E-sign services

Blog By - Team MyGov,
June 30, 2015

esign

For creating electronic signatures, the signer is required to obtain a Digital Signature Certificate (DSC) from a Certifying Authority (CA) licensed by the Controller of Certifying Authorities (CCA) under the Information Technology (IT) Act, 2000. Before a CA issues a DSC, the identity and address of the signer must be verified. The private key used for creating the electronic signature is stored in hardware cryptographic token which is secured with a password/pin. This current scheme of in-person physical presence, paper document based identity & address verification and issuance of hardware cryptographic tokens does not scale to a billion+ people. For offering fully paperless citizen services, mass adoption of digital signature is necessary.

To address these concerns, Govt. of India through the Department of Electronics and Information Technology, Ministry of Communications and Information Technology has launched a simple to use online service which allows everyone to have the ability to digitally sign electronic documents.

What is eSign?

eSign facilitates digitally signing a document by an Aadhaar holder using an Online Service. eSign is designed for applying Digital Signature using authentication of signer through Aadhaar e-KYC service. This is an integrated service which facilitates issuing a Digital Signature Certificate and performing signing of requested data by authenticating the Aadhaar holder. Aadhaar is mandatory for availing the eSign Service.

esign Flow
What are the expected benefits of eSign?

Easy and secure way to digitally sign information anywhere, anytime – eSign is an online service that offers application service providers the functionality to authenticate signers and perform the digital signing of documents using Aadhaar e-KYC service. Hardware tokens are not required to be used.

Facilitates legally valid signatures – eSign process involves consumer consent, Digital Signature Certificate generation, Digital Signature creation & affixing and Digital Signature Certificate acceptance in accordance with the provisions of the Information Technology (IT) Act, 2000. It enforces compliance, through API specification and licensing model of APIs. Comprehensive digital audit trail – in-built to confirm the validity of transactions is also preserved.

Flexible and easy to implement – eSign provides configurable authentication options in line with Aadhaar e-KYC service and also records the Aadhaar number that is used to verify the identity of the signer. The authentication options for eKYC include biometric (fingerprint or iris scan) or OTP (through the registered mobile in the Aadhaar database). eSign enables millions of Aadhaar holders easy access to legally valid Digital Signature service.

Respecting privacy – eSign ensures the privacy of the signer by requiring that only the thumbprint (hash) of the document be submitted for signature function instead of the whole document.

Secure online service – The eSign Service is governed by e-authentication guidelines. While authentication of the signer is carried out using Aadhaar e-KYC services, the signature on the document is carried out on a backend server of the e-Sign provider. eSign services are offered by trusted third party service provider, currently Certifying Authorities (CA) licensed under the IT Act. To enhance security and prevent misuse, Aadhaar holders private keys are created on Hardware Security Module (HSM) and destroyed.

  • Save cost and time
  • Aadhaar e-KYC based authentication
  • Improve User Convenience
  • Flexible and fast integration with application
  • Easy to apply Digital Signature
  • Biometric or OTP based authentication
  • Verifiable Signatures and Signatory
  • Aadhaar is mandatory
  • Legally recognized
  • Integrity with a complete audit trail
  • Managed by Licensed CAs
  • API subscription Model
  • Privacy concerns addressed
  • No key storage and key protection concerns
  • Simple Signature verification
  • Suitable for individual, business and Government
  • Short validity certificates
  • Immediate destruction of keys after usage

To know more about eSign, please visit the CCA website.

  • usericon
    rupesh vishwakarma - 9 years ago

    me e-hastakshar seva ko sbhi ke liye sulabh karane ke liye e- saksharta badana chahiye|

  • usericon
    rupesh vishwakarma - 9 years ago

    ई-हस्ताक्षर सेवा का लाभ समस्त देश वासियों के लिए लाभदायक रहेगा इसके लिए ई -साक्षरता को बढावा देने की आवश्यकता हे|

  • usericon
    subhash mallick - 9 years ago

    Sir, my request is Govt. have to open "citizen center" in every Panchayat i.e. in village level, so that common people have to operate or find help from that center. otherwise this type of important system will be meaning less.

  • usericon
    Lokesh_27 - 9 years ago

    Sir,can we arrange TT for every local train,because due large numbers of people in queue people not able to buy ticket.if we arrange TT in every local train it makes profit to railways.

  • usericon
    sunil kumar_203 - 9 years ago

    Modi ji i am sunil kumar ..asstt lecturer working in an Autonomous institute but governed by central government ministry of tourism and affiliated from NCHMCT…sir i am phschially hadicapped person and working in kerela ,but my hometown is baghpat uttarpredesh…sir there is no rule as such under nchmct that a phschially handicapped would pe posted near to his hometown…sir i am handicapped person and have two childeren and i face lots of difficulty in travelling …please help me sir..plz

  • usericon
    varala praveenkumar - 9 years ago

    RESPECTED PRIME MINISTER OF INDIA: sir we request you to furinish the satus of the case and action should taken on uor represention of 31.5.2014 and copy enclosed to jintersing pmo 11.6.2014 and nripendra mishra pri se7.201cto pm. and sir we appiled RTI ON 16.7.2014 and on 17.8.2014. A postal bearing number 29F 422035 RTINUMBER:14171204/PMR. SIR no action is taken on TRS MLC SWAMY GOUD TELANGANA MANDAL CHAIRMAN.

  • usericon
    Chandrashekara Hebbar Kollya - 9 years ago

    Of late traditional signature by pen is all most out dated. Practically, in course of time a person’s hand writing inevitably changes. That doe’s not mean that the person is fake. Now a days banks irritate account holder for small change in signature.So there is requirement of Innovation in way and means of signature. Biometric signature has long history of thumb impression. In the same manner the modern day signature can be hybrid by electronic thumb impression. Zero ink & environment friendly

  • usericon
    nimesh chitalia - 9 years ago

    sir,
    i like to give you input on HSM , HSM should be self destroy instead of it is been destroyed, secondly i feel it will be little unsecure on sharing individual signature online , instead one should be given password for securly submitting his documents for E-SIGN

  • usericon
    ANUSHA_10 - 9 years ago

    e Aadhaar card pdf is password protected and it can’t be e-signed. Can we fix this issue or this is intended behaviour?

  • usericon
    Rishi Sharma_1 - 9 years ago

    Most important before generating e-sign is to maintain security of theft and misuse of esignature it should be bind with mobile number of residents so that if any of the resident uses e-signature it should generate an OTP or CAPTCHA before signing any documents.

  • usericon
    SUBRAMANIAN C RAMANARAYANAN - 9 years ago

    Why criticisms await moderation for so many days. better i use other media to criticize.

  • usericon
    RAJEEV BHANDARI - 9 years ago

    compare to computer based internet in future the mobile use internet will increase, so please create eSign and mSign both. please insure that this kind of signature also should be applicable for banking application and future money transaction by mobile.

Total Comments - 89

Leave a Reply