"Digital signature" and "electronic signature" get used interchangeably in everyday conversation, but Indian law treats them as genuinely different things — and Section 73 of the Bharatiya Sakshya Adhiniyam, 2023 (BSA) only governs one of the two. Understanding which one, and why the distinction survived the BSA's rewrite of the evidence code, matters every time a court is asked to verify whether a signed electronic document is authentic.
73. Proof as to verification of digital signature. In order to ascertain whether a digital signature is that of the person by whom it purports to have been affixed, the Court may direct— (a) that person or the Controller or the Certifying Authority to produce the Digital Signature Certificate; (b) any other person to apply the public key listed in the Digital Signature Certificate and verify the digital signature purported to have been affixed by that person.
Section 73 carries forward Section 73A of the Indian Evidence Act, 1872 — itself an insertion made by the Information Technology Act, 2000 — without any change in wording. It gives the Court two independent verification routes, and it is useful to think of them as complementary rather than alternative: one route interrogates the paper trail behind the signature, the other tests the signature itself against cryptographic proof.
Route (a) is a documentary route: the Court can direct the alleged signatory, the Controller of Certifying Authorities appointed under the IT Act, or the Certifying Authority itself, to produce the Digital Signature Certificate. The DSC is the credential that binds a specific public key to a specific individual's identity, issued after the Certifying Authority verifies the applicant's identity through its own procedures. Producing it lets the Court confirm the certificate exists, is validly issued, and has not expired or been revoked at the relevant time.
Route (b) is the technical route: the Court can direct any person — typically a forensic or technical expert, though the section does not require any specific qualification — to apply the public key listed in that Digital Signature Certificate against the disputed signature. Digital signatures rely on asymmetric cryptography: a private key, held only by the signatory, generates the signature; the corresponding public key, listed on the DSC, can verify that a given signature could only have been generated by that private key. If the verification succeeds, it demonstrates mathematically that the signature was affixed using the key pair bound to that individual's identity — a form of proof with no real analogue in the handwriting-comparison provisions that precede this section.
| Aspect | "Digital signature" — Section 73 | "Electronic signature" — Section 66 |
|---|---|---|
| IT Act basis | Section 3 (asymmetric cryptosystem + hash function) | Section 3A (technology-neutral, broader category) |
| Verification credential | Digital Signature Certificate, issued by a licensed Certifying Authority | No uniform credential — depends on the specific signature method used |
| Typical use case | Company filings, GST returns, court e-filings requiring a DSC token | Aadhaar eSign, OTP-based consent, click-wrap agreements |
Why does Section 73 give the Court two separate routes rather than mandating one? In practice, they answer different challenges to a digital signature's authenticity. Route (a) is the natural first step when the dispute is about whether the certificate itself was validly issued, current, or belonged to the person claimed — questions of institutional trust, resolved by the Certifying Authority's own records. Route (b) becomes necessary when the certificate's validity is not in dispute but the question is narrower and more technical: did this specific signature, on this specific document, actually verify against that particular public key? A forged digital signature will typically fail route (b)'s mathematical test even where the underlying DSC is perfectly genuine.
Section 73 also needs to be read alongside the separate statutory presumptions the IT Act itself attaches to secure digital signatures. Where a digital signature qualifies as a "secure" digital signature under the applicable IT Act provisions, the law separately presumes — unless the contrary is proved — that the signature is the signatory's own and was applied with the intention of signing the record. Section 73 is the evidentiary mechanism for testing that presumption when it is challenged, not a substitute for it; an unchallenged secure digital signature ordinarily needs no Section 73 verification exercise at all.
The section is also deliberately silent on who bears the cost or logistical burden of verification, and on what happens if a Certifying Authority has since ceased operations or had its licence revoked. In practice, courts have relied on the Controller of Certifying Authorities — the statutory regulator under the IT Act — as a fallback repository of licensing and revocation records when an individual Certifying Authority cannot itself produce a certificate, since the Controller maintains the root of trust for the entire licensed Certifying Authority hierarchy in India. This is one reason route (a) names the Controller separately from the Certifying Authority, rather than assuming the two will always be interchangeable sources for the same certificate.
Key Takeaways
- Unchanged from IEA 73A: Section 73 carries forward the 2000-era Information Technology Act insertion without any drafting change.
- Two independent verification routes: production of the Digital Signature Certificate (route a) and cryptographic public-key verification (route b).
- "Digital signature" is narrower than "electronic signature": Section 73 governs only the asymmetric-cryptosystem method under IT Act Section 3 — broader electronic signatures fall under Section 66 of this Act instead.
- Different routes answer different challenges: certificate validity disputes call for route (a); disputes about a specific signature's authenticity call for route (b).
- Complements, doesn't replace, IT Act presumptions: Section 73 is the mechanism for testing a secure digital signature's presumed authenticity once genuinely disputed.
Section 73 rarely comes up in routine litigation, precisely because most digital signatures go unchallenged — the cryptography behind them is, by design, far harder to forge convincingly than a handwritten signature. When a genuine dispute does arise, though, this section gives courts a verification toolkit that handwriting-comparison provisions simply cannot offer: a way to test a signature's authenticity mathematically, rather than by eye.