Indian Regulations regarding Recognition of Foreign Certifying Authorities : Facilitating Cross-Border Trade and Investments using Digital Signatures Website.

Slides:



Advertisements
Similar presentations
© ITU Telecommunication Development Bureau (BDT) – E-Strategy Unit.. Page - 1 Seminar on Standardization and ICT Development for the Information.
Advertisements

International forum on eNotarization and eApostilles The impact of e-technology on notarial acts: legal and technical possibilities and limits -relevance.
Digital Certificate Installation & User Guide For Class-2 Certificates.
Launching Egyptian Root CA and Inaugurating E-Signature Dr. Sherif Hazem Nour El-Din Information Security Systems Consultant Root CA Manager, ITIDA.
AFACT eCOO WG interim meeting - Conference Call 1st March of 2011 Mahmood Zargar eCOO Experiences and Standards.
EXPORT CERTIFICATES IN GLOBAL FOOD TRADE Mr. Bi Kexin AQSIQ
Digital Certificate Installation & User Guide For Class-2 Certificates.
Policy interoperability in electronic signatures Andreas Mitrakas EESSI International event, Rome, 7 April 2003.
European Electronic Identity Practices Country Update of …………… Speaker: Date:
Promoting the Regulatory Recognition Approach to Accelerate Regional Financial Integration APFF Seattle 2014 July 7, 2014.
1st Expert Group Meeting (EGM) on Electronic Trade-ECO Cooperation on Trade Facilitation May 2012, Kish Island, I.R.IRAN.
Certification Authority. Overview  Identifying CA Hierarchy Design Requirements  Common CA Hierarchy Designs  Documenting Legal Requirements  Analyzing.
ESign-Online Digital Signature Service February 2015 Controller of Certifying Authorities Department of Electronics and Information Technology Ministry.
Identity Standards (Federal Bridge Certification Authority – Certificate Lifecycle) Oct,
The ABA’s Digital Signature Guidelines: An Imperfect Solution to Digital Signatures on the Internet By: Edward D. Kania.
I NFORMATION T ECHNOLOGY A CT B ACKGROUND 1. Drew inspiration from Model Law on Electronic Commerce adopted by the United Nations Commission of.
1 Steps for incorporation of company in India. 2 Obtain Digital Signature Certificate (DSC) Summarized steps for incorporation of company in India Obtain.
Information security An introduction to Technology and law with focus on e-signature, encryption and third party service Yue Liu Feb.2008.
6/1/20151 Digital Signature and Public Key Infrastructure Course:COSC Instructor:Professor Anvari Student ID: Name:Xin Wen Date:11/25/00.
Juan A. Avellán Chief Legal Officer WISeKey S.A. Regulatory Considerations for the Establishment of a Global Public Key Infrastructure.
COEN 351: E-Commerce Security Public Key Infrastructure Assessment and Accreditation.
Elitex ’08 : Securing Indian Cyber Space Interoperability and Standardisation issues for India PKI Sivarama Krishnan Executive Director PricewaterhouseCoopers.
E-Procurement: Digital Signatures and Role of Certifying Authorities Jagdeep S. Kochar CEO, (n)Code Solutions.
An ASEAN Mutual Recognition Arrangement for Tourism Services Professor Chris Cooper Bangkok December 2006 Professor Chris Cooper Bangkok December 2006.
In the CA I trust. A look at Certification Authorities James E. Shearer CSEP 590 March 8 th 2006.
Cross-border Empowerment of Next Generation Access National Networks MINISTRY OF TRANSPORT, INFORMATION TECHNOLOGY AND COMMUNICATIONS REPUBLIC OF BULGARIA.
Session 6: Data Integrity and Inspection of e-Clinical Computerized Systems May 15, 2011 | Beijing, China Kim Nitahara Principal Consultant and CEO META.
Rural Development Department Government of Tripura Venue: Conference Hall #1, Pragna Bhawan, Gorkhabasti Date: 7 th March, 2014.
Creating Trust in Electronic Environment - IT Act 2000 Deputy Controller (Technology) Controller of Certifying Authorities Ministry of Communications &
Self-Certification under ASEAN Trade in Goods Agreement (ATIGA)
Ministry of Transport, Information Technology and Communications Technological base: Interoperability Tsvetanka Kirilova Ministry of TITC Bulgaria.
Cyber Law & Islamic Ethics
UN Economic Commission for Europe 23rd UN/CEFACT FORUM 7-11 April rd UN/CEFACT FORUM – Geneva Tahseen A. Khan Project Proposal : Trusted Third Party.
