Home India Ministry of Communications In exercise of the powers conferred by section 87 of the Inf...
Date: 2015-08-26 Category: Extra Ordinary State: Union Government Country: India

In exercise of the powers conferred by section 87 of the Information Technology Act, 2000 (21 of 2000), the Central Government hereby makes the following rules, namely.

Issued by Ministry of Communications · Department of Electronics and Information Technology

Research with AI Agent Chat with Document Generate Summary Translate Helpful Share Add to Project Create Task

Executive Summary & Key Takeaways

Executive Summary: The document comprises three notifications from the Ministry of Communications and Information Technology, Department of Electronics and Information Technology. These notifications establish the Digital Signature End Entity Rules, amend the Information Technology Security Procedure Rules, and further amend the Information Technology Certifying Authorities Rules. All rules come into force on the date of their publication in the Official Gazette, August 25, 2015. Key Points / Main Content: Digital Signature End Entity Rules, 2015: * **Short Title and Commencement:** These rules are called the Digital Signature End Entity Rules, 2015 and take effect on the date of publication in the Official Gazette. * **Definitions:** Defines key terms related to digital signatures and XML digital signatures, including "Act," "canonicalisation," "counter signature," "detached signature," "end entity," "long term signature," "time stamp," "XML," and others. * **Authentication by Digital Signature:** Specifies that a digital signature shall be created and verified by cryptography, use Public Key Cryptography, and use a hash function. * **Creation of Digital Signature:** Outlines the process for creating a digital signature, including applying a hash function, transforming the result using a private key, and including contextual information like date and time. Allows for counter and parallel signatures. Specifies that a timestamp shall be applied to create long term valid digital signatures. * **Verification of Digital Signature:** Describes how to verify a digital signature, counter signature, parallel signature and long term signature. * **Verification of Digital Signature Certificate:** Details the process for verifying a digital signature certificate, including checking the trust chain and certificate revocation lists. * **Digital Signature Standards:** Lists applicable standards for cryptographic hash functions, RSA Public Key Technology, ECC curve and long term signature formats. * **Authentication by XML Digital Signature:** Specifies that XML digital signatures shall be created and verified by cryptography, use Public Key Cryptography, use a cryptographic hash function, and use canonicalization and XML transformation. * **Creation of XML Digital Signature:** Outlines the process for creating an XML digital signature, including constructing reference elements, XML digital signature element, signedinfo, keyinfo and signaturevalue. * **Verification of XML Digital Signature:** Describes how to verify an XML digital signature, including signature validation, reference validation, and certificate validation. Specifies how to verify counter signature, parallel signature and long term signature. * **XML Digital Signature Standards:** Lists applicable standards for XML digital signatures. * **Digital Signature Functions Standard:** Specifies guidelines issued by the Controller for digital signature creation and verification, in respect of signature profile and signature format. Amendment to Information Technology Security Procedure Rules, 2004: * **Short Title and Commencement:** These rules are called the Information Technology Security Procedure Amendment Rules, 2015 and take effect on the date of publication in the Official Gazette. * **Rule 2 Amendment:** Updates the definition of words and expressions to include those defined in the Digital Signature End Entity Rules, 2015. * **Rule 4 Amendment:** Updates the standards to refer to rule 7 or rule 12 of the Digital Signature End entity Rules, 2015 regarding the creation, storage and transmission of the digital signature. Amendment to Information Technology Certifying Authorities Rules, 2000: * **Short Title and Commencement:** These rules are called the Information Technology Certifying Authorities Amendment Rules, 2015 and take effect on the date of publication in the Official Gazette. * **Rule 6 Amendment:** Modifies the standard entries for DSA and RSA to include Curves NIST P256, P384, or P521. * **Rule 7 Substitution:** Requires all Digital Signature Certificates and Certificate Revocation Lists issued by Certifying Authorities to conform to Interoperability Guidelines issued by the Controller. * **Rule 23 Amendment:** Includes Identity Verification Guidelines issued by the Controller for subscriber identity verification. * **Rule 24 Amendment:** Includes X.509 Certificate Policy for India PKICP issued by the Controller at the end. * **Rule 25 Amendment:** Includes Identity Verification Guidelines issued by the Controller at the end. * **Rule 31 Amendment:** Inserts new clauses related to compliance with X.509 Certificate Policy, guidelines for Time Stamping and OCSP service, Identity Verification Guidelines, and Digital Signature Certificates Interoperability Guidelines. * **Schedule IV Amendment:** Modifies Forms A and B by substituting "filled" with "signed" and omitting "Application form must be submitted in person." Also updates Authentication of Identity and Proof of Residence requirements in Form B. Impact Analysis: Certifying Authorities (CAs): * Impact: CAs must ensure their Digital Signature Certificates and Certificate Revocation Lists conform to the Controller's Interoperability Guidelines. They must also adhere to new Identity Verification Guidelines. * Action Required: Update practices and statements to align with the new rules, including changes to certificate policies and implementation of updated identity verification methods. Subscribers/End Entities: * Impact: End entities are subject to new rules regarding the creation, verification, and long-term validity of digital signatures and XML digital signatures. * Action Required: Understand and comply with the new requirements for digital signature creation and verification, including the use of specified cryptographic standards and timestamping procedures. Controller of Certifying Authorities: * Impact: The Controller's role is reinforced through the issuance of guidelines and oversight of compliance with the new rules. * Action Required: Issue and maintain updated guidelines for digital signature certificates, identity verification, and other relevant services, and ensure CAs comply with these guidelines.

Key Entities Referenced

Information Technology Act, 2000: An Act of the Parliament of India concerning Information Technology Digital Signature End entity Rules, 2015: Rules pertaining to Digital Signatures Certifying Authorities: Entities licensed to issue Digital Signature Certificates Information Technology Certifying Authorities Rules, 2000: Rules governing the operation of Certifying Authorities Public Key Cryptography: Cryptographic system using pairs of keys: public keys and private keys. Digital Signature Certificate: An electronic document used to verify the identity of an individual, a computer, or other entity. Information Technology Security Procedure Rules, 2004: Rules pertaining to Information Technology Security Procedure Controller of Publications, Delhi: Publisher of the Gazette of India
Official Source Record View Original Source →
See Full Document Text
jftLVªh laö Mhö ,yö&33004@99 REGD. NO. D. L.-33004/99 vlk/kj.k EXTRAORDINARY Hkkx II—[k.M 3—mi&[k.M (i) PART II—Section 3—Sub-section (i) izkf/dkj ls izdkf'kr PUBLISHED BY AUTHORITY la- 530] ubZ fnYyh] cq/okj] vxLr 26] 2015@Hkkæ 4] 1937 No. 530] NEW DELHI, WEDNESDAY, AUGUST 26, 2015/BHADRA 4, 1937 ससससचचंंचचंं ाााारररर औऔऔऔरररर ससससचचूूचचूू ननननाााा (cid:1)(cid:1)(cid:1)(cid:1)ौौौौ(cid:3)(cid:3)(cid:3)(cid:3)ोोोोििििगगगगकककक(cid:8)(cid:8)(cid:8)(cid:8) मममम(cid:11)(cid:11)ंं(cid:11)(cid:11)ंं ााााललललयययय ((((इइइइलललल(cid:17)(cid:17)ैै(cid:17)(cid:17)ैै (cid:18)(cid:18)(cid:18)(cid:18)ॉॉॉॉििििननननकककक(cid:8)(cid:8)(cid:8)(cid:8) औऔऔऔरररर ससससचचूूचचूू ननननाााा (cid:1)(cid:1)(cid:1)(cid:1)ौौौौ(cid:3)(cid:3)(cid:3)(cid:3)ोोोोििििगगगगकककक(cid:8)(cid:8)(cid:8)(cid:8) ििििववववभभभभाााागगगग)))) अअअअििििधधधधससससचचूूचचूू ननननाााा नई (cid:1)द(cid:3)ली, 25 अग(cid:8)त , 2015 ससससाााा....ककककाााा....ििििनननन.... 666666660000((((अअअअ))))....—के(cid:13) (cid:14)ीय सरकार, सूचना (cid:15)ौ(cid:17)ोिगक(cid:20) अिधिनयम, 2000 (2000 का 21) क(cid:20) धारा 87 (cid:21)ारा (cid:15)द(cid:24) शि(cid:26)य(cid:28) का (cid:15)योग करते (cid:29)ए िन(cid:31)िलिखत िनयम बनाती ह,ै अथा"त ्:-- 1. ससससंिंिंिंि(cid:22)(cid:22)(cid:22)(cid:22)(cid:23)(cid:23)(cid:23)(cid:23)तत तत ननननाााामममम औऔऔऔरररर (cid:1)(cid:1)(cid:1)(cid:1)ााााररररंंंंभभभभ....