Consider the following statements:
A digital signature is
- 1.an electronic record that identifies the certifying authority issuing it
- 2.used to serve as a proof of identity of an individual to access information or server on Internet
- 3.an electronic method of signing an electronic document and ensuring that the original content is unchanged
Which of the statements given above is/are correct?
Answer & explanation
Answer: (c) 3 only
Why not the tempting option · UPSC's key is (c). Statement 2 is tempting because the Controller of Certifying Authorities says a digital signature 'provides the electronic authentication of individual', but the same sentence binds that authentication 'to the documents or transactions being signed': a digital signature authenticates a record, whereas proving one's identity to get access to information or a server is the job of a login credential or of a Digital Signature Certificate presented as one. Statements 1 and 2 both describe the certificate, not the signature. In the exam, keep the IT Act's distinction between the signature (section 2(1)(p)) and the certificate (section 35).
A digital signature is a method of authenticating an electronic record, and it also shows whether the record has been altered, so statement 3 is correct. Statement 1 describes a digital signature certificate issued by a Certifying Authority, and statement 2 describes proof of identity for access, which is not what a digital signature is.
- ✗ 1. This describes a Digital Signature Certificate, not the signature. The IT Act defines the two separately, and certificates are issued to users by licensed Certifying Authorities.
- ✗ 2. This too describes what a Digital Signature Certificate is used for. The signature itself authenticates a particular electronic record and ties the signer to it: the CCA says it provides electronic authentication of the individual and binds it to the documents or transactions being signed. A one-time proof of identity to get access to information or a server is a different thing.
- ✓ 3. Under the IT Act, 2000 a digital signature authenticates an electronic record through an asymmetric crypto system and a hash function, and anyone can verify the record with the signer's public key. Since the same record always gives the same hash result, a changed record fails verification.
Remember · Digital signature = electronic authentication of a record (asymmetric keys plus hash), which also shows the content is unchanged. The certificate that names the Certifying Authority is separate.
Sources
- Information Technology Act, 2000 (India Code), section 2(1)(p), definition of digital signature ↗ “means authentication of any electronic record by a subscriber by means of an electronic method or procedure in accordance with the provisions of section 3 … an electronic record yields the same hash result every time the algorithm is executed with the same electronic record as its input”
- Controller of Certifying Authorities (MeitY), FAQ: How to get Digital Signature Certificate ↗ “The Office of Controller of Certifying Authorities (CCA), issues Certificate only to Certifying Authorities(CAs). CAs issue Digital Signature Certificates to end-entities.”
- Controller of Certifying Authorities (MeitY), Digital Signature FAQ: Aadhaar eKYC authentication versus digital signature ↗ “the Digital Signature provides the electronic authentication of individual and bind it to the documents or transactions being signed”
Question and answer: UPSC's official GS Paper I (2019, Series A) — paper ↗ · answer key ↗. Explanation: Minimalist IAS, checked 1 Oct 2026 (how we verify). ·