E Sign

eSign is an innovative online electronic signature service in India that allows individuals to digitally sign electronic documents without needing a physical Digital Signature Certificate (DSC) or cryptographic token. 

Here’s a breakdown of what eSign is all about:

  1. Core function
  • eSign enables the legally valid signing of documents electronically, eliminating the need for physical signatures.
  • It utilizes Aadhaar-based e-KYC (Know Your Customer) service to authenticate the signer’s identity and uses Public Key Infrastructure (PKI) for secure digital signature creation. 
  1. Key features and benefits
  • Convenience: Sign documents anytime, anywhere, without physical dongles or being physically present.
  • Legal Validity: eSignatures are legally recognized under the Information Technology Act, 2000.
  • Enhanced Security: Private keys used for signing are generated on Hardware Security Modules (HSM) and immediately destroyed after a single use, enhancing security and preventing misuse.
  • Privacy: Only a “thumbprint” or hash of the document is submitted for signing, not the entire document, ensuring signer privacy.
  • Efficiency: Streamlines workflows and reduces time and costs associated with traditional paper-based signing processes.
  • Verifiability: Signatures and the signatory can be easily verified.
  • Audit Trail: A comprehensive digital audit trail is maintained to confirm the validity of transactions. 
  1. How eSign works
  • Application Service Providers (ASPs) integrate with the eSign API and gateway.
  • Users are authenticated using their Aadhaar ID and either biometric or OTP (one-time password) authentication.
  • The user’s document is then digitally signed using the PKI infrastructure on the eSign provider’s backend server, and the digitally signed document along with the Digital Signature Certificate is returned to the user. 
  1. Usage
  • eSign can be used by individuals, businesses, and government entities for various purposes, including contracts, agreements, applications, and official documents.
  • Biometric authentication is ideal for transactions with moderate risks, while OTP-based authentication is suitable for situations with lower risks. 
  1. Providers
  • eSign services are facilitated by trusted third-party Certifying Authorities (CAs) licensed under the IT Act.
  • C-DAC also facilitates eSign services through its e-Hastakshar initiative. 

In essence, eSign is a secure, efficient, and legally recognized method for digitally signing documents in India, leveraging Aadhaar-based authentication to provide a seamless and paperless experience. 

Information and diagram from CCA on-boarding guide (Copyright CCA office)

The service is provided through a Eco-system of ASP’s in various verticicals. Please select a vertical on the right to see all the solutions available for your sector.

On High level, the eSign Services are provided to Aadhar Card holders and by taking consent ASP would use OTP authentication before Digitally Signing a document.