―――― (1) इन िनयम(cid:28) का संि)* त नाम अंक(cid:20)य ह(cid:8)त ा)र (अंितम िनकाय) िनयम, 2015 ह ै । (2) ये उनके राजप/ म 0 (cid:15)काशन क(cid:20) तारीख से (cid:15)वृ3त ह(cid:28)गे । पपपप(cid:30)(cid:30)(cid:30)(cid:30)ररररभभभभााााषषषषााााएएएए―ंंंं (1) इन िनयम(cid:28) म0 जब तक (cid:1)क संदभ" स े अ(cid:13)य था अपेि)त न हो,— """"अिधिनयम"""" से सूचना (cid:15)ौ(cid:17)ोिगक(cid:20) िनयम,,,, 2000 (2000 का 21) अिभ(cid:15)ेत ह ै;;;; ((((क)))) ““““कैनोिनकैलाइजोशन””””,,,, (cid:1)कसी ए:स एमएल अंक(cid:20)य ह(cid:8)त ा)र के संबंध (cid:1)कसी इलै:< ोिनक(cid:20) अिभलेख को िजसके ((((ख)))) एक से अिधक संभव अ= यावेदन हो सकते ह > को मानक, सामा(cid:13)य या कैनोिनकल (cid:15)@प म0 संपरीवAतत करने क(cid:20) (cid:15)(cid:1)Bया अिभ(cid:15)ेत ह ै िजसम0 इल:ै <ोिनक(cid:20) अिभलेख क(cid:20) (cid:15)(cid:8)त ुती म0 िभ(cid:13)न ताD का सगं त िनयम(cid:28) को लाग ू करके, मुE यत: ए: सएमएल अंक(cid:20)य ह(cid:8) ता)र सृजन और स3य ापन (cid:15)(cid:1)BयाD के एक भाग के @प म0 मानक(cid:20)करण (cid:1)कया जाएगा;;;; 3643 GI/2015 (1)2 THE GAZETTE OF INDIA : EXTRAORDINARY [PART II—SEC. 3(i)] ““““(cid:15)ित ह(cid:8) ता)र”””” से ह(cid:8) ता)र(cid:28) क(cid:20) Iृंखला म0 पूव"वतJ ह(cid:8)त ा)र पर इलै:< ािनक(cid:20) अिभलेख पर ह(cid:8)त ा)र के ((((ग)))) स3 यापन के पK चात ् च(cid:8) पा (cid:1)कए गए और Bम संEय ांक @प से पूव"वतJ ह(cid:8)त ा)र(cid:28) पर पKच ातवतJ ह(cid:8)त ा)र अिभ(cid:15)ेत ह;;;;> ““““असंबL ह(cid:8) ता)र”””” वे ह(cid:8) ता)र अिभ(cid:15)ेत ह > िजनका भडं ारण ह(cid:8)त ा)र (cid:1)कए जा रह े इलै:< ािनक(cid:20) अिभलेख से ((((घ)))) (cid:8) वतं/ (cid:1)कया गया ह;;;;ै ““““डायजे(cid:8) ट िविध एलीम0ट”””” से (cid:1)कसी ए:स एमएल अंक(cid:20)य ह(cid:8)त ा)र के संबंध म0 मलू डाटा व(cid:8)त ु के िलए उपयोग ((((ङ)))) (cid:1)कया गया डायजे(cid:8) ट ए(cid:3)गोOरPम या @पांतOरत अबजे:ट , य(cid:1)द ए:स एमएल @पांतरण, िव(cid:17)मान ह,ै कोई ह ै अिभ(cid:15)ेत ह;;;;ै ““““डायजेि(cid:8) टव एलीम0ट”””” से डायज(cid:8)े ट का म(cid:3)ू य अिभ(cid:15)ेत ह;;;;ै ((((च)))) """"सीमांत िनकाय”””” अंशदाता क(cid:20) ओर से अशं दाता या (cid:15)णाली अिभ(cid:15)ेत ह ै िजसके नाम से इलै:< ोिनक(cid:20) ह(cid:8)त ा)र ((((छ)))) (cid:15)माणप/ जारी (cid:1)कए जात े ह;;;;> """" सीमांत िनकाय ह(cid:8) ता)र"""" से (cid:1)कसी सीमांत िनकाय (cid:21)ारा अिधिनयम क(cid:20) धारा 3 या 3क के उपबंध(cid:28) के ((((ज)))) अनुसरण म0 अंक(cid:20)य ह(cid:8) ता)र, इलै:< ािनक(cid:20) िविध या (cid:15)(cid:1)Bया के माSय म से (cid:1)कसी इलै:< ोिनक(cid:20) अिभलेख का अिध(cid:15)माणन अिभ(cid:15)ेत ह;;;;ै ““““पOरवेिT टत ह(cid:8) ता)र”””” ह(cid:8) ता)र और आरंिभक इलै:< ािनक(cid:20) अिभलेख का (cid:1)कसी अ(cid:13)य इलै:< ािनक(cid:20) अिभलेख ((((झ)))) म0 पOरवेT टन अिभ(cid:15)ेत ह;;;;ै ““““ह(cid:8) ता)र का पOरवेT टन”””” से (cid:1)कसी ह(cid:8)त ा)र का पOरवेTट न अिभ(cid:15)ेत ह ै िजसको ह(cid:8)त ा)र त3व के भीतर िनVदTट ((((ञ)))) और अंतAवT ट (cid:1)कया गया;;;; ““““आरंिभक इलै: <ािनक अिभलखे ””””,,,, से (cid:1)कसी ए:स एमएल अंक(cid:20)य ह(cid:8)त ा)र (cid:15)(cid:1)Bया के संदभ" म0 ह(cid:8)त ा)Oरत ((((ट)))) सूचना का कैनोिनकेलाइW ड और @पांतOरत (cid:15)@प अिभ(cid:15)ेत ह;;;;ै ““““क(cid:20)इ(cid:13) फो त3 व”””” से कोई त3 व अिभ(cid:15)ेत ह ै जो (cid:1)कसी क(cid:20) सूचना को ह(cid:8)त ा)र त3व के साथ पकै करने म0 समथ " ((((ठ)))) बनाता ह;;ै;; """"दीघा"विध ह(cid:8)त ा)र"""" से कोई ह(cid:8)त ा)र त3व अिभ(cid:15)ेत ह ै िजसे ह(cid:8)त ा)र(cid:28) म 0 अ(cid:15)ािधकृत पOरवत"न(cid:28) का पता ((((ड)))) लगान े म0 समथ" होन े के िलए काया"(cid:13)व यनकारी उपाय(cid:28) (cid:21)ारा दीघा"विध के िलए स3य ापन के योZय बनाया गया ह;;ै;; ““““(cid:15)मुख त3 व””””,,,, से (cid:1)कसी ए: सएमएल अंक(cid:20)य ह(cid:8)त ा)र के संबंध म 0 एक संदभ " त3व (cid:28) के (cid:15)सं(cid:8)क रणकारी माडल को ((((ढ)))) पूरा करने के िलए अनु(cid:15)योग (cid:21)ारा पOरभािषत कोई ढांचा अिभ(cid:15)ेत ह ै;;;; ““““व(cid:8) तु त3 व”””” से ए: सएमएल अकं (cid:20)य ह(cid:8)त ा)र का कोई वैकि(cid:3)प क त3व अिभ(cid:15)ेत ह ै िजसका उपयोग ह(cid:8)त ा)र(cid:28) के ((((ण)))) पOरवेT टन के िलए वहां (cid:1)कया जाता ह ै जहा ं ह(cid:8)त ा)र क(cid:20) जा रही डाटा व(cid:8)त ु को ए:स एमएल म 0 शािमल (cid:1)कया जाएगा;;;; """"ओसीएसपी Oर(cid:8) प(cid:28)डम"""" से कोई ऑनलाइन सेवा अिभ(cid:15)ेत ह ै जो अंक(cid:20)य ह(cid:8)त ा)र (cid:15)माण प/ क(cid:20) (cid:15)ितसं^ण ((((त)))) (cid:15)ाि(cid:8) थित का उपबंध करती ह;;;;ै """"ऑनलाइन (cid:15)माण प/ (cid:15)ाि(cid:8) थित (cid:15)ोटोकॉल"""" से ऑनलाइन (cid:15)माण प/ (cid:15)ितस^ं ण जांच (cid:15)ोटोकॉल अिभ(cid:15)ेत ह ै ((((थ)))) जो परेषणकारी प)कार(cid:28) को (cid:1)कसी पहचाने गए अंक(cid:20)य ह(cid:8)त ा)र (cid:15)माण प/ क(cid:20) (cid:15)ितसं^ण (cid:15)ाि(cid:8)थ ित का अवधारण करन े म0 स)म बनाता ह ै;;;; ““““समांनातर ह(cid:8)त ा)र(cid:28)”””” से उसी इलै:< ािनक(cid:20) अिभलेख के ऊपर एक या अिधक (cid:8)व तं/ ह(cid:8)त ा)र अिभ(cid:15)ते ह > ((((द)))) िजसम0 ह(cid:8) ता)र(cid:28) का Bम मह3 वपूण" नहa ह;;;;ै¹Hkkx IIµ[k.M 3(i)º Hkkjr dk jkti=k % vlk/kj.k 3 (cid:1)कसी ए: सएमएल अंक(cid:20)य ह(cid:8) ता)र के संदभ " म 0 ““““संदभ" त3व ””””,,,, से कोई त3व अिभ(cid:15)ते ह ै जो डाटा पदाथb को, ((((ध)))) डाइजे(cid:8) ट से पूव " अनु(cid:15)यु: त करने के िलए @पांतरण(cid:28) क(cid:20) वैकि(cid:3)प क सूची (ए:सएमएल @पातं रण), डाइजे(cid:8)ट िविध और िनVदT ट (cid:1)कए गए डाटा पदाथb का डाइजे(cid:8)ट म(cid:3)ू य का वहन करता ह;;;;ै (cid:1)कसी ए: सएमएल अंक(cid:20)य ह(cid:8) ता)र के संबंध म0 ““““ह(cid:8)त ा)Oरत सूचना””””,,,, से कोई त3व अिभ(cid:15)ेत ह ै िजसम0 (cid:1)कसी ((((न)))) ए: सएमएल ह(cid:8)त ा)र का सृजन करने के िलए ह(cid:8)त ा)Oरत (cid:1)कए जाने के िलए सूचना का कोई सेट अतं AवTट ह,ै जहां इसम0 (cid:1)कसी डाटा पदाथ " के िलए िनदeश अंतAवTट ह ै िजसम0 कैनोिनकैलाइजेशन और ह(cid:8)त ा)र ए(cid:3)गोOरPम शािमल ह;;;;> ““““ह(cid:8) ता)र”””” से अकं (cid:20)य ह(cid:8)त ा)र या ए:स एमएल अंक(cid:20)य ह(cid:8)त ा)र अिभ(cid:15)ते ह;;;;ै ((((प)))) ““““ह(cid:8) ता)र म(cid:3)ू य”””” से कोई त3 व अिभ(cid:15)ेत ह ै जो अंक(cid:20)य ह(cid:8)त ा)र का वा(cid:8)त िवक मू(cid:3)य ह;;;;ै ((((फ)))) ““““ह(cid:8) ता)र िविध ”””” से कोई त3 व अिभ(cid:15)ेत ह ै िजसम 0 ह(cid:8)त ा)र सृजन के िलए उपयोग (cid:1)कया गया ए(cid:3)गोOरPम ((((ब)))) अंतAवT ट ह ैऔर ए(cid:3)गोOरPम ह(cid:8)त ा)र के सृजन म 0 अतं वAलत सभी कूटकारी कृ3य (cid:28) क(cid:20) पहचान करता ह;;;;ै ““““ह(cid:8) ता)र अिभल)ण”””” से कोई त3व अिभ(cid:15)ेत ह ै जो ह(cid:8)त ा)र के िवषय म0 अितOर:त सूचना जसै े समय (cid:8)ट >प या ((((भ)))) कोई अ(cid:13) य सूचना जो अनु(cid:15)योग (cid:21)ारा पOरभािषत ह,ै को पूरा करने का उपबंध करता ह;;;;ै """"समय (cid:8) टप> ”””” से केाई अंकन अिभ(cid:15)ेत ह ै जो (cid:1)कसी कार"वाई क(cid:20) सही तारीख और समय को उपदAशत करता ह ै ((((म)))) तथा उस f यि: त या युि: त क(cid:20) पहचान करता ह ै िजसम 0 समय (cid:8)ट >प को भेजा या (cid:15)ा*त (cid:1)कया ह ै और समय (cid:8)ट >प टोकन को (cid:15)वृ3 त करता ह;;;;ै """"समय (cid:8) ट>प टोकन"""" से (cid:1)कसी समय (cid:8)ट >प सेवा (cid:15)दाता के अंक(cid:20)य ह(cid:8)त ा)र का उपयोग करके सृिजत कूट @प स े ((((य)))) सुरि)त पुिT ट अिभ(cid:15)ेत ह ैऔर इसके अंतग"त वह समय भी ह ैजब पुिTट का सृजन (cid:1)कया गया था ;;;; (यक) """"समय (cid:8) ट>प सेवा (cid:15)दाता"""" से समय (cid:8)ट >प सृिजत करने के िलए कोई िवKव सनीय िनकाय अिभ(cid:15)ेत ह;;;;ै (यख) ““““ए: सएमएल”””” से ए: सट0सीबल माक"अप ल>Zव ेज अिभ(cid:15)ते ह ै जो एक औपचाOरक gसटै:स के साथ सूचना के त3 व(cid:28) क(cid:20) पहचान करन े के िलए मानक िविध उपलhध कराती ह,,ै,, डाटा अवसंरचना का वण"न करती ह ैऔर एक (cid:8) वतं/ रीित म 0डाटा का भंडारण भी करती ह,ै इसक(cid:20) िनiन िलिखत िवशेषताएं ह(cid:28)गी,———— (i) ए: सएमएल के साथ अतं व"(cid:8) त ुऔर (cid:15)(cid:8)त तु ीकरण पथृ क् ह;;;;> (ii) (cid:1)कसी िविशT ट संदभ" म0 ए: सएमएल डाटा क(cid:20) अवसंरचना का वण"न या तो ए:स एमएल (cid:8)क (cid:20)म या द(cid:8) तावेज (cid:1)क(cid:8) म क(cid:20) पOरभाषा का उपयोग करके (cid:1)कया जाता ह ै;;;; (iii) ए: सएमएल (cid:8) क(cid:20)म या द(cid:8)त ावेज (cid:1)क(cid:8)म क(cid:20) पOरभाषा का भडं ारण (cid:8)व य ं ए:स एमएल द(cid:8)त ावेज से पृथक् (cid:1)कया जाता ह ै और इसका उपयोग पुिTट के िलए (cid:1)कसी (cid:1)दए गए ए:स एमएल द(cid:8)त ावेज को िविधमा(cid:13)य बनाने के िलए (cid:1)कया जा सकता ह ै;;;; (यग) ““““ए: सएमएल अंक(cid:20)य ह(cid:8)त ा)र त3 व”””” से कोई त3व अिभ(cid:15)ेत ह ै िजसको ए:स एमएल (cid:15)@प म 0 एकप)ीय डाटा को (cid:15)य:ु त अंक(cid:20)य ह(cid:8) ता)र (cid:15)चालन के पOरणाम को कै*चर करने के िलए मानक ए:स एमएल (cid:8)क (cid:20)म को पOरभािषत करता ह,ै यह िनi निलिखत को परू ा करेगा,,,,———— (i) ए: सएमएल अंक(cid:20)य ह(cid:8) ता)र त3 व एक मानक द(cid:8)त ावेज के @प म0 िव(cid:17)मान होगा या उस डाटा व(cid:8)त ु को परावेिT टक करेगा िजसे यह ह(cid:8)त ा)Oरत करता ह ै;;;; (ii) ए: सएमएल अंक(cid:20)य ह(cid:8) ता)र त3 व क(cid:20) ह(cid:8)त ा)Oरत सूचना, ह(cid:8)त ा)Oरत म(cid:3)ू य , मुEय सूचना, त3व होगा और इसके उनके (cid:15)कट होन े वाल े Bम म0 टाइप चाइ(cid:3)ड त3व अिभल)ण ह(cid:28)ग;;े;; (यघ) ““““ए: सएमएल अंक(cid:20)य ह(cid:8)त ा)र”””” से ए: सएमएल इलै:< ािनक(cid:20) अिभलेख पर अंक(cid:20)य ह(cid:8)त ा)र अिभ(cid:15)ेत ह;;>;; (यङ) ““““ए: सएमएल द(cid:8) तावेज”””” ए: सएमएल तक" और भौितक संरचना के साथ द(cid:8)त ावेज अिभ(cid:15)ेत ह ैिजसका उपयोग डाटा त3व के वहन के िलए घोषणाD क(cid:20) संरचना, त3व (cid:28), Oट*प िणय(cid:28), िवशेषता संदभb और अनुदशे (cid:28) के (cid:15)सं(cid:8)क रण और िनकाय(cid:28) से िमलकर बनने वाली भौितक संरचना के िलए (cid:1)कया जाता ह ैजो मूल या द(cid:8)त ावेज (cid:15)िविTट से आरंभ होता ह ै;;;;4 THE GAZETTE OF INDIA : EXTRAORDINARY [PART II—SEC. 3(i)] (यच) ““““ए: सएमएल (cid:8) क(cid:20)म”””” से पूव" पOरभािषत या उपयोगकता" (cid:21)ारा पOरभािषत क(cid:20) वड " और अवसंरचना3म क रीित म 0 इकj े (cid:1)कए गए उनके अिभल)ण अिभ(cid:15)ेत ह,> जो िनiन िलिखत को परू ा करत े ह >,,,,———— (i) (cid:1)कसी िविशT ट (cid:15)योजन के िलए इ(cid:8)त मे ाल (cid:1)कए जाने चािहए ं जहां एक (cid:8)क (cid:20)म के @प म0 (cid:1)कसी ए:स एमएल द(cid:8) तावेज क(cid:20) अवसंरचना का वण"न करते ह > और त3व नाम(cid:28) क(cid:20) िविशिTट य(cid:28) का उपबंध करते ह > जो यह उपदAशत करती ह > (cid:1)क (cid:1)कसी ए: सएमएल द(cid:8)त ावेज म 0 (cid:1)कन त3व (cid:28) को और (cid:1)कन संयोजन(cid:28) म0 अनुkात (cid:1)कया जाएगा;;;; और (ii) उ(cid:13) ह 0 िव(cid:8) ताOरत (cid:1)Bयाशीलता जैसे डाटा (cid:1)क(cid:8)म , िवरासत और (cid:15)(cid:8)त तु ीकरण िनयम तथा अिभल)ण(cid:28) के िलए िडफा(cid:3) ट म(cid:3)ू य ;;;; (यछ) ““““ए: सएमएल @पांतरण”””” से कोई त3 व अिभ(cid:15)ेत ह ै (cid:1)कसी डाटा व(cid:8)त ु को उसको डाइजे(cid:8)ट करन े स े पूव" (cid:15)सं(cid:8)क रण उपाय(cid:28) क(cid:20) कोई वैकि(cid:3) पक Bमवार सूफ(cid:20) को िविनVदTट करता ह ै जहां @पांतरण म0 कैनोिनकैलाइजेशन, कूटकरण या कूटकरण को हटान े िव(cid:8) तृत (cid:8) टाइल शीट भाषा @पांतरण, ए:स पाथ (cid:1)फ(cid:3)ट रीकरण और ए:स एमएल (cid:8)क (cid:20)म िविधमा(cid:13) यकरण शािमल ह;;;;ै (यज) ““““ए: सएमएल नेम(cid:8)प से ”””” से यूनीफाम" Oरसोस" आइड0टीफायर (यआू रआई) िनदeश अिभ(cid:15)ेत ह ै जहां िविशिTट म0 वAणत तं/(cid:28) का उपयोग ए: सएमएल द(cid:8) तावेज(cid:28) म0 त3व (cid:1)क(cid:8)म और अिभल)ण नाम के @प म0 (cid:1)कया जाता ह ै और नाम(cid:28) के टकराव के िबना िविभ(cid:13) न ए: सएमएल शhद कोश(cid:28) का भी उपयोग (cid:1)कया जाता ह ै । ((((2222)))) वे शh द और पद जो इसम 0 (cid:15)यु: त ह,> पOरभािषत नहa ह > lकत ु अिधिनयम म 0 पOरभािषत ह > का Bमश: वही अथ " होगा जो उनका उ: त अिधिनयम म 0ह ै । 