A digital signature shall be deemed to be a secure digital signature for die pur poses of the Act if the following procedure has been applied to it, namely:—
(a) that the smart card or hardware token, as die case may be, with cryptograpliic module, in it, is used to create die key pair;
(b) dial the private key used to create die digital signature always remains in die smart card or hardware token as die case may be;
[MFTII—75^ 3 (i)] MTOT̂ t TT5P̂ : ggpngj 3
(c) that the hash of the content to be signed is taken from tlie host system to tlie smart card or hardware token and tlie private key is used to create tlie digital signature and tlie signed hash is returned to tlie host system;
(d) that tlie information contained in tlie smart card or hardware token, as the case may be, is solely under tlie control of the person who is purported to have created the digital signature;
(e) that tlie digita 1 signature can be verified by using tlie public key listed in tlie Digital Signature Certificate issued • to that person;
(f) that tlie standards referred to in rule 6 of tlie Information Technology (Certifying Authorities) Rules, 2000 have been complied with, in so far as they relate to the creation, storage and transmission of the digital signature:
and
(g) that tlie digital signature is linked to the electronic record in such a manner that if the electronic record was altered tlie digital signature would be inval idated. • [F,No.9(8)/2003-EC] S. LAKSHMINARAYANAN, Add! Secy.