash function, which is an algorithm that turns the record into a smaller hash result. The same record always gives the same hash result. It is computationally infeasible to rebuild the record from the hash result, and infeasible for two different records to give the same hash result. The hash result is then locked using the subscriber's private key. This is the asymmetric crypto system: one key pair, a private key and a public key.

Any person can use the subscriber's public key to verify the record (Section 3(3)). The private key and public key are unique to the subscriber and form a functioning key pair (Section 3(4)). If even one bit of the record changes, verification fails. This is why a digital signature protects the origin and the integrity of a record.

A public key alone does not tell you who owns it. That is the job of the Certifying Authority (CA). It issues a Digital Signature Certificate (DSC) that links the key pair to a named subscriber. The Controller supervises the CAs (Section 18).

On terminology: the Act's original term was "digital signature". Since 27 October 2009 the Act also uses the wider term "electronic signature" in many places, such as Sections 30, 35 and 73, in place of "digital signature". Sections 3 and 36 to 41, as supplied, still use "Digital Signature Certificate". Use the exact term the section uses. A digital signature, based on an asymmetric crypto system and hash function, is one technique of electronic signature. Do not claim more than this about the difference unless the question gives a definition.

Key rules to remember

Authentication of electronic records (Section 3)
Subscriber + digital signature → authenticated electronic record
Done through an asymmetric crypto system and a hash function. Anyone can verify it with the subscriber's public key.
Hash function (Section 3(2) Explanation)
Same record → same hash result, every time
It must be infeasible to derive the record from the hash result, and infeasible for two records to give the same hash result.
Key pair (Section 3(4))
Private key + public key = functioning key pair, unique to the subscriber
The private key signs. The public key verifies.
Application for certificate (Section 35)
Application in prescribed form + fee not exceeding ₹25,000 + certification practice statement
Different fees may be prescribed for different classes of applicants. Rejection needs written reasons and a reasonable opportunity to show cause.
Duties of a CA (Section 30)
Secure systems; reliable services; secrecy and privacy of signatures; repository of certificates; publish practices and certificate status; other standards by regulations
Clauses (a) to (c), (ca), (cb) and (d).
Representations by CA (Section 36)
CA certifies clauses (a) to (f)
Includes compliance with the Act, publication, subscriber holds the private key, a functioning key pair, accurate information, and no knowledge of a material adverse fact.
Suspension (Section 37)
Suspension on request or in public interest; not beyond 15 days without a hearing
The CA must communicate the suspension to the subscriber.
Revocation (Section 38)
Revoke on request, death, dissolution or winding up; or on grounds in 38(2); only after hearing
The CA must communicate the revocation to the subscriber.
Penalty (Section 73)
Imprisonment up to 2 years, or fine up to ₹1 lakh, or both
For publishing a certificate knowing it was not issued by the CA, not accepted by the subscriber, or is revoked or suspended.

How to solve Digital Signature and Electronic Signature questions

Use this order for any theory or problem question on digital and electronic signatures. It matches the ICSI answer style: provision, analysis, conclusion.

  1. 1Identify what is asked: authentication method, role of the CA or Controller, issue, suspension, revocation, acceptance, or penalty.
  2. 2Name the provision. Use Section 3 for authentication, 30 and 36 for CA duties, 35 for issue, 37 for suspension, 38 for revocation, 41 for acceptance, 18 and 19 for the Controller, 73 for penalty.
  3. 3State the rule in plain words with its conditions, such as the 15-day limit or the right to be heard.
  4. 4Apply the rule to the facts. Pick out who the subscriber is, who the CA is, and what has happened to the certificate.
  5. 5Check for exceptions, for example the Section 73 exception for verifying a signature created before suspension or revocation.
  6. 6Write a clear conclusion that answers the question asked, and cite the section again.
  7. 7For definition questions, use the Act's own terms: subscriber, hash function, key pair, Digital Signature Certificate.

Quickest way: Lifecycle method: issue, use, suspend, revoke, misuse

When to use it: Use it when the question is a short fact-based problem and you have little time.

  1. Place the facts on the lifecycle: apply (35), issue and CA representations (36), accept (41), use (3), suspend (37), revoke (38), misuse (73).
  2. Write the section for that stage and its key condition in one or two lines.
  3. Check the hearing rule. Suspension beyond 15 days and any revocation need a hearing. Rejection of an application needs a chance to show cause.
  4. Close with a one-line conclusion naming the section.

Common mistakes in Digital Signature and Electronic Signature

  • Saying the Controller issues Digital Signature Certificates.

    Students mix up the Controller and the Certifying Authority.

    Fix: The CA issues certificates (Section 35). The Controller supervises CAs, certifies their public keys and lays down standards (Section 18).

  • Saying the private key is used to verify a signature.

    The two keys sound alike and are easy to swap.

    Fix: The private key creates the signature. Any person verifies with the subscriber's public key (Section 3(3)).