Controller of Certifying Authorities PKI Technology - Role of CCA Assistant Controller (Technology) Controller of Certifying Authorities Ministry of Communications.
Controller of Certifying Authorities Public Key Infrastructure for Digital Signatures under the IT Act, 2000 : Framework & status Mrs Debjani Nag Deputy.
Digital Signatures. Electronic Record 1.Very easy to make copies 2.Very fast distribution 3.Easy archiving and retrieval 4.Copies are as good as original.
United Nations Economic Commission for Europe (UNECE) UN/CEFACT Single Window Repository September 2005 Tom Butterly Deputy Chief, Global Trade Solutions.
National Smartcard Project Work Package 8 – Security Issues Report.
European Electronic Identity Practices Country Update of Austria Peter F Brown Office of the CIO, Austrian Federal Chancellery Chair, CEN eGov Focus Group.
Facilitating Cross Border Trade and Commerce through Mutual Recognition of Digital Signatures/Certifying Authorities Controller of Certifying Authorities(CCA)
Galileo - Knowledge Testing Service e-MSoft Artur Majuch.
Recognition of Foreign Certifying Authorities Vakul Sharma © Vakul Corporate Advisory, 2014.
Circulation of authentic instruments under Regulation 650/2012 speaker – Ivaylo Ivanov – Bulgarian Notary Chamber.
Accounting Reform and Development in China FENG Shuping Assistant Minister, Ministry of Finance People's Republic of China.
Information Technology Act India is one of the few countries other than U.S.A, Singapore, Malaysia in the world that have Information Technology.
SPECIAL ECONOMIC ZONES BILL, 2013 PRESENTATION TO PORTFOLIO COMMITTEE ON TRADE AND INDUSTRY 11 JUNE
1 Certification of Community Origin Presenter Bernard Black Senior Project Officer – Customs & Trade Policy CARICOM Secretariat.
Risks of data manipulation and theft Gateway Average route travelled by an sent via the Internet from A to B Washington DC A's provider Paris A.
FOURTH EUROPEAN QUALITY ASSURANCE FORUM "CREATIVITY AND DIVERSITY: CHALLENGES FOR QUALITY ASSURANCE BEYOND 2010", COPENHAGEN, NOVEMBER IV FORUM-
Massella Ducci Teri Italian approach to long-term digital preservation Policies for Digital Preservation ERPANET Training Seminar.
Transboundary Trust Space February 16, 2012 Ensuring trust in information exchange – proposal and approaches from Russia and CIS-states (RCC states) National.
DIGITAL SIGNATURE. GOOD OLD DAYS VS. NOW GOOD OLD DAYS FILE WHATEVER YOU WANT – PUT ‘NA’ OR ‘-’ OR SCRATCH OUT FILE BACK DATED, FILE BLANK FORMS, FILE.
Evolving Issues in Electronic Data Collection Workshop Interoperability Russ Savage Electronic Transactions Liaison Arizona Secretary of State Office.
16-17 November 2005 COSCAP – NA Project Steering Group Guangzhou, China 1 Co-operating with the European Aviation safety Agency.
UNCITRAL United Nations Commission on International Trade Law Policy considerations on the Electronic Communications Convention Luca Castellani Head, UNCITRAL.
1 Mutual Acceptance of Conformity Assessment Results - Japan ’ s Experience and Observation - 16 March 2006 Shinji FUJINO Director International Standards.
M O N T E N E G R O Negotiating Team for the Accession of Montenegro to the European Union Working Group for Chapter 6 – Company Law Bilateral screening:
Content Introduction History What is Digital Signature Why Digital Signature Basic Requirements How the Technology Works Approaches.
TAIEX-REGIO Workshop on Applying the Partnership Principle in the European Structural and Investment Funds Bratislava, 20/05/2016 Involvement of Partners.
Certifying Authorities Liability under PKI: A Global Perspective Seema Sharma Senior Partner Vakul Corporate Advisory © All rights reserved, 2010.
 Introduction  History  What is Digital Signature  Why Digital Signature  Basic Requirements  How the Technology Works  Approaches.
ESign Aashutosh.
PRESENTATION OF MONTENEGRO
Co-operating with the European Aviation safety Agency
Legal And Policy Framework
Digital Signature.
Draft ETSI TS Annex C Presented by Michał Tabor for PSD2 Workshop
WEQ-012 PKI Overview March 19, 2019
ELECTRONIC SIGNATURES
ELECTRONIC SIGNATURES
Presentation transcript:

