Digital Signatures and Public Key Infrastructure
By anurag Agnihotri
Introduction: The "paperless office" concept has been around for well over a decade. It has failed to move from theory to reality, however, because of cultural reticence, unequal access to technology, and the lack of an adequate legal and service infrastructure to support such a paradigm shift. Ours is a paper-based society. We are comfortable with paper, it is tangible, and we feel secure about the integrity and source of the information it conveys. In short, we trust it.
The Internet and Electronic Commerce: The explosion of Internet use has been tempered only by the lack of sufficient information security and a legal framework to enable electronic commerce via the Internet to flourish. Despite these shortcomings, governments, businesses and individuals are using the Internet more and more as an inexpensive and convenient tool to disseminate and obtain information, goods and services. With the advent of public key cryptography technology and the legal recognition of digital signatures at the national level, the full potential of the Internet is just beginning to be discovered. For the Internet to offer an inexpensive and ubiquitous solution to eCommerce, the focus must be on information security. The Internet is insecure - millions of people have access and "hackers" can intercept anything traveling over the wire. The goal should be to protect the message, not the medium. Public key cryptography, a data encryption technique, provides just that kind of message protection.
Overview: All legally binding communications or transactions, whether electronic or paper-based, must meet some fundamental requirements: the message should provide for sender authenticity to enable the recipient (or relying party) to determine who really sent the message and if that individual is, in fact, authorized to commit his organization to the transaction. The second major requirement is that there be some means to ascertain that the message has integrity. The recipient must be able to determine whether or not the message received has been altered en route. The third, and most critical, requirement addresses the ability to "prove up" the message in court. Referred to as non-repudiation, this requires some way to ensure that the sender cannot falsely deny sending the message.
Digital Signatures and Information Security: In defining digital signatures and how they work, it is helpful to begin by clarifying what they are not. A digital signature is not a digitized image of a handwritten signature. Digital signatures on the other hand are an actual transformation of an electronic message using public key cryptography. Through this process, the digital signature is tied to the document being signed, as well as to the signer, and therefore cannot be reproduced. Furthermore, with the passage of the lndian IT Act 2000, digitally signed electronic transactions have the same legal weight as transactions signed in ink.
The Basic Principles: The principles underlying the use of cryptography in electronic communications are as follows:
1. All data entered into a computer is read as a binary number. For example, when "Jack and Jill went up the hill" is typed in, the computer reads it as "1000111010100111000101," etc.
2. Because electronic messages are represented numerically in the computer, it is possible to perform mathematical functions on them.
3. Electronic messages can thus be transformed into alternate representations that are unique to the original
Public Key Cryptography: Encryption technique known as asymmetric cryptography - also known as public key cryptography - involves using a asymmetric key pair. This key pair is comprised of what is referred to as a public key and a private key. The public key, as its name suggests, may be freely disseminated. This key does not need to be kept confidential. The private key, on the other hand, must be kept secret. The sender authenticity and non-repudiation are based on the signer having sole access to his private key. There are several important characteristics of these key pairs. First, while they are mathematically related to each other, it is impossible to calculate one key from the other. Therefore, the private key cannot be compromised through knowledge of the associated public key. Second, each key in the key pair performs the inverse function of the other. What one key does, only the other can undo.
Digital Signature Components: Digital signatures are based on asymmetric, or public key, cryptography. The digital signing and verification processes involve something known as a hash algorithm and a signature algorithm. The hash and signature algorithms are extremely complex mathematical equations. The hash algorithm is performed on the original electronic message's binary code, resulting in what is referred to as a message digest, which is a 160-bit string of digits that is unique to the original message. The signature algorithm is then performed on this message digest. The resultant string of digits is the digital signature. The signer's private key is used during the signing process, and the public key is used during the verification process for verifying digital signature.
It is an actual transformation of the message itself that incorporates a "secret" known only to the signer, and is therefore tied to both the signer and the message being signed. A signer's digital signature will be different for each different document he signs.
Digital Signature Processes: The following are graphical representations of the digital signing and verification processes, respectively:
Public Key Infrastructure:The widespread use of digital signatures underscores the need for some type of entity to serve as a trusted third party (TTP) to vouch for individuals' identities, and their relationship to their public keys. This entity, in public key infrastructure (PKI) terminology, is referred to as a certification authority (CA). The CA is a trusted third party that issues digital certificates to its subscribers, binding their identities to the key pairs they use to digitally sign electronic communications. Digital certificates contain the name of the subscriber, the subscriber's public key, the digital signature of the issuing CA, the issuing CA's public key, and other pertinent information about the subscriber and his organization, such as his authority to conduct certain transactions, etc. These certificates have a life cycle of 1 or 2 years, and can be revoked upon private key compromise, separation from an organization, etc. These certificates are stored in an on-line, publicly accessible repository. The repository also maintains an up-to-date listing of all the certificates, that have not yet expired, which have been revoked, referred to as a certificate revocation list (CRL).