3333.... अअअअककंंककंं (cid:8)(cid:8)(cid:8)(cid:8)यययय हहहह$$$$तततत ाााा(cid:22)(cid:22)(cid:22)(cid:22)रररर ककककेेेे ममममाााा&&&&यय यय मममम सससस ेे ेेससससचचूूचचूू ननननाााा ककककेेेे अअअअििििधधधध(cid:1)(cid:1)(cid:1)(cid:1)ममममााााणणणणनननन कककक(cid:8)(cid:8)(cid:8)(cid:8) ररररीीीीिििितततत.—(cid:1)कसी अंक(cid:20)य ह(cid:8)त ा)र,,,,———— (क) का सृजन और स3 यापन कूटकरण (cid:21)ारा (cid:1)कया जाएगा जो (cid:1)कसी इलै:< ािनक(cid:20) अिभलखे को (cid:15)3य ) @प स े दबु mध (cid:15)@प म 0@पांतOरत करन े से संबिं धत ह;;;;ै (ख) (cid:1)कसी लोक कुंजी कूटकरण का लोप करेगा िजसम0 (cid:1)कसी दो िभ(cid:13)न lकतु गिणतीय @प से संबंिधत कुंिजय(cid:28) का उपयोग करत े (cid:29)ए (cid:1)कसी अ(cid:3)ग ोOरदम का उपयोग (cid:1)कया जाता ह ै ;;;; एक कुंजी (िजसे (cid:15)ाइवेट कुंजी कहा जाता ह)ै का उपयोग अंक(cid:20)य ह(cid:8) ता)र के सृजन के िलए और दसू री कुंजी का उपयोग (िजसे पिhल क कुंजी कहा जाता ह)ै अंक(cid:20)य ह(cid:8)त ा)र(cid:28) के स3 यापन के िलए (cid:1)कया जाता ह ै। (ग) (cid:1)कसी अंक(cid:20)य ह(cid:8)त ा)र के सृजन और स3य ापन के िलए हशै कृ3य का उपयोग जो अकं (cid:20)य ह(cid:8)त ा)र सृजन और स3 यापन फलो3 पादक अंक(cid:20)य हस त् ा)र बनान े के िलए अपेि)त ह ै। 4444.... अअअअककंंककंं (cid:8)(cid:8)(cid:8)(cid:8)यययय हहहह$$$$तत तत ाााा(cid:22)(cid:22)(cid:22)(cid:22)रररर ककककाााा ससससजजृृजजृृ नननन....————((((1111)))) हहहह$$$$तत तत ाााा(cid:22)(cid:22)(cid:22)(cid:22)ररररककककतततताााा .. .. ////ककककससससीीीी इइइइलललल(cid:17)(cid:17)(cid:17)(cid:17)ैैैै (cid:18)(cid:18) (cid:18)(cid:18) ााााििििननननकककक(cid:8)(cid:8)(cid:8)(cid:8) अअअअििििभभभभललललखखेेखखेे पपपपरररर हहहह$$$$ततत त ाााा(cid:22)(cid:22)(cid:22)(cid:22)रररर ककककररररतततत ेे ेे ससससममममयययय ययययाााा ससससचचूूचचूू ननननाााा कककक(cid:8)(cid:8)(cid:8)(cid:8) ////ककककससससीीीी अअअअ1111यय यय ममममदददद पपपपरररर हहहह$$$$तत तत ाााा(cid:22)(cid:22)(cid:22)(cid:22)रररर ककककररररतततत ेे ेे ससससममममयययय (cid:1)(cid:1)(cid:1)(cid:1)थथथथममममतततत:::: हहहह$$$$तत तत ाााा(cid:22)(cid:22)(cid:22)(cid:22)ररररककककतततताााा .. .. ककककेेेे हहहहााााडडडड.व.व.व.वययेेययेे रररर ययययाााा ससससाााा7777टटटटववववययेेययेे रररर मममम 99 99 एएएएकककक हहहहशशैैशशैै फफफफंंंं(cid:17)(cid:17)(cid:17)(cid:17)शश शश नननन ककककोोोो ललललाााागगगग ूू ूू ककककररररेेेेगगगगाााा।।।। ((((2222)))) हहहहशशैैशशैै फफफफंंंं(cid:17)(cid:17)(cid:17)(cid:17)शश शश नननन एएएएकककक हहहहशशैैशशैै पपपप(cid:30)(cid:30)(cid:30)(cid:30)ररररणणणणाााामममम (cid:1)(cid:1)(cid:1)(cid:1)$$$$तत तत ततुुततुु ककककररररेेेेगगगगाााा ।।।। (3) ह(cid:8)त ा)रकता" का हाड"वेयर या साnटवेयर तब हशै पOरणाम को ह(cid:8)त ा)कता" क(cid:20) (cid:15)ाइवेट क(cid:20) और ह(cid:8)त ा)र ए(cid:3) गोOरदम का उपयोग करते (cid:29)ए एक अंक(cid:20)य ह(cid:8) ता)र म 0 @पातं Oरत कर दगे ा । (4) तारीख और समय जैसी पOर(cid:15)ेo य जानकारी को तब अंक(cid:20)य ह(cid:8)त ा)र का भाग बनाया जाए । (5) (cid:15)ित ह(cid:8) ता)र या समानांतर ह(cid:8)त ा)र या दोन(cid:28) को भी इल:ै < ोिनक(cid:20) अिभलेख को लाग ू (cid:1)कया जा सकेगा । (6) िनi निलिखत सूचना भी ह(cid:8)त ा)र का भाग हो सकेगी,— (क) ह(cid:8) ता)रकता" के लोक क(cid:20) ह(cid:8) ता)र (cid:15)माण प/;;;; (ख) अनुk*त (cid:15)माणीकरण (cid:15)ािधकाOरय(cid:28) के लोक क(cid:20) (cid:15)माण प/ जो ह(cid:8)त ा)रकता" को जारी अंक(cid:20)य ह(cid:8)त ा)र (cid:15)माण प/ क(cid:20) अिध(cid:15)माणत: का स3 यापन करत े ह;;;;> (ग) िनयं/क के (cid:8) वयं ह(cid:8) ता)Oरत सृिजत (cid:15)माण प/ िजनका उपयोग अनुkप त् (cid:15)माणीकरण (cid:15)ािधकाOरय(cid:28) के लोक क(cid:20) (cid:15)माण प/(cid:28) क(cid:20) अिध(cid:15)माणत: का स3 यापन करन े के िलए (cid:1)कया जाता ह ै;;;;¹Hkkx IIµ[k.M 3(i)º Hkkjr dk jkti=k % vlk/kj.k 5 (घ) अनुk* त (cid:15)माणीकरण (cid:15)ािधकाOरय(cid:28) और िनयं/क (cid:21)ारा अनुरि)त (cid:15)माण प/ (cid:15)ितसं^ण सूची (सूिचयां) और िजनका उपयोग यह जांच करन े के िलए (cid:1)कया जाता ह ै (cid:1)क अकं (cid:20)य ह(cid:8)त ा)र (cid:15)माण प/ का अिधिनयम क(cid:20) धारा 38 के अधीन (cid:15)ितसं^ण कर िलया गया ह;;ै;; (ड.) ऑनलाइन (cid:15)माण प/ (cid:15)ाि(cid:8) थित (cid:15)ोटोकॉल रे(cid:8)प (cid:28)डर (cid:15)माण प/ और ऑनलाइन (cid:15)माण प/ (cid:15)ाि(cid:8)थ ित (cid:15)ोटोकॉल Oर(cid:8) प(cid:28)सेस िजनका उपयोग (cid:15)माण प/ (cid:15)ितसं^ण सचू ी के (cid:8)थ ान पर (cid:1)कया जाता ह ै। (7) दीघा"िविध मा(cid:13) य (cid:15)माण प/ सृिजत करन े के िलए,- (क) (cid:15)ारंभ म0 ह(cid:8) ता)Oरत डाटा िजसके अंतग"त (cid:15)माणप/ और (cid:15)ितसं^ण सूचना ह ै को समय (cid:8) ट>प लागू क(cid:20) जाएगी;;;; (ख) यह सुिनK चय करना क(cid:20) समय (cid:8)ट >प सभी डाटा और ह(cid:8)त ा)र (र(cid:28)) को कवर करती ह ै;;;; (ग) एक ने(cid:8) टड समय (cid:8) ट>प िवक(cid:3) प का उपयोग समय (cid:8)ट >प सेवा (cid:15)दाता (टीएसएसपी) कुंजी या ए(cid:3)ग ोOरदम अवसान जहां समय (cid:8) ट>प(cid:28) क(cid:20) नेg(cid:8) टग यह दशात" ी ह ै (cid:1)क पKच ातवतJ समय (cid:8)ट >प पूव" समय (cid:8)ट >प को लागू क(cid:20) जाएगी के पK चात् ह(cid:8)त ा)र क(cid:20) िविधमा(cid:13) यता का सुिनKच य करना (घ) ह(cid:8) ता)र और समय (cid:8) ट>प को (cid:8)व यं डाटा म0 ही रखा जाएगा या उनका पृथक् @प से एक अलग के @प म 0 भंडारण (cid:1)कया जाएगा । 5. अअअअककंंककंं (cid:8)(cid:8)(cid:8)(cid:8)यययय हहहह$$$$तततत ाााा(cid:22)(cid:22)(cid:22)(cid:22)रररर ककककाााा सससस>>>>यय यय ाााापपपपनननन....————(1) अंक(cid:20)य ह(cid:8)त ा)र के स3य ापन को अंक(cid:20)य ह(cid:8)त ा)र के सृजन के िलए हशै फं:श न के माS यम से मूल इलै: <ािनक(cid:20) अिभलेख के नए हशै पOरणाम क(cid:20) संगणना करने के माSय म से लोक कुंजी का उपयोग करके पूरा (cid:1)कया जाएगा, स3 यापनकता" िनi निलिखत क(cid:20) जांच करेगा— (क) य(cid:1)द अंक(cid:20)य ह(cid:8) ता)र(cid:28) का सृजन त3(cid:8) थ ानी (cid:15)ाइवेट का उपयोग करते (cid:29)ए (cid:1)कया गया था और व े इलै:< ािनक(cid:20) अिभलेख, य(cid:1)द िव(cid:17)मान हो के िलए समानांतर और (cid:15)ित ह(cid:8)त ा)र(cid:28) पर लाग ू ह(cid:28)ग े । (ख) वह समय जब अंक(cid:20)य ह(cid:8) ता)र का सृजन (cid:1)कया गया था । (2) (cid:15)ितह(cid:8)त ा)र का स3 यापन करन े के िलए इलै:< ािनक(cid:20) अिभलेख पर ह(cid:8)त ा)र और त3प Kच ात् पूव"वतJ ह(cid:8)त ा)र पर ह(cid:8) ता)र को BमवतJ @प से स3य ािपत (cid:1)कया जाएगा । (3) समानांतर ह(cid:8) ता)र का स3 यापन करन े के िलए इलै:< ािनक(cid:20) अिभलेख पर ह(cid:8)त ा)र को (cid:8)व तं/ @प स े स3य ािपत (cid:1)कया जाएगा । (4) दीघा"विध ह(cid:8)त ा)र का स3 यापन करने के िलए आरंिभक समय (cid:8)ट >प और सभी पKच ातवतJ समय (cid:8)ट >प िजसको (cid:15)3 येक पूव"वतJ (cid:8) ट>प पर लागू (cid:1)कया गया था का स3य ापन लाग (cid:1)कया गया था । 6666.... अअअअककंंककंं (cid:8)(cid:8)(cid:8)(cid:8)यययय हहहह$$$$तततताााा(cid:22)(cid:22)(cid:22)(cid:22)रररर (cid:1)(cid:1)(cid:1)(cid:1)ममममााााणणणणपपपप(cid:11)(cid:11)(cid:11)(cid:11) .—(1) (cid:8) वयं (cid:21)ारा ह(cid:8)त ा)Oरत (cid:15)माणप/ िजसका सृजन िनयं/क (cid:21)ारा (cid:1)कया गया था, जो लोक कुंजी अवसंरचना के िलए िवK वास दावा आरंभ करता ह,ै का उपयोग अनुk*त (cid:15)माणीकरण (cid:15)ािधकाOरय(cid:28) के लोक कुंजी (cid:15)माणप/ क(cid:20) अिध(cid:15)मािणता का स3 यापन करन े के िलए (cid:1)कया जाएगा । (2) अनुk* त (cid:15)माणीकरण (cid:15)ािधकाOरय(cid:28) के ललललोोोोकककक ककककुंुंुंुंजजजजीीीी (cid:15)माणप/ का उपयोग अंशदाताD को जारी अंक(cid:20)य ह(cid:8)ता)र (cid:15)माणप/ क(cid:20) अिध(cid:15)मािणता का स3 यापन करन े के िलए (cid:1)कया जाएगा । (3) अनुk* त (cid:15)माणीकरण (cid:15)ािधकाOरय(cid:28) (cid:21)ारा रखी गई (cid:15)माणप/ (cid:15)ितसं^ण सूची क(cid:20) जांच या पुिTट करने के िलए क(cid:20) जाएगी (cid:1)क : या अनkु * त (cid:15)माणीकरण (cid:15)ािधकाOरय(cid:28) का (cid:15)माणप/ िविधमा(cid:13)य ह ै या इसका अिधिनयम क(cid:20) धारा 38 के अधीन (cid:15)ितसं^ण कर िलया गया ह ै । (4) अंक(cid:20)य ह(cid:8)ता)र क(cid:20) िविधमा(cid:13) यता का स3य ापन करत े समय त3(cid:8) थ ानी अंक(cid:20)य ह(cid:8)ता)र (cid:15)माणप/ को जारी करन े वाले (cid:15)माणीकरण (cid:15)ािधकारी के लोक कुंजी (cid:15)माणप/ के माSय म से (cid:8)व यं (cid:21)ारा ह(cid:8)त ा)Oरत िनयं/क के (cid:15)माणप/ को IृंखलाबL करके और य(cid:1)द िवK वसनीय Iृंखला म0 कोई (cid:15)माणप/ िवKव सनीय नहa ह ै तो ह(cid:8)त ा)र का स3य ापन नहa (cid:1)कया जाएगा ।6 THE GAZETTE OF INDIA : EXTRAORDINARY [PART II—SEC. 3(i)] (5 अंक(cid:20)य ह(cid:8)ता)र (cid:15)माणप/ का स3 यापन ह(cid:8)त ा)र के सृजन के समय क(cid:20) बाबत (cid:1)कया जाएगा । (6) (cid:15)माणप/(cid:28) क(cid:20) Iृंखला का स3 यापन िनयम 7 म0 मानक(cid:28) के अनुसार (cid:1)कया जाएगा । (7) य(cid:1)द (cid:15)माणप/ क(cid:20) िविधमा(cid:13) यता एक घंटे से कम ह ैतो (cid:15)ितसंsरण सूची क(cid:20) जांच अपेि)त नहa ह ै । 7777. अअअअककंंककंं (cid:8)(cid:8)(cid:8)(cid:8)यययय हहहह$$$$तततताााा(cid:22)(cid:22)(cid:22)(cid:22)रररर ममममााााननननकककक————ससससबबबबसससस ेे ेे ममममहहहह>>>> वव वव ममममााााननननकककक जजजजोोोो अअअअककंंककंं (cid:8)(cid:8)(cid:8)(cid:8)यययय हहहह$$$$तत तत ाााा(cid:22)(cid:22)(cid:22)(cid:22)रररर ककककृृृृ>>>>यय यय @@@@ सससस ेे ेे ससससबबंंबबंं ििंंििंं धधधधतततत ििििववववििििभभभभ1111नन नन ककककााााययययकक..