  • Allowing suspension for any length of time without a hearing.

    Students remember the hearing rule only for revocation.

    Fix: Suspension cannot exceed 15 days unless the subscriber has been given an opportunity of being heard (Section 37(2)).

  • Revoking a certificate without a hearing because the subscriber has died or has asked for it.

    Section 38(3) is read as applying to all grounds, then ignored for the easy ones.

    Fix: Section 38(3) says a certificate shall not be revoked unless the subscriber has been heard. Quote it, and note that revocation on request, death or winding up is listed in 38(1).

  • Treating digital signature and electronic signature as unrelated or identical without explanation.

    The Act changed its wording in 2009 and notes do not explain it.

    Fix: Say the Act uses 'electronic signature' in several sections since 27 October 2009, while Section 3 describes authentication by digital signature using asymmetric crypto and hash function. Use the section's own term.

  • Missing the Section 73 exception.

    Students recall only the penalty and not the carve-out.

    Fix: Publishing a suspended or revoked certificate is not an offence if it is only to verify a signature created before the suspension or revocation.

Worked examples

Example 1

Explain how a digital signature authenticates an electronic record under the IT Act, 2000. Who can verify it?

Show the solution
  1. Provision: Section 3(1) allows a subscriber to authenticate an electronic record by affixing his digital signature.
  2. Method: under Section 3(2), authentication uses an asymmetric crypto system and a hash function. The hash function turns the record into a smaller hash result. The same record always yields the same result. It is computationally infeasible to rebuild the record from the result, or to find two records with the same result.
  3. Keys: the private key and public key are unique to the subscriber and form a functioning key pair (Section 3(4)).
  4. Verification: under Section 3(3), any person can verify the electronic record using the subscriber's public key.

Answer: A subscriber authenticates an electronic record by affixing a digital signature using an asymmetric crypto system and a hash function (Section 3). Any person can verify it with the subscriber's public key.

Example 2

Ravi Sharma holds a Digital Signature Certificate issued by a Certifying Authority. On 1 March the CA suspends it in public interest and does not inform him. On 20 March the CA still has not given him a hearing. Advise on the position.

Show the solution
  1. Provision: Section 37 allows a CA to suspend a certificate on the subscriber's request, or if it thinks suspension is in public interest.
  2. Public interest suspension is a valid ground under Section 37(1)(b).
  3. Time limit: under Section 37(2), a certificate cannot be suspended for more than fifteen days unless the subscriber has been given an opportunity of being heard. From 1 March to 20 March is 19 days, which exceeds 15.
  4. Communication: Section 37(3) requires the CA to communicate the suspension to the subscriber. The CA has not done so.
  5. Conclusion: the initial suspension was within the CA's power. The suspension after 15 days without a hearing, and the failure to communicate it, breach Section 37.

Answer: The suspension in public interest was permissible. But continuing it beyond fifteen days without hearing Ravi, and not communicating it to him, contravenes Section 37(2) and (3).

Exam tips

  • Learn the verbs in each section. Issue (35), suspend (37) and revoke (38) have different conditions, and examiners test the differences.
  • Write the numbers exactly: fee up to ₹25,000, 15 days, imprisonment up to 2 years, fine up to ₹1 lakh.
  • For a 'role of Certifying Authority' question, group the duties: Section 30 duties, Section 36 representations, and Sections 35, 37 and 38 powers.
  • Use a short list of headings in the answer: provision, analysis, conclusion. Always cite the section.
  • Link this topic with the Controller's functions and with electronic records as evidence for fuller marks.

Practice questions from Law relating to Information Technology

Digital Signature and Electronic Signature in other exams

The same ground in other exams, if you are preparing for more than one or want another angle on it.

Digital Signature and Electronic Signature: frequently asked questions

What is the difference between digital signature and electronic signature?

A digital signature is the technique in Section 3: an asymmetric crypto system and a hash function, verified with the public key. Since 27 October 2009 the Act also uses the term electronic signature in sections such as 30, 35 and 73. In your answer, use the term the section uses and explain Section 3 for the method.

What does a Certifying Authority do under the IT Act, 2000?

It issues certificates after considering the application and the certification practice statement (Section 35). It must use secure systems and be a repository of certificates (Section 30). It can suspend and revoke certificates under Sections 37 and 38.

When can a Digital Signature Certificate be revoked?

Under Section 38(1), on request of the subscriber or an authorised person, on the subscriber's death, or on dissolution of the firm or winding up of the company. Section 38(2) adds grounds such as a false or concealed material fact and compromise of the CA's private key. A hearing is required before revocation.

Is it an offence to publish a revoked certificate?

Yes, if you know it is revoked or suspended, or know the CA did not issue it or the subscriber did not accept it (Section 73). The punishment is imprisonment up to two years, or fine up to ₹1 lakh, or both. Publishing it only to verify a signature made before suspension or revocation is not an offence.