Digital Signatures are an important part of electronic transactions and electronic governance. They help establish the identity of the signer, ensure the integrity of electronic records, and provide greater confidence in online communication. In India, digital signatures are legally recognised under the Information Technology Act, 2000. The Act provides a legal framework for electronic records, digital signatures, electronic authentication, and Digital Signature Certificates. The concepts of Private Key, Public Key, Digital Signature, and Digital Signature Certificate are closely connected and together form the foundation of secure digital transactions.
1. Private Key
A Private Key is a confidential electronic key used by the owner to create a digital signature. It forms an essential part of the asymmetric cryptographic system, where two mathematically related keys are used: a private key and a public key. The private key must remain secret and under the control of its owner. When a person digitally signs an electronic document, the private key is used to generate the digital signature. Anyone possessing the corresponding public key can verify that signature. Under Section 2(1)(f) of the Information Technology Act, 2000, an asymmetric crypto system involves a secure key pair consisting of a private key and its mathematically related public key. Loss or unauthorised disclosure of a private key can compromise the security of digital transactions. Therefore, the signer must protect the private key carefully and prevent unauthorised access. The private key is generally stored securely through a cryptographic device or secure digital signing system. It is not normally shared with other persons. Its primary purpose is to provide authentication and security during electronic transactions. Thus, the private key establishes a secure connection between the signer and the digital signature created by that signer.
2. Public Key
A Public Key is an electronic key that is mathematically related to a private key and is used primarily for verification of digital signatures. Unlike the private key, the public key can be made available to other persons. When a document is digitally signed using the signer’s private key, the corresponding public key can be used to verify whether the signature is genuine and whether the document has been altered after signing. Section 2(1)(f) of the Information Technology Act, 2000 recognises the use of an asymmetric crypto system, consisting of a secure key pair of a private key and its mathematically related public key. The public key therefore plays an important role in establishing the authenticity of an electronic signature. It does not reveal the private key. In practical use, the public key is associated with the signer’s Digital Signature Certificate issued by a licensed Certifying Authority. When a recipient receives a digitally signed electronic document, the recipient can use the public key contained in or associated with the certificate to verify the signature. Therefore, the public key supports authentication, verification, integrity, and trust in electronic transactions.
3. Digital Signature
A Digital Signature is an electronic method used to authenticate an electronic record and identify the person who has signed it. Under Section 2(1)(p) of the Information Technology Act, 2000, a digital signature means authentication of an electronic record by a subscriber by means of an electronic method or procedure in accordance with Section 3 of the Act. A digital signature is created using the signer’s Private Key and can be verified using the corresponding Public Key. It helps determine whether the electronic document was signed by the claimed person and whether its contents have been changed after signing. Under Section 3 of the Information Technology Act, 2000, authentication of electronic records may be carried out through a Digital Signature using an asymmetric crypto system and hash function. Digital signatures are widely used for online filing, electronic contracts, government services, income tax filings, corporate filings, and other electronic transactions. They provide important security benefits by supporting authentication, integrity, and non repudiation. However, the security of a digital signature depends significantly on protecting the associated private key. A valid digital signature therefore provides greater confidence that an electronic record has been authenticated by the stated subscriber.
4. Digital Signature Certificate
A Digital Signature Certificate (DSC) is an electronic certificate used to establish the identity of a person or entity associated with a digital signature. Under Section 35 of the Information Technology Act, 2000, a person may apply to a Certifying Authority for a Digital Signature Certificate. The Certifying Authority may issue the certificate after following the prescribed requirements. A DSC generally contains information that identifies the subscriber, along with the subscriber’s public key, and other relevant certificate details. It helps users verify that a particular public key is associated with the identified subscriber. Under Section 30 of the Information Technology Act, 2000, a Certifying Authority is responsible for functions relating to issuing Digital Signature Certificates in accordance with the Act and applicable rules. A DSC is commonly used for income tax filing, MCA filings, GST related activities, e tenders, and other online services requiring digital authentication. The certificate helps establish trust and identity in electronic transactions. The subscriber must also exercise reasonable care to protect the corresponding private key and prevent its unauthorised use. Thus, a DSC act