“ The first step towards an Information Society requires that millions of people be entrusted with information considered sensitive or even secret” -S.Frederic Starr
The above quote implicitly considers that secret information be protected to maintain its secrecy ! But the very openness of the Internet, that has led to its explosive growth, has also given rise to security limitations. Government entities and private businesses that are obvious candidates for participating in electronic commerce are understandably cautious. To be able to rely on the electronic messages they receive, such organizations need assurance that those messages are authentic and reliable. Digital communication has created new complications for old business models: ? How do you know the identity of the person you’re dealing with? ? How do you prove that a certain transaction was performed ? ? How do you secure your communication? By implementing a public key infrastructure (PKI), entities can be assured that data remains confidential and intact, and all transactions are legally binding.
?| NIC Certifying Authority (NICCA) As the Government of India moves toward the implementation of E-Governance at various levels of Government functioning, authentication of information becomes a critical requirement. To provide the necessary platform, a Public Key Infrastructure becomes essential. NIC has set up a Certifying Authority, which is an integral part of this Public Key Infrastructure. PKI refers to a whole host of components, applications, policies and practices which are responsible for offering its users the following benefits: ? Certainty of the quality of information sent and received electronically ? Certainty of the source and destination of that information ? Assurance of the time and timing of that information ? Certainty of the privacy of that information ? Assurance that the information may be introduced as evidence in a court of law
PKI Model The basic components of a PKI are the Registration Authority (RA) and the Certifying Authority (CA). The RA authenticates and registers new users and requests certificates for them. The CA generates certificates on the RA’s request and posts the certificate to a directory. A PKI also includes policies, procedures, and contracts that govern how and when digital certificates are issued, renewed, or revoked, among other issues. Therefore, public key infrastructure consists of : ? A certifying authority (CA) that issues and verifies Digital Signature Certificate. ? A registration authority (RA) that acts as the verifier for the certificate authority before a digital certificate is issued to a requestor ? One or more directories where the certificates (with their public keys) are held ? A certificate management system A Certifying Authority (CA) is a trusted third party or an entity that has been granted license by the Controller of Certifying Authorities (CCA), the apex regulatory body for Certifying Authorities in the country, to validate identities and issue Digital Signature Certificates. The method of validating identities, issuing of certificates, certificate management etc depends on the policies of CA as defined and published in their Certificate Practice Statement (CPS). NICCA fulfills requirements of trustworthiness of a Certifying Authority as laid down by the IT Act2000.
?| A certificate-based system provides services commonly known as ‘CAIN’ : ? Confidentiality- to ensure that sensitive information does not fall into the wrong hands ? Authentication- to verify the identity of the sender and the recipient of digital information ? Integrity- to verify that information is received unaltered from the sender ? Non-repudiation- to ensure that transactions are legally binding, protecting your business from fraud
?| How Public Key Cryptography Works : The method of disguising plain text in such a way to hide its substance is called Encryption. Encrypting plain text results in unreadable gibberish called Ciphertext. The process of reverting ciphertext to its original plain text is called Decryption.
?| In public key cryptography : ? A public and private key (called as key pair), are created by a Certifying Authority (CA) in the presence of the subscriber or alternately this key pair may be generated by subscriber himself. ? The private key is given only to the requesting party. The private key is never shared with anyone or sent across the Internet. ? The public key is made publicly available (as part of a digital certificate) in a directory that all parties can access. The private key is used to decrypt text that has been encrypted with the corresponding public key of the key pair. Thus, if a person ‘A’ wants to send a message to a person ‘B’, ‘A’ can find out the public key (but not the private key) of ‘B’ from a central administrator and encrypt a message using the same. When the person ‘B’ at the other end receives it, he/she can decrypt it with his/her private key. The Information Technology Act, 2000 provides the required legal sanctity to the Digital Signatures based on asymmetric crypto systems.
?| Functions of NIC Certifying Authority : ? Subscriber Request: Identification of persons applying for Digital Signature Certificate (DSC) through Registration Authority (RA). ? Key Certification: The transaction that results in the CA signing a subscribers’ public key and issuing the Digital Signature Certificate. ? Certificate Publishing: placing the certificate in the PKI directory where PKI users can search for and retrieve it. ? Certificate Renewal: issuing a new certificate to the subject when the current certificate has expired. ? Certificate Revocation: adding a users certificate to the revocation list making the certificate invalid from that date and time onward. ? Revocation list Publishing and maintenance: to keep the Certificate Revocation list (CRL) current within the PKI and place the current CRL in the PKI directory where PKI users can search for and retrieve it. Initially, NICCA functions as a trusted authority in the G2G domain for issuance of Digital Signature Certificates (DSC).
?| Basic Services ? Issuing Digital Signature Certificates to Subscribers in G2G environment. ? Secure Socket Layer (SSL) Certificates: Issuance of Web Server Certificate. ? Online Certificate Status Protocol (OCSP) Services: sends a request of a certificate status information to the client. ? Directory Services: Posting and maintenance of Valid Certificates and Certificate Revocation List. ? Time Stamping Services: a unique and unforgeable time stamp can be assigned to any piece of digital data. The time stamp provides proof that this particular data existed at a certain point in time. ? Round the clock (24X 7) operations. ? Provision for Key Archiving Services ? Provision for Sub CA ? Provision for Multiple RA: establishing multiple Registration Authority within various parts of the country, to function under NICCA ? Provision for Disaster Recovery Site
?| Application Development Services ? Build awareness among Government Departments. ? Provide training and consultancy services. ? Integrate Digital Signature with existing NICNET applications. ? Assist development of new Digital Signature based Applications.
Shri Arun Shourie, Hon’ble Minister for Communications and Information Technology, inaugurated the Certifying Authority for Digital Signature Certificates at National Informatics Centre on 8th July,2003. With this, NIC has become the first Certifying Authority in the government sector. This facility will provide Digital Signature Certificates (DSC) to the officials of central and state government and all District Administrators with a view to promote E-Governance in the country.The first lot of digital signature certificates from NIC were presented to Mr. Shourie, Mr. Thirunavukkarasar, Minister of state for IT, and Mr. KK Jaswal, Secretary, Department of IT. As a first application of digital signatures in the government, electronically signed e-mails were exchanged.
?| Conclusion The need for secure communications in Computer Networks has brought about the need for setup of a Public Key Infrastructure. NIC Certifying Authority is one such component in a PKI setup paving the way for a ‘trusted’ digital environment leading towards good E-Governance. With the CA facility at NIC providing digital signatures, it is hoped that government offices will first turn “less-paper” and gradually “paperless”. It would also help the e-governance drive through a secure and ‘trusted’ digital environment in cyber space. In fact, with digital signatures attached e-mail and other documents transmitted over the Net would become valid legal documents.
For further information please contact: NIC Certifying Authority Division E-mail: support@camail.nic.in WWW : http://nicca.nic.in