कक.. ललललाााापपपप@@@@ ककककोोोो ललललाााागगगग ूू ूूहहहह@@@@गगगग,,,,ेेेे ननननीीीीचचचच ेे ेे////ददददएएएए अअअअननननससुुससुु ाााारररर हहहह BB BB— उउउउ(cid:2)(cid:2)(cid:2)(cid:2)पप पप ाााादददद ममममााााननननकककक कूट कृत हशै फं(cid:12) शन एसएचए-2 जैसा एफआईपीएस 180-4 म(cid:14) िविन(cid:18)द(cid:20)ट ह ै आरएसए लोक कुंजी (cid:30)ौ ोिगक" पीकेसीएस#1 आरएसए कूटकरण मानक ([2048, 4096 िबट]); सं#क रण 1.5 कूटकरण और अंक"य ह#ता)र पीकेसीएस #7, सीएमएस अंक"य ह#ता)र (cid:30)माणप+ क" िविधमा- यता आरएफसी 5280 ईसीसी कव / एनआईएसटी पी-256, पी-384, या पी-521 दीघा/विध ह# ता)र (cid:30)1प 1. CAdES आरएफसी 5126, 2. PAdES with CAdES समय # ट2प टोकन जैसा आरएफसी 3161 म(cid:14) िविन(cid:18)द(cid:20)ट ह ै 8 एएएए(cid:17)(cid:17)(cid:17)(cid:17)ससससएएएएममममएएएएलललल अअअअककंंककंं (cid:8)(cid:8)(cid:8)(cid:8)यययय हहहह$$$$तततताााा(cid:22)(cid:22)(cid:22)(cid:22)रररर ककककेेेे ममममाााा&&&&यय यय मममम सससस ेे ेेससससचचूूचचूू ननननाााा ककककेेेे अअअअििििधधधध(cid:1)(cid:1)(cid:1)(cid:1)ममममााााणणणणनननन कककक(cid:8)(cid:8)(cid:8)(cid:8) ररररीीीीिििितततत————ए:सएमएल अंक(cid:20)य ह(cid:8)ता)र,— (क) ककककाााा बबबबीीीीजजजज ललललखखेेखखेे नननन ककककेेेे ममममाााा&&&&यय यय मममम सससस ेे ेेससससजजृृजजृृ नननन औऔऔऔरररर सससस>>>>यय यय ाााापपपपनननन ////ककककययययाााा जजजजााााएएएएगगगगाााा जजजजोोोो इइइइलललल(cid:17)(cid:17)ैै(cid:17)(cid:17)ैै (cid:18)(cid:18) (cid:18)(cid:18) ााााििििननननकककक(cid:8)(cid:8)(cid:8)(cid:8) अअअअििििभभभभललललखखेेखखेे ककककोोोो (cid:1)(cid:1)(cid:1)(cid:1)तततत यय यय ् ् ् ् (cid:22)(cid:22)(cid:22)(cid:22)तततत:::: अअअअबबबबोोोो&&&&यय यय (cid:1)(cid:1)(cid:1)(cid:1)DDDDपपपप मममम 99 99DDDDपपपपााााततंंततंं (cid:30)(cid:30)(cid:30)(cid:30)ररररतततत ककककररररनननन ेे ेेसससस ेे ेेससससबबंंबबंं ििंंििंं धधधधतततत हहहह ैै ैै; (ख) लोक कुंजी बीज लेखन का उपयोग जो दो िभ(cid:13)न lकत ु गणीतीय @प स े संबL कुंिजय(cid:28), एक कुंजी (िजस े (cid:15)ाइवेट कुंजी कहा जाता ह)ै का उपयोग ए:सएमएल अंक(cid:20)य ह(cid:8)ता)र और दसू री कुंजी (िजस े लोक कुंजी कहा जाता ह)ै का उपयोग ए:सएमएल अंक(cid:20)य ह(cid:8)ता)र का स3य ापन करन े के िलए एक ए(cid:3)ग ोOरदम का इ(cid:8) तमे ाल करता ह;ै (ग) बीज लेखन हशै फं: शन का (cid:1)कसी ए:सएमएल अंक(cid:20)य ह(cid:8)ता)र के सृजन और स3य ापन के िलए उपयोग; (घ) कैनोिनकैनाइजेशन और ए:सएमएल @पांतरण का उपयोग मानक इलै:< ािनक(cid:20) अिभलेख का ए:सएमएल अंक(cid:20)य ह(cid:8)ता)र का सृजन और स3य ापन से पूव" सजृ न के िलए उपयोग; (ङ) ऐसे ए:सएमएल द(cid:8) तावेज(cid:28) का अिध(cid:15)माणन िजनम 0 डाटा एक िनदeश और त3(cid:8) थ ानी हशै के @प म 0 अंतAवT ट ह ै जो हशै ए(cid:3)ग ोOरदम, कैनोिनकैनाइजेशन, ए:स एमएल @पांतरण और लोक कुंजी ए(cid:3)ग ोOरदम के उपयोग स े (cid:15)भािवत होता ह ै 9999.... एएएए(cid:17)(cid:17)(cid:17)(cid:17)ससससएएएएममममएएएएलललल अअअअककंंककंं (cid:8)(cid:8)(cid:8)(cid:8)यययय हहहह$$$$तततताााा(cid:22)(cid:22)(cid:22)(cid:22)रररर ककककाााा ससससजजृृजजृृ नननन .—(1) (cid:1)कसी इल:ै < ािनक(cid:20) अिभलेख या सूचना क(cid:20) (cid:1)कसी अ(cid:13)य मद पर ह(cid:8)त ा)र करते समय ह(cid:8) ता)रकता" पहले संदभ" त3 व(cid:28), ए:सएमएल अंक(cid:20)य ह(cid:8)ता)र त3व , ह(cid:8)त ा)Oरत सूचना, कुंजी सूचना और ह(cid:8) ता)र मू(cid:3) य का संिनमा"ण करेगा । (2) ससससददंंददंं भभभभ .. ..तततत>>>>वव वव ककककेेेे ससससजजृृजजृृ नननन ककककेेेे ििििललललएएएए,,,, हहहह$$$$तत तत ाााा(cid:22)(cid:22)(cid:22)(cid:22)ााााककककााााररररीीीी ससससाााा7777टटटटववववययेेययेे रररर ििििननननEEEEननन न ििििललललििििखखखखतततत ककककृृृृ>>>>यय यय @@@@ ककककोोोो ककककररररेेेेगगगगाााा—¹Hkkx IIµ[k.M 3(i)º Hkkjr dk jkti=k % vlk/kj.k 7 (क) सूचना क(cid:20) मद, ए:सएमएल @पांतरण त3व (वैकि(cid:3)प क), डाइजे(cid:8)ट ए(cid:3)ग ोOरदम और डाइजे(cid:8)ट मू(cid:3)य के संदभ" म0 संदभ" त3 व(cid:28) का सृजन करेगा ; (ख) वैकि(cid:3) पक @प स े ए:सएमएल @पांतरण(cid:28) को (cid:15)3य ेक िनVदTट व(cid:8)त ु म0 Bमवार @प से लाग ू करेगा; (ग) ह(cid:8) ता)रकता" के हाड"वेयर या साnटवेयर म0 हशै फं:श न को (cid:15)3य ेक िनVदTट त3व को लागू करेगा, हशै पOरणाम को िनVदT ट त3व म0 भडं ाOरत करेगा; (घ) यह सुिनिK चत करेगा (cid:1)क य(cid:1)द लि)त त3व का सृजन (cid:1)कया जाता ह ै तो उसम0 (cid:15)मुख त3व नहa होगा ; (ङ) यह सुिनिK चत करेगा (cid:1)क िविशTट कैनोिनकलाइजेशन "िबना Oट*प ािणय(cid:28) के" को अिनवाय"त: (cid:1)कसी अ(cid:13) य @पांतरण के िविनVदTट (cid:1)कया गया ह ै । (3) एएएए(cid:17)(cid:17)(cid:17)(cid:17)ससससएएएएममममएएएएलललल अअअअककंंककंं (cid:8)(cid:8)(cid:8)(cid:8)यययय हहहह$$$$तततताााा(cid:22)(cid:22)(cid:22)(cid:22)रररर सृजन के (cid:15)योजन के िलए, ह(cid:8)त ा)रकता" साnटवेयर िनiन िलिखत कृ3य करेगा— (क) ह(cid:8) ता)र िविध, कैनोिनकेलाजशे न िविध और िनदeश(cid:28) के साथ ह(cid:8)त ा)र सूचना का सृजन करेगा ; (ख) ह(cid:8) ता)र सूचना को कैनोिनकेलाजेशन लाग ू करेगा और कैनोिनकेलाइजड सूचना के हसै मू(cid:3)य का हgै सग ए(cid:3)ग ोOरदम का उपयोग करते (cid:29)ए ह(cid:8)त ा)र िविध स े संगणना करेगा ; (ग) सुिनिK चत करेगा (cid:1)क,— (i) ह(cid:8) ता)रकता " के पास ह(cid:8)त ा)र करने स े पूव" द(cid:8)त ावेज क(cid:20) सभी अंतव"(cid:8)त ुह ै; (ii) (cid:8) वचािलत ह(cid:8) ता)र करन ेक(cid:20) (cid:15)(cid:1)Bया क(cid:20) दशा म0 अंतव"(cid:8)त ु (cid:15)दश"न अपे)ाD क(cid:20) अपे)ा नहa ह ै; (iii) एक साथ ब(cid:29)संसाधन(cid:28) पर ह(cid:8) ता)र करने के िलए,— (क) (cid:15)3 येक संसाधन को स(cid:1)Bन पर डाला जाएगा ; (ख) (cid:15)3 येक ए:सएमएल संदभ" संसाधन को ए:स एलटी का उपयोग करते (cid:29)ए डाला जाएगा और ए: सएलटी संसाधन को स(cid:1)Bन पर डालन े के िलए (cid:1)कया गया अंितम @पांतरण होगा ; (ग) (cid:15)3 येक गरै ए: सएमएल संसाधन को माइम (cid:1)क(cid:8)म अिभल)ण, जो आबजे:ट म 0 वAणत ह,ै का उपयोग करते (cid:29)ए डाला जाएगा ; (घ) ह(cid:8) ता)र ए(cid:3)गोOरवदम हसै , ह(cid:8) ता)कता" क(cid:20) (cid:15)ाइवेट कुंजी और पिhल क कुंजी पैरामीटर (य(cid:1)द लागू ह(cid:28)) का उपयोग करते (cid:29)ए, ह(cid:8) ता)र का सृजन (cid:1)कया जाएगा और काय"करण आधाOरत ह(cid:8)त ा)र पOरणाम का 64 मलू कूटकरण पOरणाम और उसका उपयोग ह(cid:8) ता)र म(cid:3)ू य के (cid:15)@पण के िलए (cid:1)कया जाएगा ; (ङ) ह(cid:8)त ा)र त3 व(cid:28) का संिनमा"ण, िजसके अतं गत" ह(cid:8)त ा)Oरत सूचना, सूचना क(cid:20) मvे ए:स 509 (cid:15)माणप/ त3व के साथ कुंजी सूचना और ह(cid:8)त ा)र म(cid:3)ू य तथा ए: स 509 (cid:15)माणप/ त3व ह(cid:8)त ा)रकता" क(cid:20) ए:स 509 लोक कुंजी (cid:15)माणप/ को कैरी कर0गे । ((((4444) संदAभक सूचना, जैसे तारीख और समय को तब ए:सएमएल अंक(cid:20)य ह(cid:8)ता)र का भाग बनाया जाएगा । (5) (cid:15)ित ह(cid:8) ता)र या समानांतर ह(cid:8)त ा)र या दोन(cid:28) को भी इल:ै < ािनक अिभलेख म 0 लागू (cid:1)कया जा सकेगा ।।।। (6) िनi निलिखत सूचना भी ह(cid:8)त ा)र का भाग हो सकेगी— (क) ह(cid:8) ता)Oरत (cid:15)माणीकरण (cid:15)ािधकाOरय(cid:28) के लोक कुंजी (cid:15)माणप/, जो ह(cid:8)त ा)कता" को जारी अकं (cid:20)य ह(cid:8)त ा)र (cid:15)माणप/ क(cid:20) अनु(cid:15)मािणता का स3य ापन करत े ह >; (ख) िनयं/क (cid:21)ारा सृिजत (cid:8) वय: (cid:21)ारा ह(cid:8)त ा)Oरत (cid:15)माणप/, जो अनुk*त (cid:15)माणीकरण (cid:15)ािधकाOरय(cid:28) क(cid:20) लोक कुंजी (cid:15)माणप/(cid:28) क(cid:20) अनु(cid:15)मािणकता का स3य ापन करन े के िलए उपयोग (cid:1)कए जाते ह >; (ग) अनkु * त (cid:15)माणीकरण (cid:15)ािधकाOरय(cid:28) और िनयं/क (cid:21)ारा रखी गई (cid:15)माणप/ (cid:15)ितसंहरण सूची, िजसका उपयोग यह जांच करने के िलए (cid:1)कया जाता ह ै (cid:1)क :य ा अंक(cid:20)य ह(cid:8)त ा)र (cid:15)माणप/ का अिधिनयम क(cid:20) धारा 38 के अधीन (cid:15)ितसंहरण कर िलया गया ह ै;8 THE GAZETTE OF INDIA : EXTRAORDINARY [PART II—SEC. 3(i)] (घ) ऑनलाइन (cid:15)माणप/ (cid:15)ाि(cid:8)थ ित (cid:15)ोटोकाल Oर(cid:8)प (cid:28)डर (cid:15)माणप/ और ऑनलाइन (cid:15)माणप/ (cid:15)ाि(cid:8)थ ित अनु(cid:1)BयाD का उपयोग (cid:15)माणप/ (cid:15)ितसंहरण सूची के (cid:8)थ ान पर (cid:1)कया जा सकेगा । (7) दीघा"विध िविधमा(cid:13) य ए:सएमएल अंक(cid:20)य ह(cid:8)ता)र का सजृ न करन े के िलए िनiन िलिखत कृ3य (cid:1)कए जाएंग—े (क) (cid:15)ारंभ म0 ह(cid:8)त ा)Oरत द(cid:8) तावजे पर एक समय (cid:8)ट ॉप लगाई जाएगी, जहां आरंिभक समय (cid:8)ट ॉप सभी इलै: <ािनक अिभलेख और ह(cid:8) ता)र(cid:28) को कवर करेगी ; (ख) एक न(cid:8)े टेड समय (cid:8) टॉप िवक(cid:3)प का उपयोग समय (cid:8)ट ाgiप ग सेवा (cid:15)दा3त ा (टीएसएसपी) के कुंजी या ए(cid:3) गोOरदम के अवसान के पK च ह(cid:8)त ा)र क(cid:20) िविधमा(cid:13)य ता का सुिनKच य करन े के िलए (cid:1)कया जाएगा, जहां समय (cid:8) टॉप(cid:28) क(cid:20) नेg(cid:8) टग का यह अथ" ह ै(cid:1)क पKच ातवतJ समय (cid:8)ट ॉप पूव" समय (cid:8)ट ॅाप को लाग ू क(cid:20) जाएगी ; (ग) ह(cid:8) ता)र और समय (cid:8) टॉप(cid:28) को डाटा म0 ही रखा जा सकेगा या पृथक् @प म 0एकल के @प म0 भडं ाOरत (cid:1)कया जाएगा । 11110000.... एएएए(cid:17)(cid:17)(cid:17)(cid:17)ससससएएएएममममएएएएलललल अअअअककंंककंं (cid:8)(cid:8)(cid:8)(cid:8)यययय हहहह$$$$तततताााा(cid:22)(cid:22)(cid:22)(cid:22)रररर ककककाााा सससस>>>>यय यय ाााापपपपनननन.—(1) ए:सएमएल अंक(cid:20)य ह(cid:8)ता)र के स3य ापन को ह(cid:8)त ा)र के िविधमा(cid:13) यकरण, संदभ " िविधमा(cid:13) यकरण और (cid:15)माणप/ िविधमा(cid:13)य करण के (cid:21)ारा परू ा (cid:1)कया जाएगा और ए:सएमएल अंक(cid:20)य ह(cid:8)ता)र को केवल तभी िविधमा(cid:13) य माना जाएगा य(cid:1)द ह(cid:8)त ा)र िविधमा(cid:13)य करण, संदभ " िविधमा(cid:13)य करण और (cid:15)माणप/ िविधमा(cid:13) यकरण जैसा नीचे िविनVदT ट (cid:1)कया गया ह,ै का अनुपालन (cid:1)कया गया हो । (2) ह(cid:8) ता)र िविधमा(cid:13) यकरण को िनi निलिखत के माSय म से पूरा (cid:1)कया जाएगा— (क) संदभ" िविधमा(cid:13) यकरण के दौरान तैयार क(cid:20) गई ह(cid:8)त ा)र सूचना का कैनोिनकल (cid:15)@प का उपयोग (cid:1)कया जाएगा ; (ख) कैनोिनकलाइजेशन िविध का उपयोग करत े (cid:29)ए ह(cid:8)त ा)र पLित के कैनोिनकल (cid:15)@प को अिभ(cid:15)ा*त (cid:1)कया जाएगा ; (ग) ह(cid:8) ता)रकता" के ए: स 509 (cid:15)माणप/ म0 अंतAवTट लोक कुंजी, िजसे ए:स एमएल अंक(cid:20)य ह(cid:8)त ा)र म 0 सिi मिलत (cid:1)कया गया ह,ै ह(cid:8) ता)र सूचना, ह(cid:8)त ा)र म(cid:3)ू य का कैनोिनकलाइजेड (cid:15)@प और ह(cid:8)त ा)र पLित के कैनोिनकलाइजेड (cid:15)@प का ह(cid:8)त ा)र का स3य ापन करन े के िलए उपयोग (cid:1)कया जाएगा ; (3) संदभ" िविधमा(cid:13) यकरण को (cid:15)ा* त करन े के िलए िनiन िलिखत का उपयोग (cid:1)कया जाएगा— (कककक) ह(cid:8) ता)र सूचना म 0 कैनोिनकलाइजेशन िविध के आधार पर ह(cid:8)त ा)र सूचना त3व के कैनोिनकलाइज का उपयोग (cid:1)कया जाएगा ; (खखखख) ह(cid:8) ता)र सूचना म 0 (cid:15)3 येक संदभ" के िलए-- य(cid:1)द ह(cid:8) ता)रकता" (cid:21)ारा @पांतरण(cid:28) को लागू (cid:1)कया जाता ह,ै तब स3य ापनकता" साnटवेयर यूिनफोम" (i) Oरसोस आइडे(cid:13) टीफायर (यआू रआई) को डीरेफर0स कर देगा और रेफर0स त3व म0 ह(cid:8)त ा)रकता" (cid:21)ारा उपबंिधत @पांतरण(cid:28) को िनTप ा(cid:1)दत करेगा ; रेफर0स त3 व म 0 िविनVदTट डाइजे(cid:8)ट पLित का उपयोग करत े (cid:29)ए रेफर0(cid:8)ड मद के डाइज(cid:8)े ट क(cid:20) संगणना (ii) करेगा ; ह(cid:8) ता)Oरत सूचना रेफर0स म 0 डाइजे(cid:8)ट मू(cid:3)य के िव|L संगिणत डाइजे(cid:8)ट मू(cid:3)य क(cid:20) तलु ना करेगा । (iii) (4) ए:सएमएल अंक(cid:20)य ह(cid:8)ता)र म0 सिi मिलत अंक(cid:20)य ह(cid:8)ता)र (cid:15)माणप/ का िनयम 6 म 0 िविनVदTट उपबधं (cid:28) के अनुसार स3 यापन (cid:1)कया जाएगा । (5) (cid:15)ित ह(cid:8) ता)र का स3 यापन करने के िलए इलै:< ािनक अिभलेख पर पहले ह(cid:8)त ा)र और पूव"वतJ ह(cid:8)त ा)र पर ह(cid:8) ता)र(cid:28) का Bम संE यंक @प से स3 यापन (cid:1)कया जाएगा । (6) समानातर ह(cid:8)त ा)र(cid:28) का स3 यापन करन े के िलए इलै:< ािनक अिभलेख पर ह(cid:8)त ा)र का (cid:8)व त/ं @प स े स3य ापन (cid:1)कया जाएगा । (7) दीघा"विध ह(cid:8) ता)र का स3 यापन करन े के िलए आरंिभक समय (cid:8)ट ॉप और (cid:15)3य ेक पूव"वतJ समय (cid:8)ट ॉप पर सभी पK चातवतJ लाग ू समय (cid:8) टॉप का स3 यापन (cid:1)कया जाएगा ।¹Hkkx IIµ[k.M 3(i)º Hkkjr dk jkti=k % vlk/kj.k 9 11111111.... एएएए(cid:17)(cid:17)(cid:17)(cid:17)ससससएएएएममममएएएएलललल अअअअककंंककंं (cid:8)(cid:8)(cid:8)(cid:8)यययय हहहह$$$$तततताााा(cid:22)(cid:22)(cid:22)(cid:22)रररर ममममााााननननकककक....