PKI Process Flow: Step 1. Subscriber applies to Certification Authority for Digital Certificate.
Step 2. CA verifies identity of Subscriber and issues Digital Certificate.
Step 3. CA publishes Certificate to Repository.
Step4 Subscriber digitally signs electronic message with Private Key to ensure Sender Authenticity, Message Integrity and Non-Repudiation and sends to Relying Party.
Step 5 Relying Party receives message, verifies Digital Signature with Subscriber's Public Key and checks Repository for status and validity of Subscriber's Certificate.
Step 6.Repository returns results of status on Subscriber's Certificate to Relying Party.
Digital Signature Applications: Digital signatures are critical to the electronic conversion of any presently paper-based process that requires strong authentication of both the sender and the contents of the message, and/or non-repudiation. The number of such applications is virtually endless, ranging from purchase order systems, form filing with any government, form processing to contracts and remote financial transactions or inquiries. Some of the applications more commonly used in India are:
a. Online form filing with DGFT: online forms, digitally signed, can be filed with DGFT for the purposes of EPCG, DEPB and advance licences. DGFT offers 50% discount on filing fee for the applications received online.
b. E-Procurement: Several state governments, public sector and private organizations have started e-procurement activities. The entire tendering cycle from ‘Notice Inviting Tender’ to final placement of order happens online using Digital Signatures.
c. MCA 21: The recent high profile project of the ministry of Company affairs seeks to accept only online forms for all the filings under the Companies Act. All the incorporated companies, CAs., company secretaries and bank officials are covered as a part of this.
d. Income Tax Deptt. Has started accepting online returns for the income tax, provided they are digitally signed.
Obligations and Legalities:The effective use of digital signatures imposes certain obligations on the parties involved. The signers of electronic messages must protect their private key from compromise. This is the fundamental building block of the PKI. If a signer's private key is compromised, he must report it immediately so the CA can revoke his certificate and place it on a CRL. Certification authorities are obligated to use due diligence to verify the identity of their subscribers and their relationship to their public keys. The CA must also promptly suspend or revoke a certificate at a subscriber's request. Finally, the relying parties must actually verify the digital signature and check its validity against the current CRL maintained by an on-line repository.
Sunday, March 25, 2007
Mca 21 and corporate governance
National seminar on MCA21 and Corporate governance
Delhi College of advance studies has organized a national seminar on the MCA 21 and corporate governance. The chairman cyber appellate tribunal hon’ble R.C. Jain was the chief guest of the seminar. He was welcome by the chairman of the college Shri Bijender Singh and the members of organizing committee. There were many eminent speakers in the seminar including Shri S. koley, Rajesh Dogra (TCS),
Jagdeep S kochar (Gnfc), Dr.S.Chandrasekharan, Bipin. S. Acharya and Anurag Agnihotri. The Speakers were welcomed by director of college Dr. P.V.Khatri. shri Rajesh dogra has explained the practical applicability of the MCA21and role of TCS in it. Suchita Koley , a senior company secretary has explained the legal implication of the MCA21. Mr. Jagdeep .S. Kochar has explained the role of digital signature in the MCA21.
In the second session Dr. S. Chandrasekharan has provided the overview of corporate governance. Bipin S.Acharya has explained the issues and challenges of the corporate governance in Indian scenario. Mr. Anurag Agnihotri, has stated that the introduction of information technology in the corporate governance will bring the transparency and efficiency in the board functioning .it will also help in the investor’s protection.
In the audiences many prominent personsnalties were present. There were many professors; lecturers were present from many universities such as GGSIP university, Delhi university, IGNOU, Kurukshetra university and Jamia milia islamia. The personalities from other walk of life such as Supreme Court and Delhi High Court, and other areas including the research students were present. The vote thanks was given by prof. DPS Verma and Dr. Mohan. They were helped by the members of organizing committee, which include the Chairman, Director, faculties and the Students of the College. It was a great expirence of learning for every body in the audiences.
