Consider the following statements: A digital signature is 1. an electronic record that identifies the certifying authority issuing it 2. used to serve as a proof of identity of an individual to access information or serve on Internet 3. an electronic method of signing an electronic document and ensuring that the original content is unchanged Which of the statements given above is/are correct?

Updated 11 Apr 2026 · From UPSC Prelims GS Paper I 2019, Q95

Contents16
UPSC Prelims GS2019Science and Technology
  1. A1 only
  2. B2 and 3 only
  3. C3 only
  4. D1, 2 and 3
Show answer

Answer: (C) 3 only

Correct Answer: 3 only

The Core Difference: Signature vs. Certificate

The examiner is testing whether you can tell the difference between a Digital Signature (an action/mathematical tool) and a Digital Certificate (an identity file).


1. Identifies the certifying authority (Incorrect)

  • The Mistake: A digital signature doesn't identify the authority; a Digital Certificate does.
  • The Truth: Think of a Digital Certificate like a digital passport issued by an official agency (Certifying Authority) to prove who you are.

2. Proof of identity to access a server (Incorrect)

  • The Mistake: You don't use a signature to log in or access a secure server; you present your Digital Certificate (like showing your ID card at a secure entrance).

3. Electronic method of signing and ensuring content is unchanged (Correct)

  • The Truth: This is the exact definition of a Digital Signature. It uses cryptography to lock a document. If anyone alters even a single letter after it is signed, the signature instantly breaks, proving the document was tampered with.

The Simple Parallel

Concept Everyday Equal What it actually does
Digital Certificate Your Passport / ID Card Proves your identity to an outside system or server.
Digital Signature Ink Signature + Wax Seal Locks a document to prove it came from you and hasn't been altered.

Because Statements 1 and 2 describe a Certificate, only Statement 3 correctly describes a Signature.

Why this was asked

Digital signatures became mandatory for many government and business transactions in India, making this a core e-governance concept.

UPSC is testing whether students understand that digital signatures serve dual purposes: identity verification (like an ID card) and document integrity (like a tamper-proof seal).

The question checks if students can distinguish between the technical function (ensuring unchanged content) and practical applications (identity proof for online access).

Digital Signature Certificates (DSC)

Science And Technology digital signature electronic record certifying authority

Digital Signature Certificates: Identity, Authentication & Document Integrity

Must know

DSC is an electronic identity certificate issued by Certifying Authority (CA)

Serves dual purpose: proves identity AND ensures document integrity

Legally valid under Information Technology Act, 2000

Good to know

Uses asymmetric cryptography with public-private key pairs

What is DSC

A Digital Signature Certificate (DSC) is the electronic equivalent of a physical identity document like a passport or driving licence. It combines identity verification with document security in the digital world.

Three Core Functions of DSC

Function

What it Does

Real-world Analogy

Identity Verification

Identifies the Certifying Authority that issued the certificate

Passport shows issuing country

Authentication

Proves your identity to access online services

ID card at office entry

Document Integrity

Ensures signed document content remains unchanged

Tamper-evident seal on packages

How DSC Works

%%{init: {"flowchart": {"wrappingWidth": 460}}}%%
flowchart TD
  s1["`**Certificate Issuance**
**Certifying Authority** verifies identity and issues DSC with public-private key pair`"]
  s2["`**Document Signing**
User signs document with **private key**, creating unique digital signature`"]
  s3["`**Verification**
Recipient uses **public key** to verify signature and document integrity`"]
  s4["`**Trust Chain**
CA's digital signature on certificate establishes authenticity`"]
  s1 --> s2
  s2 --> s3
  s3 --> s4

Key Technical Features

Uses asymmetric cryptography — different keys for signing and verification

Creates a hash of document content that changes if document is altered

Non-repudiation — signer cannot deny having signed the document

Time-stamping capability shows when document was signed

Certificates have validity periods and can be revoked if compromised

Question Connection

This question tested all three core functions of DSC. Many students incorrectly think digital signatures only verify documents, missing the identity and authentication aspects covered in statements 1 and 2.