—सबसे मह3व पूण" मानक, िज(cid:13)ह 0 ए:स एमएल अंक(cid:20)य ह(cid:8)त ा)र कृ3य (cid:28) के साथ सहबL िविभ(cid:13) न काय"कलाप(cid:28) के िलए लागू (cid:1)कया जाएगा, नीच े (cid:1)दए अनुसार ह—ै उ4 पाद मानक आरएफसी 3275 िन5न िलिखत क-स 7(cid:14)8स के साथ o :कसी ओबजे(cid:12)ट के अंदर मेनी:फ#ट अनु=ात नह> ह,ै o ए(cid:12)स 509 (cid:30)माणप+ को अंत?व(cid:20)ट करते @ए कुंजी सूचना आ=ापक ह ै o रेफर(cid:14)स (cid:30):Bया अन-य कैनोिनकलाइजेशन का (िबना CटDप िणयE के) अ-य 1पांतरणE के अितCर(cid:12)त उपयोग करेगी ए(cid:12)सएमएल अंक"य ह#ता)र मानक o ए(cid:12)सएमएल Fोत के िलए ए(cid:12)स एसएलटी #B "न पर द#त ावेज को रखने म(cid:14) समथ / बनाने के िलए :कया गया अंितम 1पांतर होगा o #B "न पर द#त ावेज को रखने के िलए o (cid:30)4य ेक संद?भत ए(cid:12)सएमएल संसाधन का ए(cid:12)स एसएलटी का उपयोग करते @ए काया/-व यन :कया जाएगा o (cid:30)4य ेक गैर ए(cid:12)सएमएल संसाधन का माइम :क#म के ओबजे(cid:12)ट म(cid:14) व?णत अिभल)णE का उपयोग करते @ए काया/-व यन :कया जाएगा ए(cid:12)सएमएल नाम # थान आरएफसी 3986 ह# ता)र कूटकरण यूटीएफ-8 आरएफसी 3629 ह# ता)र मूJ य कूटकरण बेस64 आरएफसी 4648 सदभं / ऐलीम(cid:14)ट डाइजे# ट एसएचए256 एफआईपीएस 180-4 ह# ता)र एJ गोCरदम आरएसए पीकेसीएस-1 सं# करण 1.5 के साथ एसएचए 256 o अन-य (िबना CटDप िणयE के), ए(cid:12)सएमएल-ईए(cid:12)स सी-सी14एन, आरएफसी 3741 o कैनोिनकल ए(cid:12)सएमएल 1. कैनोिनकल ए(cid:12)सएमएल 1.0 (CटDप िणयE का लोप करता ह)ै ह# ता)र खंड कैनोिनकलाइजेशन http://www.w3.org/TR/2001/REC-xml-c14n-20010315 2. कैनोिनकल ए(cid:12)सएमएल 1.1 (CटDप िणयE का लोप करता ह)ै http://www.w3.org/2006/12/xml-c14n11 अन-य (िबना CटDप िणयE के), ए(cid:12)सएमएल-ईए(cid:12)स सी-सी14एन, आरएफसी 3741 कैनोिनकल ए(cid:12)सएमएल 1पांतर एJ गोCरदम 1. कैनोिनकल ए(cid:12)सएमएल 1.0 (CटDप िणयE का लोप करता ह)ै http://www.w3.org/TR/2001/REC- xml -c14n-20010315 2. कैनोिनकल ए(cid:12)सएमएल 1.1 (CटDप िणयE का लोप करता ह)ै10 THE GAZETTE OF INDIA : EXTRAORDINARY [PART II—SEC. 3(i)] http://www.w3.org/2006/12/ xml-c14n11 ए(cid:12) सएसएलटी-ए(cid:12)स एसएल 1पांतर (ए(cid:12)स एसएलटी) सं#क रण 1.0. डOJ य 3ू सी http://www.w3.org/TR/1999/REC-xslt-19991116 XPath – RFC 3653 ह# ता)र :क# म परावेि(cid:20)ट त या परावेि(cid:20)ट त :कया जा रहा या असंलPन अंक"य ह#ता)र (cid:30)माणप+ (डीइआर) ए(cid:12)स .509 वी3 अंत/काय/कारी माग/दश/क िसQांतE के अनुसार जारी लोक कुंजी एJ गोCरदम आरएसए पीकेसीएस-1 सं# करण 1.5 इसीसी कव / एनआईएसटी पी-256, पी-384, या पी-521 दीघा/विध ह# ता)र (cid:30)ा1प 1. ए(cid:12)सएमएलइआरएस आरएफसी 6283 और XAdES 2. ए(cid:12)सएमएलइआरएस आरएफसी 6283 और PAdES XAdES के साथ समय # टॉप टोकन जैसा :क ए(cid:12)सएमएल नोटेशन म(cid:14) िविन(cid:18)द(cid:20)ट आरएफसी 3161 11112222.... ए:सएमएल अंक(cid:20)य ह(cid:8)ता)र का मलू िस(cid:13) टे:स और िनयम म0 इ(cid:8)त ेमाल (cid:1)कए गए पद िनiन ानुसार ह(cid:28)गे, अथा"त ् :— <Signature ID?> <Signed Info> <canonicalization Method/> <Signature Method/> (<Reference URI?> (<Transforms>)? <Digest Method> <Digest Value> </Reference>+ </Signed Info> <Signature Value> (<KeyInfo> (Key Name) (Key Value) (Retrieval Method) (<X509 Data> (X509 SKI)¹Hkkx IIµ[k.M 3(i)º Hkkjr dk jkti=k % vlk/kj.k 11 (X509 Subject Name) (X509 Certificate) (X509 CRL) (X509 Digest) </x509 Data>) </Keyinfo>) (<Object ID?>)* </Signature> जहां "?" शू(cid:13) य या एक बार उपदAशत होन े को दशा"ता ह ै; "+" एक या अिधक बार उपदAशत होने को दशा"ता ह ै; और "*" शू(cid:13) य या अिधक बार उपदAशत होने को दशा"ता ह ै। 11113333.... अअअअककंंककंं (cid:8)(cid:8)(cid:8)(cid:8)यययय हहहह$$$$तततताााा(cid:22)(cid:22)(cid:22)(cid:22)रररर ककककृृृृ>>>>यय यय ममममााााननननकककक.— ह(cid:8) ता)र (cid:15)ोफाइल और ह(cid:8)त ा)र (cid:15)@प क(cid:20) बाबत अंक(cid:20)य ह(cid:8)ता)र सृजन और स3य ापन क(cid:20) रीित िनयं/क (cid:21)ारा जारी िनi निलिखत माग"दश"क िसLांत(cid:28) के भी अनु@प होगी, अथा"त ्:- (i) अंक(cid:20)य ह(cid:8)ता)र (cid:15)माणप/ के िलए सूचना (cid:15)ौ(cid:17)ोिगक(cid:20) अिधिनयम के अधीन जारी अंत"काय"कारी माग"दश"क िसLांत ; (ii) भारत पीकेआई के िलए ए: स.509 (cid:15)माणप/ नीित ; (iii) ह(cid:8) ता)र (cid:15)ोफाइल ; (iv) (cid:15)माणीकरण (cid:15)ािधकाOरय(cid:28) (सीए) के िलए ऑनलाइन (cid:15)माणप/ (cid:15)ाि(cid:8)थ ित (cid:15)ोटोकाल (ओसीएसपी) सेवा माग"दश"क िसLांत ; (v) (cid:15)माणप/ (cid:15)ािधकाOरय(cid:28) (सीए) के िलए समय (cid:8)ट ॉप सेवा मागद" श"क िसLांत । [फा. सं. 19/26/2015-सीसीए] तपन राय, अपर सिचव MINISTRY OF COMMUNICATIONS AND INFORMATION TECHNOLOGY (Department of Electronics and Information Technology) NOTIFICATION New Delhi, the 25th August, 2015 G.S.R. 660(E).―In exercise of the powers conferred by section 87 of the Information Technology Act, 2000 (21 of 2000), the Central Government hereby makes the following rules, namely:— 1. Short title and commencement.― (1) These rules may be called the Digital Signature (End entity) Rules, 2015. (2) They shall come into force on the date of their publication in the Official Gazette. Definitions-―(1)In these rules, unless the context otherwise requires,— (a) "Act" means the Information Technology Act, 2000(21 of 2000); (b) “canonicalisation”, in relation to a xml digital signature, means the process of converting electronic record that has more than one possible representation into a ‘standard’, ‘normal’, or ‘canonical form’ in which the variations12 THE GAZETTE OF INDIA : EXTRAORDINARY [PART II—SEC. 3(i)] in representation of electronic record shall be standardised by applying consistent rules, primarily as part of the xml digital signature creation and verification processes; (c) “counter signature” means a signature on a previous signature in a series of signatures, affixed after the verification the signature on electronic record and subsequent signatures on previous signatures serially; (d) “detached signature” means the signature that is stored independent of electronic record being signed; (e) “digestmethod element”, in relation to a xml digital signature, means the digest algorithm to be used for the original data object or transformed, if any ‘xml transforms’ exists; (f) “digestvalue element” means the value of the digest; (g) "end entity” means the subscriber or system on behalf of the subscriber in whose name the Electronic Signature Certificate is issued; (h) "end entity signature" means authentication of any electronic record by an end entity by means of a digital signature, electronic method or procedure in accordance with the provisions of sections 3 or 3A of the Act; (i) “enveloped signature” means enveloping of the signature and the initial electronic record into another electronic record; (j) “enveloping signature” means a signature over a electronic record that is referenced and contained within the signature element; (k) “initial electronic record”, in the context of xml digital signature process, means canonicalised and transformed form of signedInfo; (l) “keyinfo element” means an element that enables key information to be packaged along with the signature element; (m) "long term signature" means a signature element that is made verifiable for a long term by implementing measures to enable the detection of unauthorised alterations of signature; (n) “manifest element”, in relation to a xml digital signature, means a structure to carry a list of reference elements processing model defined by the application; (o) “object element” means an optional element of xml digital signature, which is used for enveloping signature where the data object being signed is included in the xml; (p) "ocsp responder" means an online service that provides revocation status of a digital signature certificate; (q) "online certificate status protocol" means an online certificate-revocation checking protocol that enables relying- parties to determine the revocation status of an identified digital signature certificate; (r) “parallel signatures” means one or more independent signature over the same electronic record in which the ordering of the signatures is not important; (s) “reference element”, in relation to a xml digital signature, means an element that carries a references to data objects, an optional list of transforms to be applied prior to digest (xml transforms), digestmethod and digestvalue value of referenced data objects; (t) “signedinfo”, in relation to a xml digital signature, means an element that contains a set of information to be signed for creating an xml signature, where it shall contains references to the data object that includes the canonicalisation and signature algorithms; (u) “signature” means digital signature or xml digital signature; (v) “signaturevalue” means an element that the actual value of the digital signature; (w) “signaturemethod ” means an element that contains the algorithm used for signature generation and this algorithm identifies all cryptographic functions involved in the signature generation;¹Hkkx IIµ[k.M 3(i)º Hkkjr dk jkti=k % vlk/kj.k 13 (x) “signatureproperties” means an element that provides a way to carry additional information about the signature, such as a time stamp or any other information which are defined by application; (y) "time stamp” means a notation that indicates the correct date and time of an action and identity of the person or device that sent or received the time stamp and is enforced using time stamp token; (z) "time stamp token " means a cryptographically secure confirmation generated by applying digital signature of a time stamping service provider that includes the time when the confirmation was generated; (za) "time stamping service provider " means a trusted entity authorised to generate time stamps; (zb) “xml” means Extensible Markup Language that provides a standard methodology with formal syntax to identify elements of information, describe the structure of data and also to store data in an independent manner, shall have the following properties,— (i) with xml, content and presentation are separate; (ii) the structure of xml data in a particular context is described using either xml schema or a document type definition; (iii) xml schema or a document type definition are stored separately from the xml document itself and can be used to validate a given xml document for conformance; (zc) “xml digital signature element” means an element that defined