Indian Regulations regarding Recognition of Foreign Certifying Authorities : Facilitating Cross-Border Trade and Investments using Digital Signatures Website : cca.gov.in

AFACT Members and India AFACT members are already having strong economic linkages with India, eg,  India - ASEAN trade : $79.3 billion ( ), target of $100 billon by 2015 and $200 billion by  India - China trade : $ 67 billion ( ), target of $ 100 billion by 2015  India - Iran Trade : $ 13.4 billion ( ), India is also involved in projects like development of Chabahar Port, International North-South Corridor.  India – Japan Trade : $18.43 billion ( ),Comprehensive Economic Partnership Agreement signed.  India – Republic of Korea : $ 20.5 billion ( ), target of $ 40 billion by Comprehensive Economic Partnership Agreement in force.  Cross-border trade could be further facilitated by use of Digital Signatures

Why Digital Signatures? For using Internet as a safe and secure medium for e-Commerce and e-Governance Most countries have already given Legal Validity to Documents signed digitally. Electronic documents are convenient for copying,transmission,storage. Reduces dependence paper based documents, hence environment friendly. Digital Signatures provide Authenticity(assurance of the genuineness of the source/signer), Integrity(assurance that document hasn't been changed after signing) and Non-repudiation(the signer cannot later deny signing the document ) to electronic documents.

Digital Signature Usage in AFACT member countries Many of the AFACT members like Japan, S.Korea, India, Chinese Taipei, Malaysia, Singapore have already implemented Electronic Signature Act/IT Act modelled on UNCITRAL's Model Law and have provided legal validity to documents signed digitally at par with paper signature. The use of Digital Signatures is already widespread in many AFACT members and is increasing further due to presence of strong, secure and robust PKI environments

Public Key Infrastructure in India Information Technology Act, 2000 has given legal recognition to documents signed Digitally. Controller of Certifying Authorities(CCA) acts as the Regulator and Facilitator of PKI in India Certifying Authorities are licensed by the Controller (CCA).Compliance with the Information Technology Act, 2000 and other Rules and Regulations is monitored by the CCA. Office of CCA is also Root Certifying Authority of India. Public Keys of licensed Certifying Authorities are signed by the Office of CCA. More than 6.6 Million Digital Signature Certificates have been issued till now. Broad applications include eLICENCE, ePROCUREMENT, eIPO, eIncome Tax, eBanking, e-Governance.

Current Scenario : Public Key Infrastructure (PKI) Digitally signed documents are signed using a Private Key and verified using corresponding Public Key. Some Trusted Agency is required which certifies the association of an individual with the key pair. Such trusted agencies are called “Certifying Authorities”(CA).Most countries issue licenses to agencies which operate as CAs. Documents signed using Digital Signature Certificate issued by such recognized Certifying Authorities are legally equivalent to documents signed manually inmost countries. However, a CA which is legally recognized in country “X” may not be legally recognized in country “Y”

Limiting Recognition of Certifying Authorities creates few inconveniences Mr “Good-Trader” in a country “Utopia” has a Digital Signature Certificate issued by “SecureCA”, a recognized Certifying Authority in “Utopia” and wants to sign a document and send it to Mr “Good-Customer” in another country “Heaven”. However, “SecureCA” is not a recognized Certifying Authority in “Heaven” and hence the digitally signed document lacks legal validity in “Heaven”. To increase Mr. Good-Trader's problems, no recognized Certifying Authority of “Heaven” is having local presence in “Utopia”

