(ze) “secure system” means computer hardware, software, and procedure that–
(a) are reasonably secure from unauthorised access and misuse;
(b) provide a reasonable level of reliability and correct operation;
(c) are reasonably suited to performing the intended functions; and
(d) adhere to generally accepted security procedures;
(zf) “security procedure” means the security procedure prescribed under section 16 by the Central
Government;
(zg) “subscriber” means a person in whose name the 1[electronic signature] Certificate is issued;
(zh) “verify”, in relation to a digital signature, electronic record or public key, with its
grammatical variations and cognate expressions, means to determine whether–
(a) the initial electronic record was affixed with the digital signature by the use of private key
corresponding to the public key of the subscriber;
(b) the initial electronic record is retained intact or has been altered since such electronic
record was so affixed with the digital signature.
(2) Any reference in this Act to any enactment or any provision thereof shall, in relation to an area in
which such enactment or such provision is not in force, be construed as a reference to the corresponding
law or the relevant provision of the corresponding law, if any, in force in that area.
CHAPTER II
2
[DIGITAL SIGNATURE AND ELECTRONIC SIGNATURE]
3. Authentication of electronic records.–(1) Subject to the provisions of this section any subscriber
may authenticate an electronic record by affixing his digital signature.
(2) The authentication of the electronic record shall be effected by the use of asymmetric crypto
system and hash function which envelop and transform the initial electronic record into another electronic
record.
Explanation.–For the purposes of this sub-section, “hash function” means an algorithm mapping or
translation of one sequence of bits into another, generally smaller, set known as “hash result” such that an
electronic record yields the same hash result every time the algorithm is executed with the same electronic
record as its input making it computationally infeasible–
(a) to derive or reconstruct the original electronic record from the hash result produced by the
algorithm;
(b) that two electronic records can produce the same hash result using the algorithm.
(3) Any person by the use of a public key of the subscriber can verify the electronic record.
(4) The private key and the public key are unique to the subscriber and constitute a functioning key
pair.
3
[3A. Electronic signature.–(1) Notwithstanding anything contained in section 3, but subject to the
provisions of sub-section (2), a subscriber may authenticate any electronic record by such electronic
signature or electronic authentication technique which–
(a) is considered reliable; and
(b) may be specified in the Second Schedule.
(2) For the purposes of this section any electronic signature or electronic authentication technique
shall be considered reliable if–
(a) the signature creation data or the authentication data are, within the context in which they are
used, linked to the signatory or, as the case may be, the authenticator and to no other person;
1. Subs. by Act 10 of 2009, s. 2, for “digital signature” (w.e.f. 27-10-2009).
2. Subs. by s. 5, ibid., for the heading “DIGITAL SIGNATURE” (w.e.f. 27-10-2009).
3. Ins. by s. 6, ibid. (w.e.f. 27-10-2009).
8