Loading...

⚠ โœ•
❮ Top
☎ Help
Draft upto 3 replies to a
tax notice โ€” FREE ๐ŸŽ‰ โœ•

150 credits ยท 30 days

โ€ข Basic Search โ†’ 1 Credit
โ€ข Advanced Search โ†’ 3 Credits
โ€ข Drafter โ†’ 20 to extract + 25 per issue
(โ‰ˆ upto 2-3 drafts on us)

Already used our earlier 20-Credit Demo?
You are still eligible for this new 150-Credit Demo.

Activate your FREE Demo โ†’
☰
×

By creating an account you can:

Logo TaxTMI
Call Us / Help / Feedbackโœ•

Contact Us At :

✉ E-mail: [email protected]

✆ Call / WhatsApp at: +91 99117 96707

For more information, Check Contact Us

FAQs :

To know Frequently Asked Questions, Check FAQs

Most Asked Video Tutorials :

For more tutorials, Check Video Tutorials

Submit Feedback/Suggestion :

Email :
Please provide your email address so we can follow up on your feedback.
Category :
Description :
Min 15 characters 0/2000
TMI Blog
Home / TMI Blogs / RSS

Digital Signature (End entity) Rules, 2015

X X   X X   Extracts   X X   X X

Full Text of the Document

X X   X X   Extracts   X X   X X

.... shall be standardised by applying consistent rules, primarily as part of the xml digital signature creation and verification processes; (c) "counter signature" means a signature on a previous signature in a series of signatures, affixed after the verification the signature on electronic record and subsequent signatures on previous signatures serially; (d) "detached signature" means the signature that is stored independent of electronic record being signed; (e) "digestmethod element", in relation to a xml digital signature, means the digest algorithm to be used for the original data object or transformed, if any 'xml transforms' exists; (f) "digestvalue element" means the value of the digest; (g) "end entity" means the subscriber or system on behalf of the subscriber in whose name the Electronic Signature Certificate is issued; (h) "end entity signature" means authentication of any electronic record by an end entity by means of a digital signature, electronic method or procedure in accordance with the provisions of sections 3 or 3A of the Act; (i) "enveloped signature" means enveloping of the signature and the i....

X X   X X   Extracts   X X   X X

Full Text of the Document

X X   X X   Extracts   X X   X X

....ographic functions involved in the signature generation; (x) "signature properties" means an element that provides a way to carry additional information about the signature, such as a time stamp or any other information which are defined by application; (y) "time stamp" means a notation that indicates the correct date and time of an action and identity of the person or device that sent or received the time stamp and is enforced using time stamp token; (z) "time stamp token " means a cryptographically secure confirmation generated by applying digital signature of a time stamping service provider that includes the time when the confirmation was generated; (za) "time stamping service provider " means a trusted entity authorised to generate time stamps; (zb) "xml" means Extensible Markup Language that provides a standard methodology with formal syntax to identify elements of information, describe the structure of data and also to store data in an independent manner, shall have the following properties,- (i) with xml, content and presentation are separate; (ii) the structure of xml data in a particular context is described u....

X X   X X   Extracts   X X   X X

Full Text of the Document

X X   X X   Extracts   X X   X X

....gs respectively assigned to them in the said Act. 3. Manner of authentication of information by means of digital signature.- A digital signature shall,- (a) be created and verified by cryptography which concerns with transforming electronic record into seemingly unintelligible forms; (b) use Public Key Cryptography, which employs an algorithm using two different but mathematical related keys; one key (called the private key) for creating a digital signature and another key (called the public key) for verifying a digital signature; (c) use an hash function for creating and verifying a digital signature which required to make digital signature generation and verification efficient. 4. Creation of digital signature.- (1) The signatory shall, while signing an electronic record or any other item of information, first apply an hash function in the signatory's hardware or software. (2) The hash function shall produce a hash result. (3) The signatory's hardware or software shall then transform the hash result into a digital signature using signatory's private key and signature algorithm. (4) The contextual information like date and time....

X X   X X   Extracts   X X   X X

Full Text of the Document

X X   X X   Extracts   X X   X X

....ll be verified. (3) To verify parallel signature, signature on electronic record shall be verified independently. (4) To verify long term signature, the initial timestamp and all subsequent time stamp applied on the each prior timestamp shall be verified. 6. Verification of Digital Signature Certificate.- (1) The self signed certificate generated by the Controller, which begins the trust chain for the public key infrastructure, shall be used to verify the authenticity of the public key certificate of the licensed Certifying Authorities. (2) The public key certificate of the licensed Certifying Authorities shall be used to verify the authenticity of the digital signature certificate issued to the subscribers. (3) The certificate revocation list maintained by the licensed Certifying Authorities shall be checked to confirm whether the certificate of the licensed Certifying Authorities is valid or whether it has been revoked under section 38 the Act. (4) While verifying the validity of a digital signature the corresponding digital signature certificate shall chain up through the public key certificate of the issuing Certifying Authority to the self signed certificate ....

X X   X X   Extracts   X X   X X

Full Text of the Document

X X   X X   Extracts   X X   X X

.... create reference(s) element(s) with reference to the item of information, xml transform element(s) (optional), digest algorithms and digest value; (b) optionally apply xml transform(s) to each referenced object in a sequential order; (c) apply the hash function in the signatory's hardware or software to each reference elements, store the hash result in the reference element; (d) ensure that if the object element is created, it shall not have a manifest element; (e) ensure that exclusive canonicalization "without comments" has been mandatorily specified in addition to any other transforms. (3) For the purpose xml digital signature generation, the signing software shall- (a) create signed info element with signature method, canonicalisation method and reference(s); (b) apply canonicalisation to signed info and calculate the hash value of canonicalised signed info using the hashing algorithms implied by the signature method; (c) ensure that,- (i) the signatory has seen all the contents of the document before signing; (ii) the contents display requirements, in the case of automated signing process,....

X X   X X   Extracts   X X   X X

Full Text of the Document

X X   X X   Extracts   X X   X X

.... (c) signature(s) and time stamps may be embedded in the data itself or stored separately as standalone. 10. Verification of xml digital signature.- (1) The verification of the xml digital signature shall be accomplished by signature validation, reference validation and certificate validation and an xml digital signature shall be treated valid only if signature validation, reference validation and certificate validation as specified below are complied with. (2) To accomplish signature validation- (a) canonical form of signed info as produced during reference validation shall be used; (b) canonical form of signature method using the canonicalization method shall be obtained; (c) the public key contained in the signatory's x509 certificate that is included in the xml digital signature, the canonicalisied form of signed info signature value, and canonicalisied form of signature method shall be used to verify the signature. (3) To accomplish reference validation- (a) canonicalise the signed info element based on the canonicalisation method in the signed info shall be used; (b) for each reference in the signed info- (i) ....