Delhi College of advance studies has organized a national seminar on the MCA 21 and corporate governance. The chairman cyber appellate tribunal hon’ble R.C. Jain was the chief guest of the seminar. He was welcome by the chairman of the college Shri Bijender Singh and the members of organizing committee. There were many eminent speakers in the seminar including Shri S. koley, Rajesh Dogra (TCS),
Jagdeep S kochar (Gnfc), Dr.S.Chandrasekharan, Bipin. S. Acharya and Anurag Agnihotri. The Speakers were welcomed by director of college Dr. P.V.Khatri. shri Rajesh dogra has explained the practical applicability of the MCA21and role of TCS in it. Suchita Koley , a senior company secretary has explained the legal implication of the MCA21. Mr. Jagdeep .S. Kochar has explained the role of digital signature in the MCA21.
In the second session Dr. S. Chandrasekharan has provided the overview of corporate governance. Bipin S.Acharya has explained the issues and challenges of the corporate governance in Indian scenario. Mr. Anurag Agnihotri, has stated that the introduction of information technology in the corporate governance will bring the transparency and efficiency in the board functioning .it will also help in the investor’s protection.
In the audiences many prominent personsnalties were present. There were many professors; lecturers were present from many universities such as GGSIP university, Delhi university, IGNOU, Kurukshetra university and Jamia milia islamia. The personalities from other walk of life such as Supreme Court and Delhi High Court, and other areas including the research students were present. The vote thanks was given by prof. DPS Verma and Dr. Mohan. They were helped by the members of organizing committee, which include the Chairman, Director, faculties and the Students of the College. It was a great expirence of learning for every body in the audiences.
National seminar on MCA21 and Corporate governance
Delhi College of advance studies has organized a national seminar on the MCA 21 and corporate governance. The chairman cyber appellate tribunal hon’ble R.C. Jain was the chief guest of the seminar. He was welcome by the chairman of the college Shri Bijender Singh and the members of organizing committee. There were many eminent speakers in the seminar including Shri S. koley, Rajesh Dogra (TCS),
Jagdeep S kochar (Gnfc), Dr.S.Chandrasekharan, Bipin. S. Acharya and Anurag Agnihotri. The Speakers were welcomed by director of college Dr. P.V.Khatri. shri Rajesh dogra has explained the practical applicability of the MCA21and role of TCS in it. Suchita Koley , a senior company secretary has explained the legal implication of the MCA21. Mr. Jagdeep .S. Kochar has explained the role of digital signature in the MCA21.
In the second session Dr. S. Chandrasekharan has provided the overview of corporate governance. Bipin S.Acharya has explained the issues and challenges of the corporate governance in Indian scenario. Mr. Anurag Agnihotri, has stated that the introduction of information technology in the corporate governance will bring the transparency and efficiency in the board functioning .it will also help in the investor’s protection.
In the audiences many prominent personsnalties were present. There were many professors; lecturers were present from many universities such as GGSIP university, Delhi university, IGNOU, Kurukshetra university and Jamia milia islamia. The personalities from other walk of life such as Supreme Court and Delhi High Court, and other areas including the research students were present. The vote thanks was given by prof. DPS Verma and Dr. Mohan. They were helped by the members of organizing committee, which include the Chairman, Director, faculties and the Students of the College. It was a great expirence of learning for every body in the audiences.
Delhi College of advance studies has organized a national seminar on the MCA 21 and corporate governance. The chairman cyber appellate tribunal hon’ble R.C. Jain was the chief guest of the seminar. He was welcome by the chairman of the college Shri Bijender Singh and the members of organizing committee. There were many eminent speakers in the seminar including Shri S. koley, Rajesh Dogra (TCS),
Jagdeep S kochar (Gnfc), Dr.S.Chandrasekharan, Bipin. S. Acharya and Anurag Agnihotri. The Speakers were welcomed by director of college Dr. P.V.Khatri. shri Rajesh dogra has explained the practical applicability of the MCA21and role of TCS in it. Suchita Koley , a senior company secretary has explained the legal implication of the MCA21. Mr. Jagdeep .S. Kochar has explained the role of digital signature in the MCA21.
In the second session Dr. S. Chandrasekharan has provided the overview of corporate governance. Bipin S.Acharya has explained the issues and challenges of the corporate governance in Indian scenario. Mr. Anurag Agnihotri, has stated that the introduction of information technology in the corporate governance will bring the transparency and efficiency in the board functioning .it will also help in the investor’s protection.
In the audiences many prominent personsnalties were present. There were many professors; lecturers were present from many universities such as GGSIP university, Delhi university, IGNOU, Kurukshetra university and Jamia milia islamia. The personalities from other walk of life such as Supreme Court and Delhi High Court, and other areas including the research students were present. The vote thanks was given by prof. DPS Verma and Dr. Mohan. They were helped by the members of organizing committee, which include the Chairman, Director, faculties and the Students of the College. It was a great expirence of learning for every body in the audiences.
Subscribe to:
Posts (Atom)