by standard xml schema for capturing the result of a digital signature operation applied to arbitrary data in xml format, shall satisfy the following,— (i) xml digital signature element shall exist as a standalone document or envelop the data object that it signs; (ii) xml digital signature element shall have signedinfo, signaturevalue, keyinfo, object and has id attribute of type child elements in order in which they appear; (zd) “xml digital signature” means the digital signature on xml electronic record; (ze) “xml document” means a document with xml logical and physical structure that is used to carry data elements, composed of declarations, elements, comments, character references, and processing instructions and a physical structure composed of entities, starting with the root, or document entity; (zf) “xml schema” means a set of pre-defined or user defined keywords and their attributes arranged in a structured manner, shall satisfy the following,— (i) should be used for a particular purpose where as a schema describes the structure of an xml document and provides specification of element names that indicates which elements are allowed in an xml document, and in what combinations; and (ii) should provide extended functionality such as data types, inheritance, and presentation rules and default values for attributes; (zg) “xml transform” means an element that specify an optional ordered list of processing steps applied to the data objects before it was digested where the transforms include canonicalization, encoding or decoding, extensible style sheet language transformations, xpath filtering, and xml schema validation; (zh) “xml namespace” means a uniform resource identifier (uri) reference where the mechanisms described in the specification are used in xml documents as element types and attribute names and also to use various xml vocabularies without having name collision. (2) Words and expressions used herein and not defined but defined in the Act shall have the meanings respectively assigned to them in the said Act. 3. Manner of authentication of information by means of digital signature.—A digital signature shall,— (a) be created and verified by cryptography which concerns with transforming electronic record into seemingly unintelligible forms; (b) use Public Key Cryptography, which employs an algorithm using two different but mathematical related keys; one key (called the private key) for creating a digital signature and another key (called the public key) for verifying a digital signature; (c) use an hash function for creating and verifying a digital signature which required to make digital signature generation and verification efficient. 4. Creation of digital signature.—(1) The signatory shall, while signing an electronic record or any other item of information, first apply an hash function in the signatory's hardware or software.14 THE GAZETTE OF INDIA : EXTRAORDINARY [PART II—SEC. 3(i)] (2) The hash function shall produce a hash result. (3) The signatory's hardware or software shall then transform the hash result into a digital signature using signatory's private key and signature algorithm. (4) The contextual information like date and time, shall be then made part of the digital signature. (5) The counter signatures or parallel signatures or both may also be applied to electronic record. (6) The following information may also be a part of signature,— (a) the signatory’s public key signature certificate(s); (b) the public key certificate(s) of the licensed Certifying Authorities which used to verify the authenticity of the digital signature certificate issued to the signatory; (c) the self signed certificate generated by the Controller used to verify the authenticity of the public key certificate of the licensed Certifying Authorities; (d) the certificate revocation list(s) maintained by the licensed Certifying Authorities, and the controller which is used to check whether the digital signature certificate has been revoked under section 38 the Act; (e) online certificate status protocol responder certificates and online certificate status protocol responses that may be used in lieu of certificate revocation list. (7) To create long term valid digital signature,— (a) a timestamp shall be applied initially to the signed data including the certificates and revocation information; (b) ensure that initial time stamp shall cover all the data and signature(s); (c) a nested time stamp option shall be used to ensure signature validity past the time stamping service provider's (tssp) key or algorithm expiry where the nesting of time stamps implies that a subsequent time stamp shall be applied to the prior time stamp; (d) signature(s) and time stamps may be embedded in the data itself or stored separately as standalone. 5. Verification of digital signature.—(1)The verification of a digital signature shall be accomplished by computing a new hash result of the original electronic record by means of the hash function used to create a digital signature and by using the public key and the new hash result, the verifier shall check— (a) if the digital signature was created using the corresponding private key and shall be applicable for parallel and counter signatures applied on the electronic record, if present; (b) the time when the digital signature was created. (2) To verify counter signature, the signature on electronic record and thereafter signature on previous signature serially shall be verified. (3) To verify parallel signature, signature on electronic record shall be verified independently. (4) To verify long term signature, the initial timestamp and all subsequent time stamp applied on the each prior timestamp shall be verified. 6. Verification of Digital Signature Certificate.—(1) The self signed certificate generated by the Controller, which begins the trust chain for the public key infrastructure, shall be used to verify the authenticity of the public key certificate of the licensed Certifying Authorities. (2) The public key certificate of the licensed Certifying Authorities shall be used to verify the authenticity of the digital signature certificate issued to the subscribers. (3) The certificate revocation list maintained by the licensed Certifying Authorities shall be checked to confirm whether the certificate of the licensed Certifying Authorities is valid or whether it has been revoked under section 38 the Act. (4) While verifying the validity of a digital signature the corresponding digital signature certificate shall chain up through the public key certificate of the issuing Certifying Authority to the self signed certificate of the Controller and if any of the certificates in the trust chain is not trusted the signature shall not be verified. (5) The Digital Signature Certificate shall be verified with respect to time of signature created. (6) The chain of certificates shall be verified in accordance with the standards specified in rule 7. (7) If the certificate validity is less than one hour, the checking of revocation list shall not be required.¹Hkkx IIµ[k.M 3(i)º Hkkjr dk jkti=k % vlk/kj.k 15 7. Digital signature standards.—The most important standards that shall be applicable for different activities associated with digital signature functions are as under— Products Standards Cryptographic hash function SHA-2 as specified in FIPS 180-4 RSA Public Key Technology PKCS#1 RSA Encryption Standard ([2048, 4096 bit]); Version 1.5 Encryption and digital signature PKCS#7, CMS Validation of Digital Signature Certificate RFC 5280 ECC curve NIST P-256, P-384, or P-521 Long term signature formats 1. CAdES RFC 5126, 2. PAdES with CAdES Time stamp token As specified RFC 3161 8. Manner of authentication of information by means of xml digital signature.— A xml digital signature shall,— (a) be created and verified by cryptography which concerns with transforming electronic record into seemingly unintelligible forms; (b) use Public Key Cryptography, which employs an algorithm using two different but mathematical related keys, one key (called the private key) for creating a xml digital signature and another key (called the public key) for verifying a xml digital signature; (c) use an cryptographic hash function for creating and verifying a xml digital signature; (d) use canonicalization and xml transformation to create standard electronic record prior to creation and verification of xml digital signature; (e) authenticate xml documents which contain data as references and corresponding hashes, which is affected by the use of hash algorithm, canonicalization, xml transformation and public key algorithm. 9. Creation of xml digital signature.