Exam traps

Trap: Confusing Digital Signature with Electronic Signature — digital signatures use cryptography, electronic signatures are broader

Trap: Thinking DSC only ensures document integrity — it also provides identity verification and authentication

Trap: Mixing up Certifying Authority with the certificate holder — CA issues and verifies, holder uses

Common Error: Believing all three statements cannot be correct together — DSC serves multiple purposes simultaneously

Certifying Authorities & PKI

Science And Technology certifying authority

Certifying Authorities: The Trust Foundation of Digital India

Must know

Certifying Authority (CA) is licensed entity that issues and manages digital certificates

Controller of Certifying Authorities (CCA) under IT Ministry regulates CAs in India

Good to know

CAs form the trust backbone of Public Key Infrastructure (PKI)

Role of CAs

Certifying Authorities act as trusted third parties that verify identities and issue digital certificates. They are the digital equivalent of passport offices — government or licensed agencies that vouch for your identity.

CA Functions & Responsibilities

Function

Description

Example

Identity Verification

Verify applicant's identity before issuing certificate

Check PAN card, Aadhaar for individual DSC

Certificate Issuance

Generate and issue digital certificates with key pairs

Issue Class 2 or Class 3 DSC

Certificate Management

Maintain validity, renewal, and revocation services

Revoke compromised certificates

Trust Services

Provide timestamping and other trust services

RFC 3161 compliant timestamps

PKI Ecosystem in India

# Public Key Infrastructure
## Regulation
- Controller of CAs (CCA)
- IT Act 2000
- DSC Rules 2001
## Licensed CAs
- (n)Code Solutions
- SafeScrypt
- eMudhra
- NIC Certifying Authority
## Certificate Types
- Class 1 (Email)
- Class 2 (Personal)
- Class 3 (Business)
## Applications
- e-Filing
- e-Tendering
- MCA Portal
- GST Portal

Information Technology Act, 2000 provides legal recognition to digital signatures

Section 35 empowers Central Government to appoint Controller of Certifying Authorities

Only licensed CAs can issue legally valid digital certificates in India

Cross-certification allows international recognition of Indian DSCs

Exam traps

Trap: Confusing CA (Certifying Authority) with CCA (Controller of Certifying Authorities) — CCA regulates CAs

Trap: Thinking any organization can issue legally valid DSCs — only licensed CAs can

Trap: Missing that CAs are regulated entities under IT Act, not private companies operating freely

Digital Authentication Methods

Science And Technology proof of identity access information Internet

Digital Authentication: From Passwords to Biometrics

Must know

Authentication verifies 'who you are' using something you know/have/are

Multi-factor Authentication (MFA) combines 2+ authentication methods

Good to know

Digital certificates provide strongest authentication for online services

Authentication vs Authorization

Authentication answers 'Who are you?' while Authorization answers 'What can you do?' Digital signatures primarily handle authentication — proving your identity to access systems or sign documents.

Types of Authentication Factors

Factor Type

What It Uses

Examples

Security Level

Something you know

Knowledge

Password, PIN, Security Questions

Low

Something you have

Possession

Mobile OTP, Smart Card, DSC

Medium

Something you are

Biometrics

Fingerprint, Face, Iris scan

High

Multi-factor (MFA)

Combination

Password + OTP, Biometric + DSC

Very High

Digital India Authentication Systems

# Digital Authentication
## Aadhaar-based
- UIDAI eKYC
- Aadhaar OTP
- Biometric Auth
- e-Sign
## Certificate-based
- DSC Class 2/3
- SSL Certificates
- Code Signing
## Banking
- Net Banking
- UPI PIN
- Card + OTP
- Mobile Banking
## Government
- DigiLocker
- UMANG
- e-Filing portals
- GST Login

Passwordless authentication using biometrics and hardware tokens gaining popularity

Zero Trust Architecture — verify every user and device, regardless of location

Behavioral analytics detect unusual login patterns for additional security

FIDO standards enable secure authentication across devices and platforms

Exam traps

Trap: Confusing authentication (who you are) with authorization (what you can access)

Trap: Thinking OTP alone is multi-factor — it's single factor if sent to registered number

Trap: Missing that DSC combines authentication (proves identity) with digital signing capability