E-sign services

30 Jun 2015

esign

For creating electronic signatures, the signer is required to obtain a Digital Signature Certificate (DSC) from a Certifying Authority (CA) licensed by the Controller of Certifying Authorities (CCA) under the Information Technology (IT) Act, 2000. Before a CA issues a DSC, the identity and address of the signer must be verified. The private key used for creating the electronic signature is stored in hardware cryptographic token which is secured with a password/pin. This current scheme of in-person physical presence, paper document based identity & address verification and issuance of hardware cryptographic tokens does not scale to a billion+ people. For offering fully paperless citizen services, mass adoption of digital signature is necessary.

To address these concerns, Govt. of India through the Department of Electronics and Information Technology, Ministry of Communications and Information Technology has launched a simple to use online service which allows everyone to have the ability to digitally sign electronic documents.

What is eSign?

eSign facilitates digitally signing a document by an Aadhaar holder using an Online Service. eSign is designed for applying Digital Signature using authentication of signer through Aadhaar e-KYC service. This is an integrated service which facilitates issuing a Digital Signature Certificate and performing signing of requested data by authenticating the Aadhaar holder. Aadhaar is mandatory for availing the eSign Service.

esign Flow
What are the expected benefits of eSign?

Easy and secure way to digitally sign information anywhere, anytime – eSign is an online service that offers application service providers the functionality to authenticate signers and perform the digital signing of documents using Aadhaar e-KYC service. Hardware tokens are not required to be used.

Facilitates legally valid signatures – eSign process involves consumer consent, Digital Signature Certificate generation, Digital Signature creation & affixing and Digital Signature Certificate acceptance in accordance with the provisions of the Information Technology (IT) Act, 2000. It enforces compliance, through API specification and licensing model of APIs. Comprehensive digital audit trail – in-built to confirm the validity of transactions is also preserved.

Flexible and easy to implement – eSign provides configurable authentication options in line with Aadhaar e-KYC service and also records the Aadhaar number that is used to verify the identity of the signer. The authentication options for eKYC include biometric (fingerprint or iris scan) or OTP (through the registered mobile in the Aadhaar database). eSign enables millions of Aadhaar holders easy access to legally valid Digital Signature service.

Respecting privacy – eSign ensures the privacy of the signer by requiring that only the thumbprint (hash) of the document be submitted for signature function instead of the whole document.

Secure online service – The eSign Service is governed by e-authentication guidelines. While authentication of the signer is carried out using Aadhaar e-KYC services, the signature on the document is carried out on a backend server of the e-Sign provider. eSign services are offered by trusted third party service provider, currently Certifying Authorities (CA) licensed under the IT Act. To enhance security and prevent misuse, Aadhaar holders private keys are created on Hardware Security Module (HSM) and destroyed.

  • Save cost and time
  • Aadhaar e-KYC based authentication
  • Improve User Convenience
  • Flexible and fast integration with application
  • Easy to apply Digital Signature
  • Biometric or OTP based authentication
  • Verifiable Signatures and Signatory
  • Aadhaar is mandatory
  • Legally recognized
  • Integrity with a complete audit trail
  • Managed by Licensed CAs
  • API subscription Model
  • Privacy concerns addressed
  • No key storage and key protection concerns
  • Simple Signature verification
  • Suitable for individual, business and Government
  • Short validity certificates
  • Immediate destruction of keys after usage

To know more about eSign, please visit the CCA website.

Total Comments - 89

Leave a Reply

  • rupesh vishwakarma - 8 years ago

    me e-hastakshar seva ko sbhi ke liye sulabh karane ke liye e- saksharta badana chahiye|

  • rupesh vishwakarma - 8 years ago

    ई-हस्ताक्षर सेवा का लाभ समस्त देश वासियों के लिए लाभदायक रहेगा इसके लिए ई -साक्षरता को बढावा देने की आवश्यकता हे|

  • Kaptan Singh_5 - 9 years ago

    This one is a remarkable step taken by Govt. of India. Saving time, paper work and of course papers.

  • Prakash Tanwani - 9 years ago

    I have a suggestion for Credit card Users to prevent frauds while making payments at various places.Whenever a card user swipes card at a particular place e.g.restaurant the respective bank whose card is swiped should send SMS to the card holder on cellphone to authenticate the use of his card.the owner should send verification code assigned to it by bank by replying the SMS.This will prevent any other person using the card/s.In case it’s stolen also this will help to prevent it’s miss-use.

  • Vishal Singh Panwar - 9 years ago

    My thoughts in the adhar card the money u wast on it if you would invest in the voters card the voters card can be like our dl containing all information like adhar card nd the adhar total wast of money

  • Balaji R - 9 years ago

    e-sign seems to fail for password protected documents like e Aadhaar. Is there any solution for it?

  • Sandeep Bachhas - 9 years ago

    eSign service is explained and in great details and it looks practical. As I understand, in eSign service, Aadhaar holder will NOT get DSC for use (like you can get DSC from a CA if you need for year or two), instead he will submit document hash to eSign provider to sign the document and each time he has to use eSign provider to sign the documents and a signing will happen on backend server.

    Sandeep Bachhas
    Sr. IT Security Analyst

  • SARAVANAN_46 - 9 years ago

    Long live Modi ji.. love you…
    Please Connect CSC APNA and Digital India..
    Give Statewide ID for continue State E gov schemes
    Thank you

  • Rajendra Mehta - 9 years ago

    currently different appliation requires diff signature defeating purpose of e-sign. As a director one needs diff signature and same person requires another signature for IT return or for signing stock market contracts. We need a common regulator who will supply e-sign to various vendors like NSDL, TCS etc. Please look into the same.

  • Sawan Kumar_5 - 9 years ago

    Internet of Thing(IoT) Who knows, you can be controlling other electronic appliances in your house after completing this geeks!
    http://geekonjava.blogspot.com/2015/07/iot-project-iphone-controlled-fan.html

  • sooraj kumar avasthi - 9 years ago

    EVERY HOME IN INDIA
    THE PART OF DIGITAL INDIA.
    EVERY PERSON IN INDIA
    THE PART OF DIGITAL INDIA.
    EVERY PLACE IN INDIA
    THE PART OF DIGITAL INDIA
    EVERY THING IN INDIA
    THE PART OF DIGITAL INDIA
    JAY HIND

  • INDER DEV BANSAL - 9 years ago

    Good…think