—(1) To sign an electronic record or any other item of information, the signatory shall first constructs reference elements, xml digital signature element, signedinfo, keyinfo and signaturevalue. (2) For the purpose of reference element generation, the signing software shall— (a) create reference(s) element(s) with reference to the item of information, xml transform element(s) (optional), digest algorithms and digest value; (b) optionally apply xml transform(s) to each referenced object in a sequential order; (c) apply the hash function in the signatory's hardware or software to each reference elements, store the hash result in the reference element; (d) ensure that if the object element is created, it shall not have a manifest element; (e) ensure that exclusive canonicalization "without comments" has been mandatorily specified in addition to any other transforms. (3) For the purpose xml digital signature generation, the signing software shall— (a) create signedinfo element with signaturemethod, canonicalisation method and reference(s); (b) apply canonicalisation to signedinfo and calculate the hash value of canonicalised signedinfo using the hashing algorithms implied by the signaturemethod; (c) ensure that,— (i) the signatory has seen all the contents of the document before signing; (ii) the contents display requirements, in the case of automated signing process, is not required; (iii) to sign multiple resources together,— (a) each resource shall be rendered on the screen;16 THE GAZETTE OF INDIA : EXTRAORDINARY [PART II—SEC. 3(i)] (b) each referenced xml resource shall be rendered using xslt and the xslt shall be the last transform done to render the resource on the screen; (c) each non xml resource shall be rendered using mimetype attribute mentioned in the object; (d) generate the signature using the signature algorithm and the hash, the signatory's private key, and the public key parameters (if applicable) and perform base64 encoding of the signature result and use it to form signaturevalue; (e) construct the signature element that includes signedinfo, items of information, keyinfo with ×509 certificate element and signaturevalue and the x509 certificate element shall carry the signatory's ×509 public key certificate. (4) The contextual information like date and time, shall be then made part of the xml digital signature. (5) The counter signatures or parallel signatures or both may also be applied to electronic record. (6) The following information may also be a part of signature— (a) the public key certificate(s) of the licensed Certifying Authorities which used to verify the authenticity of the digital signature certificate issued to the signatory; (b) the self signed certificate generated by the Controller used to verify the authenticity of the public key certificate of the licensed Certifying Authorities; (c) the certificate revocation list(s) maintained by the licensed Certifying Authorities and controller which is used check whether the digital signature certificate has been revoked under section 38 the Act; (d) online certificate status protocol responder certificates and online certificate status protocol responses may be used in lieu of certificate revocation list. (7) To create long term valid xml digital signature— (a) a timestamp shall be applied initially to the signed document, where the Initial time stamp shall cover all the electronic record and signature(s); (b) a nested time stamp option shall be used to ensure signature validity past the time-stamping service provider (tssp)'s key or algorithm expiry where as nesting of time stamps implies that a subsequent time stamp shall be applied to the prior time stamp; (c) signature(s) and time stamps may be embedded in the data itself or stored separately as standalone. 10. Verification of xml digital signature.—(1) The verification of the xml digital signature shall be accomplished by signature validation, reference validation and certificate validation and an xml digital signature shall be treated valid only if signature validation, reference validation and certificate validation as specified below are complied with. (2) To accomplish signature validation— (a) canonical form of signedinfo as produced during reference validation shall be used; (b) canonical form of signaturemethod using the canonicalization method shall be obtained; (c) the public key contained in the signatory's x509 certificate that is included in the xml digital signature, the canonicalisied form of signedinfo signaturevalue, and canonicalisied form of signaturemethod shall be used to verify the signature. (3) To accomplish reference validation— (a) canonicalise the signedinfo element based on the canonicalisation method in the signedinfo shall be used; (b) for each reference in the signedinfo— (i) if transformations were applied by the signatory, then the verifier software may de-reference the uniform resource identifier (uri) and execute transforms provided by the signatory in the reference element; (ii) compute digest of referenced item using the digestmethod specified in its reference element; (iii) compare the computed digest value against digestvalue in the signedinfo reference; if there is any mismatch or validation fails; (4) The Digital Signature Certificate included in the xml digital signature shall be verified in accordance with the provisions specified in rule 6. (5) To verify counter signature, the signature on electronic record first and signature on previous signature shall be verified serially.¹Hkkx IIµ[k.M 3(i)º Hkkjr dk jkti=k % vlk/kj.k 17 (6) To verify parallel signature, signature on electronic record shall be verified independently. (7) To verify long term signature, the initial timestamp and all subsequent time stamp applied on the each prior timestamp shall be verified. 11. The xml digital signature standards.—The most important standards that shall be applicable for different activities associated with xml digital signature functions are as under— The Product Standard RFC 3275 with the following constraint o Manifest is not permitted inside Object, o KeyInfo containing X509Certificate element is mandatory. o The Reference Processing shall use the Exclusive Canonicalization(without comments) in addition to other transforms. XML Digital Signature Standard o For XML resource, XSLT shall be the last transform done to enable the rendering of the document on screen. o For rendering of document on the screen o Each referenced XML resource shall be implemented using XSLT. o Each non XML resource shall be implemented using Mime Type attribute mentioned in the object. XML Namespace RFC 3986 Signature encoding UTF-8 RFC 3629 Signature Value Encoding Base64 RFC 4648 Reference element Digest SHA256 FIPS 180-4 Signature Algorithm SHA256withRSA PKCS-1 Version 1.5 o Exclusive (without comments), XML-EXC-C14N, RFC 3741 o Canonical XML 1. Canonical XML 1.0 (omits comments) Signature block Canonicalization http://www.w3.org/TR/2001/REC-xml-c14n-20010315 2. Canonical XML 1.1 (omits comments) http://www.w3.org/2006/12/xml-c14n11 Exclusive (without comments), XML-EXC-C14N, RFC 3741 Canonical XML 1. Canonical XML 1.0 (omits comments) http://www.w3.org/TR/2001/REC-xml-c14n-20010315 Transform Algorithms 2. Canonical XML 1.1 (omits comments) http://www.w3.org/2006/12/xml-c14n11 XSLT-XSL Transforms (XSLT) Version 1.0. W3C http://www.w3.org/TR/1999/REC-xslt-19991116 XPath – RFC 3653 Signature Type enveloped or enveloping or detached Digital Signature Certificate (DER) X.509 V3 issued as per interoperability guidelines18 THE GAZETTE OF INDIA : EXTRAORDINARY [PART II—SEC. 3(i)] Public Key Algorithms RSA PKCS-1 Version 1.5 ECC curve NIST P-256, P-384, or P-521 Long Term Signature formats 1. XMLERS RFC 6283 and XAdES 2. XMLERS RFC 6283 and PAdES with XAdES Time Stamp Token As specified RFC 3161 in XML notation 12. The basic Syntax of xml digital signature and terms used in the rule shall be as follows, namely:- <Signature ID?> <SignedInfo> <CanonicalizationMethod/> <SignatureMethod/> (<Reference URI?> (<Transforms>)? <DigestMethod> <DigestValue> </Reference>+ </SignedInfo> <SignatureValue> (<KeyInfo> (KeyName) (KeyValue) (RetrievalMethod) (<X509Data> (X509SKI) (X509SubjectName) (X509Certificate) (X509CRL) (X509Digest) </x509Data>) </Keyinfo>) (<Object ID?>)* </Signature> Where "?" denotes zero or one occurrence; "+" denotes one or more occurrences; and "*" denotes zero or more occurrences.”¹Hkkx IIµ[k.M 3(i)º Hkkjr dk jkti=k % vlk/kj.k 19 13. Digital Signature functions Standard.— The manner of digital signature creation and verification, in respect of signature profile and signature format, shall also conform to the following guidelines issued by Controller, namely:- (i) Interoperability Guidelines for Digital Signature Certificates issued under Information Technology Act; (ii) X.509 Certificate Policy for India PKI; (iii) Signature profiles; (iv) Online Certificate Status Protocol (OCSP) Service Guidelines for Certifying Authorities (CA); (v) Time Stamping Services Guidelines for Certifying Authorities (CA). [F. No. 19/26/2015-CCA] TAPAN RAY, Addl. Secy. अअअअििििधधधधससससचचूूचचूू ननननाााा नई (cid:1)द(cid:3)ली, 25 अग(cid:8)त , 2015 ससससाााा....ककककाााा....ििििनननन.... 666666661111((((अअअअ))))....— के(cid:13) (cid:14)ीय सरकार, सूचना (cid:15)ौ(cid:17)ोिगक(cid:20) अिधिनयम, 2000 (2000 का 21) क(cid:20) धारा 16 के साथ पOठत धारा 87 क(cid:20) उपधारा (2) के खंड (ङ) (cid:21)ारा (cid:15)द(cid:24) शि(cid:26)य(cid:28) का (cid:15)योग करत े(cid:29)ए सूचना (cid:15)ौ(cid:17)ोिगक(cid:20) (सुर)ा (cid:15)(cid:1)Bया) िनयम, 2004 का और संशोधन करन े के िलए िन(cid:31)िलिखत िनयम बनाती ह,ै अथा"त ्:-- 1.(1) इन िनयम(cid:28) का संि)* त नाम सूचना (cid:15)ौ(cid:17)ोिगक(cid:20) (सुर)ा (cid:15)(cid:1)Bया) संशोधन िनयम, 2015 ह ै । (2) ये उनके राजप/ म 0 (cid:15)काशन क(cid:20) तारीख से (cid:15)वृ3त ह(cid:28)गे । 2. सूचना (cid:15)ौ(cid:17)ोिगक(cid:20) (सुर)ा (cid:15)(cid:1)Bया) िनयम, 2004 म0,-- (क) िनयम 2 म,0 खडं (ङ) के (cid:8)थ ान पर िनiन िलिखत खडं रखा जाएगा, अथात" ् :-- ''(ङ) इन िनयम(cid:28) म0 अनु(cid:15)यु:त शh द और पद, जो पOरभािषत नहa ह > lकत ु अिधिनयम म 0 और अंक(cid:20)य ह(cid:8)त ा)र (अंितम िनकाय) िनयम, 2015 म0 पOरभािषत ह,> का Bमश: वही अथ" होगा जो उनका उ:त अिधिनयम और िनयम(cid:28) म0 ह ै ।'' ; (ख) िनयम 4 म,0 खडं (च) के (cid:8)थ ान पर िनiन िलिखत खडं रखा जाएगा, अथात" ् :-- ''(च) अंक(cid:20)य ह(cid:8) ता)र (अंितम िनकाय) िनयम, 2015 के िनयम 7 या िनयम 12 म 0 िनVदTट मानक(cid:28) का, जहां तक उनका संबंध अंक(cid:20)य ह(cid:8) ता)र के सृजन, भंडारण और पारेषण स े ह,ै अनपु ालन कर िलया गया ह ै; और [फा. सं. 19/26/2015-सीसीए] तपन राय, अपर सिचव (cid:30)(cid:30)(cid:30)(cid:30)टटटट(cid:23)(cid:23)(cid:23)(cid:23)पपपपणणणण :::: मूल िनयम भारत के राजप/, असाधारण, भाग , खंड 3, उपखंड (i) म0 अिधसूचना सं. सा.का.िन. 735(अ), II तारीख 29 अ: तूबर, 2014 (cid:21)ारा (cid:15)कािशत (cid:1)कए गए थे । NOTIFICATION New Delhi, the 25th August, 2015 G.S.R. 661(E).―In exercise of the powers conferred by clause (e) of sub-section (2) of Section 87 read with Section 16 of the Information Technology Act, 2000 (21 of 2000), the Central Government hereby makes the following rules to amend the Information Technology (Security Procedure) Rules, 2004. 