A possible Solution The two countries “Utopia” and “Heaven” can have an arrangement through which recognized,licensed Certifying Authorities in both the countries are mutually recognized and Digital Signatures Certificates issued by them are accepted

 As per Section 19 (1) of the Information Technology Act, 2000 subject to conditions and restrictions as specified by regulations in this regard, the Controller may with the previous approval of the Central Government, and by notification in the Official Gazette, recognise any foreign Certifying Authority.  Section 89 of the Information Technology Act, 2000 requires consultation with the Cyber Regulations Advisory Committee and previous approval of the Central Government for framing Regulations for recognition of Foreign CAs.  The Controller of Certifying Authorities,following the procedure given in the IT Act, has issued Notification containing Regulations regarding Recognition of Foreign CAs.  The Notification can be accessed on CCA's website: Recognition of Foreign CAs : Indian Law

The Notification contains two sets of Regulations  One for recognized Foreign Certifying Authorities operating under a PKI Regulatory Authority comparable to that in India.  Other set of Regulations for those Foreign Certifying Authorities which are not operating under a PKI Regulatory Authority. Recognition of Foreign CAs : Indian Law

For Foreign Certifying Authorities operating under a Regulatory Authority  Digital Signature Certificates issued by a Foreign Certifying Authority,which has been authorized by legally recognized Regulatory Authority of its country, will be recognized in India, if the Controller of Certifying Authorities enters into a memorandum of understanding with the recognized Foreign Regulatory Authority.  Before entering into a Memorandum of Understanding, the Controller will ensure that the laws of the country under which such regulatory authority is established, require a level of reliability at least equivalent to that required for issuance of a Digital Signature Certificate under the IT Act of India,2000  The following are some of the factors, to be used for determining the level of reliability: (a)Financial and human resources, including existence of assets within the country; (b)Trustworthiness of hardware and software systems; (c)Procedures for processing of certificates and applications for certificates and retention of records; (d)Availability of information to subscribers identified in certificates and to potential relying parties; (e)Regularity and extent of Audit by an independent body; (f)Strength of Algorithms used.

We look forward to enter in MoUs with PKI Regulators from various countries for mutual recognition of Certifying Authorities. The details of Regulations in this regard are available on the website cca.gov.in.

Foreign Certifying Authorities not operating under any Regulatory Authority  Many countries do not have PKI Regulators like India. Certifying Authorities from such countries may also apply for recognition.  Recognition may be granted if the Controller is satisfied about their reliability, security and fulfillment other conditions.  Such CAs will have to apply to the CCA in the prescribed format. The Application should contain documents like CPS,a statement including the procedures with respect to identification of the applicant,a statement for the purpose and scope of anticipated Digital Signature Certificate technology, management, or operations to be outsourced, certified copies of the business registration documents and licences.  Further, such CAs will have to establish a Local Office in India and submit a performance bond.

International Initiatives for Cross-Border Recognition of Digital / Electronic Signatures  Regional Commonwealth in the field of Communications : The Trans-boundary Trust Space CIS Member States  European Union : Revision of e-Signature Directive for Cross-Border Mutual Recognition of Electronic IDs. esignature-directive  UN/CEFACT : A Project named “Recommendation for ensuring legally significant trusted trans-boundary electronic interaction” has been proposed, Recommendation 14.

Path Ahead 1.PKI Regulators need to work together to establish mutually acceptable Inter-operability Guidelines, security and audit criteria. However, in case countries whose IT Act/Electronic Signature Act is based on Model UNCITRAL Laws have some commonalities which will help in evolving such Guidelines. 2.MoUs for Mutual Recognition 3. Initiated with Korea through KISA, Iran through GRCA, Russia, Israel, Nepal, China, UNESCAP SRO-SSWA etc. 4.Seeking expression of interest with other AFACT members

Thank You Controller of Certifying Authorities(India) Website : cca.gov.in