1. (1) These rules may be called the Information Technology (Security Procedure) Amendment Rules, 2015. (2) They shall come into force on the date of their publication in the Official Gazette. 2. In the Information Technology (Security Procedure) Rules, 2004,― (a) in rule 2, for clause (e), the following clause shall be substituted, namely:― "(e) words and expressions used in these rules and not defined but defined in the Act and the Digital Signature (End entity) Rules, 2015 shall have the same meaning respectively assigned for them in the said Act and rules.";20 THE GAZETTE OF INDIA : EXTRAORDINARY [PART II—SEC. 3(i)] (b) in rule 4, for clause (f), the following clause shall be substituted, namely:― "(f) that the standards referred to in rule 7 or rule 12 of the Digital Signature (End entity) Rules, 2015 have been complied with, in so far as they relate to the creation, storage and transmission of the digital signature; and". [F. No. 19/26/2015-CCA] TAPAN RAY, Addl. Secy. Note : The principal rules were published in the Gazette of India, Extraordinary, Part II, and Section 3, Sub-section (i), vide notification number G.S.R. 735(E), dated the 29th October, 2004. अअअअििििधधधधससससचचूूचचूू ननननाााा नई (cid:1)द(cid:3)ली, 25 अग(cid:8)त , 2015 ससससाााा....ककककाााा....ििििनननन.... 666666662222((((अअअअ))))—के(cid:13) (cid:14)ीय सरकार, सूचना (cid:15)ौ(cid:17)ोिगक(cid:20) अिधिनयम, 2000 (2000 का 21) क(cid:20) धारा 87 (cid:21)ारा (cid:15)द(cid:24) शि(cid:26)य(cid:28) का (cid:15)योग करत े (cid:29)ए सूचना (cid:15)ौ(cid:17)ोिगक(cid:20) ((cid:15)माणीकरण (cid:15)ािधकारी) िनयम, 2000 का और संशोधन करन े के िलए िन(cid:31)िलिखत िनयम बनाती ह,ै अथा"त ्:-- 1. (1) इन िनयम(cid:28) का संि)* त नाम सूचना (cid:15)ौ(cid:17)ोिगक(cid:20) ((cid:15)माणीकरण (cid:15)ािधकारी) संशोधन िनयम, 2015 ह ै । (2) ये उनके राजप/ म 0 (cid:15)काशन क(cid:20) तारीख से (cid:15)वृ3त ह(cid:28)गे । 2. सूचना (cid:15)ौ(cid:17)ोिगक(cid:20) ((cid:15)माणीकरण (cid:15)ािधकारी) िनयम, 2000 म,0-- (क) िनयम 6 म,0 सारणी म,0 ''मानक'' शीष" के अधीन ''डीएसए और आरएसए'' (cid:15)िविTट य(cid:28) के (cid:8)थ ान पर ''डीएसए, आरएसए और कव" एनआईएसटी पी-256, पी-384 या पी-521'' (cid:15)िविTट यां रखी जाएंगी ; (ख) िनयम 7 के (cid:8)थ ान पर िनi निलिखत िनयम रखा जाएगा, अथा"त ् :-- ''7777.... अअअअककंंककंं (cid:8)(cid:8)(cid:8)(cid:8)यययय हहहह$$$$तत तत ाााा(cid:22)(cid:22)(cid:22)(cid:22)रररर (cid:1)(cid:1)(cid:1)(cid:1)ममममााााणणणणपपपप(cid:11)(cid:11)(cid:11)(cid:11) ममममााााननननकककक————(cid:15)माणीकरण (cid:15)ािधकाOरय(cid:28) (cid:21)ारा जारी सभी अंक(cid:20)य ह(cid:8)त ा)र (cid:15)माणप/ और (cid:15)माणप/ (cid:15)ितसंहरण सूची सूचना (cid:15)ौ(cid:17)ोिगक(cid:20) अिधिनयम के अधीन िनयं/क (cid:21)ारा अंक(cid:20)य ह(cid:8)त ा)र (cid:15)माणप/(cid:28) के िलए जारी अंतरकाय"कारी मागद" श"क िसLांत(cid:28) के अनु@प होगी ।'' ; (ग) िनयम 23 म,0-- (i) खंड (ङ) म0 ''िववरण'' शhद के पKच ात ् ''िनयं/क (cid:21)ारा जारी पहचान स3य ापन माग"दश"क िसLांत(cid:28) के अनुसार'' शब् द अतं :(cid:8) थािपत (cid:1)कए जाएंगे ; (ii) खंड (ङ) के पK चात ् िनi निलिखत खडं अंत:(cid:8)थ ािपत (cid:1)कया जाएगा, अथा"त ् :-- ''(ङक) िनयं/क (cid:21)ारा अनुkि* त के िलए आवेदन के दौरान (cid:15)ारंिभक (cid:15)माणीकरण पLित िववरण अनुमोदन के पK चात ् अंशदाता पहचान स3य ापन पLित या अंक(cid:20)य ह(cid:8)त ा)र (cid:15)माणप/ जारी करन े के िलए अनु(cid:15)यु:त माग"दश"क िसLांत(cid:28) म 0 सभी पOरवत"न िनयं/क (cid:21)ारा जारी पहचान स3य ापन माग"दश"क िसLांत(cid:28) के अनुसार ह(cid:28)ग े और पOरवत"न(cid:28) को आविधक @प से (cid:15)माणीकरण पLित िववरण म 0 शािमल (cid:1)कया जाएगा तथा उनका िनयं/क (cid:21)ारा अनुमोदन (cid:1)कया जाएगा ;'' ; (घ) िनयम 24 म,0 खडं (च) के अंत म0, ''िनयं/क (cid:21)ारा भारत के िलए जारी पीकेएल (सीपी) ए:स .509 (cid:15)माणीकरण नीित के अनुसार'' शब् द अतं :(cid:8) थािपत (cid:1)कए जाएंग े ; (ङ) िनयम 25 म0, खंड (ii) म,0 ''भी ह,ै (cid:1)क'' शhद (cid:28) के पKच ात ् ''िनयं/क (cid:21)ारा जारी पहचान माग"दश"क िसLांत(cid:28) के अनुसार'' शब् द अतं :(cid:8) थािपत (cid:1)कए जाएंगे ; (च) िनयम 31 म0, उपिनयम (1) म 0 खंड (ix) के पKच ात् िनiन िलिखत खडं अंत:(cid:8)थ ािपत (cid:1)कया जाएगा ; ''(x) िनयं/क (cid:21)ारा भारत के िलए जारी पीके1 सुसंगत ए:स .509 (cid:15)माणप/ नीित का अनुपालन¹Hkkx IIµ[k.M 3(i)º Hkkjr dk jkti=k % vlk/kj.k 21 (xi) िनयं/क (cid:21)ारा अ(cid:13) य सेवाD जैसे समय (cid:8)ट ॉgपग और ओसीएसपी सेवा माग"दश"क िसLांत(cid:28) का अनुपालन ; (xii) िनयं/क (cid:21)ारा जारी पहचान स3य ापन मागद" श"क िसLांत(cid:28) का अनुपालन ; (xiii) िनयं/क (cid:21)ारा जारी ''अंक(cid:20)य ह(cid:8)त ा)र (cid:15)माणप/ अतं रकाय"कारी माग"दश"क िसLांत(cid:28)'' का अनपु ालन ; (छ) अनुसूची 4 म,0 (क) (cid:15)@प क म 0 उपशीष "''मह3 वपूण" सूचना के अधीन :'',-- (i) ''भरा (cid:29)आ'' शh द(cid:28) के (cid:8)थ ान पर ''ह(cid:8)त ा)Oरत'' शhद रख े जाएंग े ; (ii) ''आवेदन अिनवाय"ता (cid:8) वय ं fय ि:त (cid:21)ारा (cid:15)(cid:8)त तु (cid:1)कया जाए'' शhद (cid:28) का लोप (cid:1)कया जाएगा ; (ख) (cid:15)@प ख म 0 उपशीष " ''पहचान और िनवास के सबूत का अिध(cid:15)माणन'' (cid:15)िविTट य(cid:28) के (cid:8)थ ान पर िनiन िलिखत रखा जाएगा, अथा"त् :-- (i) ''पहचान स3 यापन पLित और िनवास के सबतू क(cid:20) अपे)ाएं सीए क(cid:20) (cid:15)माणन पLित िववरण (सीपीएस) और िनयं/क (cid:21)ारा जारी पहचान स3य ापन माग"दशक" िसLांत(cid:28) के अनुसार ह(cid:28)गी ।'' ; (ii) ''मह3 वपूण" सूचना'' उपशीष " के अधीन :'',-- (1) ''भरा (cid:29)आ'' शh द(cid:28) के (cid:8)थ ान पर ''ह(cid:8)त ा)Oरत'' शhद रख े जाएंग े ; (2) ''आवेदन अिनवाय"ता (cid:8)व य ं fय ि:त (cid:21)ारा (cid:15)(cid:8)त तु (cid:1)कया जाए'' शhद (cid:28) का लोप (cid:1)कया जाएगा । [फा. सं. 19/26/2015-सीसीए] तपन राय, अपर सिचव (cid:30)(cid:30)(cid:30)(cid:30)टटटट(cid:23)(cid:23)(cid:23)(cid:23)पप पप णणणणीीीी :::: मूल िनयम भारत के राजप/, असाधारण, भाग , खंड 3, उपखंड (i) म 0 अिधसूचना सं. सा.का.िन. 789(अ), II तारीख 17 अ:त ूबर, 2000 (cid:21)ारा (cid:15)कािशत (cid:1)कए गए थ े और उनका अंितम संशोधन स.ं सा.का.िन. 783(अ), तारीख 25 अ: तूबर, 2011 (cid:21)ारा (cid:1)कया गया था । NOTIFICATION New Delhi, the 25th August, 2015 G.S.R. 662(E).― In exercise of the powers conferred by section 87 of the Information Technology Act, 2000 (21 of 2000), the Central Government hereby makes the following rules further to amend the Information Technology (Certifying Authorities) Rules, 2000. 1. (1) These rules may be called the Information Technology (Certifying Authorities) Amendment Rules, 2015. (2). They shall come into force on the date of their publication in the Official Gazette. 2. In the Information Technology (Certifying Authorities) Rules, 2000,— (a) in rule 6, in the table , under the heading "The Standard", for the entries "DSA and RSA", the entries " DSA , RSA and Curves NIST P-256, P-384, or P-521" shall be substituted; (b) for rule 7, the following rule shall be substituted, namely:— "7.Digital Signature Certificate Standard.—All Digital Signature Certificates and Certificate Revocation List issued by the Certifying Authorities shall conform to Interoperability Guidelines for Digital Signature Certificates issued by Controller under the Information Technology Act."; (c) in rule 23,— (i) in clause (e), after the word " Statement", the words "in accordance with the Identity Verification Guidelines issued by the Controller” shall be inserted;22 THE GAZETTE OF INDIA : EXTRAORDINARY [PART II—SEC. 3(i)] (ii) after clause(e), the following clause shall be inserted, namely:- “(ea) subsequent to initial approval of Certification Practice Statement by the Controller during the application for a licence, all the changes in the subscriber identity verification method or guidelines employed for issuance of Digital Signature Certificate shall be in accordance with the Identity Verification Guidelines issued by the Controller and the changes shall be incorporated in the Certification Practice Statement periodically and shall be approved by the Controller;”; (d) in rule 24, in clause (f) , the words, brackets and letters “in accordance with the X.509 Certificate Policy for India PKI(CP) issued by the Controller" shall be inserted at the end ; (e) in rule 25, in clause (ii) , the words “in accordance with the Identity Verification Guidelines issued by the Controller” shall be inserted at the end; (f) in rule 31, in sub-rule (1) , after clause (ix), the following clauses shall be inserted namely:- “(x) compliance to relevant X.509 Certificate Policy for India PKI issued by the Controller; (xi) compliance to guidelines issued by the Controller for other services like Time Stamping and OCSP service; (xii) compliance to Identity Verification Guidelines issued by the Controller; (xiii) compliance to "Digital Signature Certificates Interoperability Guidelines" issued by the Controller.”; (g) in SCHEDULE IV,― (a) in Form A, under the sub-heading “Important Notice:”,— (i) for the word “filled ” the word “signed” shall be substituted; (ii) the words “Application form must be submitted in person.” shall be omitted; (b) in Form B, (i) for the entries under the sub-heading “Authentication of Identity and Proof of Residence”, the following shall be substituted, namely:— ”The identity verification methods and proof of residence requirements shall be as per Certification Practice Statement (CPS) of the CA and Identity Verification Guidelines issued by the Controller.”; (ii) under the sub-heading “Important Notice:”,— (1) for the word “filled ” the word “signed” shall be substituted; (2) the words “Application form must be submitted in person.” shall be omitted. [F. No. 19/26/2015-CCA] TAPAN RAY, Addl. Secy. Note. : The principal rules were published in the Gazette of India, Extraordinary, Part II, and Section 3, Sub-section (i), vide notification number G.S.R. 789(E), dated the 17th October, 2000 and last amended by notification No. G.S.R. 783(E), dated the 25th October 2011. Printed by the Manager, Government of India Press, Ring Road, Mayapuri, New Delhi-110064 and Published by the Controller of Publications, Delhi-110054.

Continue your research