🚂 RailGuruji
Information security and cyber lawसूचना सुरक्षा और साइबर कानून3 / 6

Encryption, digital signatures and PKIएन्क्रिप्शन, डिजिटल हस्ताक्षर और पीकेआई

Updated अद्यतन 07 Oct 2026
This chapterयह अध्याय asked in 2 exams2 परीक्षाओं में पूछा गया
1
SYMMETRIC AND ASYMMETRIC CRYPTOGRAPHYसिमेट्रिक और एसिमेट्रिक क्रिप्टोग्राफी
ENCRYPTION converts plain text into cipher text with a cryptographic algorithm.
  • SYMMETRIC: ONE secret key encrypts and decrypts. It gives confidentiality only; AES is an example
  • ASYMMETRIC: TWO keys. You share the PUBLIC key, and never share the PRIVATE key
  • What one key encrypts, only the other key of the pair can decrypt
  • To send you a secret, the sender encrypts with YOUR public key; you decrypt with your private key
  • RSA, Diffie-Hellman and elliptic curve systems are asymmetric
HASHING turns data into a fixed-length value, from which the original cannot be recovered. So symmetric uses one key, and asymmetric a public and private pair.
एन्क्रिप्शन क्रिप्टोग्राफिक एल्गोरिदम से सादे पाठ को सिफर पाठ में बदलता है।
  • सिमेट्रिक: एक गुप्त कुंजी एन्क्रिप्ट और डिक्रिप्ट करती है। यह केवल गोपनीयता देती है; एईएस इसका उदाहरण है
  • एसिमेट्रिक: दो कुंजियाँ। आप सार्वजनिक कुंजी साझा करते हैं, और निजी कुंजी कभी साझा नहीं करते
  • जोड़े की एक कुंजी जो एन्क्रिप्ट करे, उसे केवल दूसरी कुंजी डिक्रिप्ट कर सकती है
  • आपको गुप्त संदेश भेजने के लिए प्रेषक आपकी सार्वजनिक कुंजी से एन्क्रिप्ट करता है; आप अपनी निजी कुंजी से डिक्रिप्ट करते हैं
  • आरएसए, डिफी-हेलमैन और एलिप्टिक कर्व प्रणालियाँ एसिमेट्रिक हैं
हैशिंग डेटा को निश्चित लंबाई के मान में बदलती है, जिससे मूल डेटा वापस नहीं मिल सकता। अर्थात् सिमेट्रिक एक कुंजी, और एसिमेट्रिक सार्वजनिक-निजी जोड़ी का उपयोग करती है।
2
HOW A DIGITAL SIGNATURE WORKSडिजिटल हस्ताक्षर कैसे काम करता है
A digital signature proves who sent a document, and that it was not altered. It uses asymmetric cryptography.
  • The sender HASHES the document into a MESSAGE DIGEST
  • The sender ENCRYPTS the digest with the sender's PRIVATE KEY. That is the signature, appended to the document
  • You decrypt the signature with the sender's PUBLIC KEY to get digest H1
  • You hash the document yourself to get H2. If H1 equals H2, the signature is valid
  • It gives INTEGRITY, AUTHENTICITY and NON-REPUDIATION
Any change after signing invalidates the signature. So you sign with your private key, and others verify with your public key.
डिजिटल हस्ताक्षर सिद्ध करता है कि दस्तावेज किसने भेजा, और वह बदला नहीं गया। यह एसिमेट्रिक क्रिप्टोग्राफी का उपयोग करता है।
  • प्रेषक दस्तावेज को हैश करके मैसेज डाइजेस्ट बनाता है
  • प्रेषक डाइजेस्ट को अपनी निजी कुंजी से एन्क्रिप्ट करता है। यही हस्ताक्षर है, जो दस्तावेज से जोड़ा जाता है
  • आप प्रेषक की सार्वजनिक कुंजी से हस्ताक्षर डिक्रिप्ट करके डाइजेस्ट एच1 पाते हैं
  • आप स्वयं दस्तावेज हैश करके एच2 पाते हैं। यदि एच1 और एच2 बराबर हों, तो हस्ताक्षर वैध है
  • यह अखंडता, प्रामाणिकता और अस्वीकार्यता-रोध देता है
हस्ताक्षर के बाद कोई भी बदलाव हस्ताक्षर को अमान्य कर देता है। अर्थात् आप अपनी निजी कुंजी से हस्ताक्षर करते हैं, और दूसरे आपकी सार्वजनिक कुंजी से सत्यापित करते हैं।
3
PKI AND THE CONTROLLER OF CERTIFYING AUTHORITIESपीकेआई और प्रमाणन प्राधिकारी नियंत्रक
PKI, PUBLIC KEY INFRASTRUCTURE, binds public keys to their owners through certificates.
  • A REGISTRATION AUTHORITY verifies a person's identity and links it to the public key
  • A CERTIFICATION AUTHORITY, CA, signs the person's public key and identity with its own private key
  • A validation system confirms whether a certificate is still valid; revoked ones go on a CERTIFICATE REVOCATION LIST
  • In India the CCA, CONTROLLER OF CERTIFYING AUTHORITIES, licenses CAs under section 21 of the IT Act
  • The CCA runs the ROOT CERTIFYING AUTHORITY OF INDIA, RCAI, and the National Repository of Digital Certificates
Certificates follow the X.509 version 3 standard. NIC, IDRBT, TCS and eMudhra are among the licensed CAs. So the CCA licenses the CAs, and the CAs issue you certificates.
पीकेआई, अर्थात् पब्लिक की इन्फ्रास्ट्रक्चर, प्रमाणपत्रों के माध्यम से सार्वजनिक कुंजियों को उनके स्वामियों से जोड़ता है।
  • रजिस्ट्रेशन अथॉरिटी व्यक्ति की पहचान सत्यापित करके उसे सार्वजनिक कुंजी से जोड़ती है
  • सर्टिफिकेशन अथॉरिटी, सीए, व्यक्ति की सार्वजनिक कुंजी और पहचान पर अपनी निजी कुंजी से हस्ताक्षर करती है
  • सत्यापन प्रणाली पुष्टि करती है कि प्रमाणपत्र अब भी वैध है या नहीं; रद्द प्रमाणपत्र सर्टिफिकेट रिवोकेशन लिस्ट में जाते हैं
  • भारत में सीसीए, अर्थात् प्रमाणन प्राधिकारी नियंत्रक, आईटी अधिनियम की धारा 21 के अंतर्गत सीए को लाइसेंस देता है
  • सीसीए भारत का रूट प्रमाणन प्राधिकारी, आरसीएआई, और डिजिटल प्रमाणपत्रों का राष्ट्रीय भंडार चलाता है
प्रमाणपत्र एक्स.509 संस्करण 3 मानक का पालन करते हैं। एनआईसी, आईडीआरबीटी, टीसीएस और ई-मुद्रा लाइसेंसधारी सीए में हैं। अर्थात् सीसीए सीए को लाइसेंस देता है, और सीए आपको प्रमाणपत्र देते हैं।
4
DIGITAL SIGNATURE CERTIFICATESडिजिटल हस्ताक्षर प्रमाणपत्र
The PKI report lists four classes of certificate.
  • CLASS 0: for demonstration and testing only
  • CLASS 1: confirms your name and e-mail address; CLASS 2: checks your details against recognised consumer databases
  • CLASS 3: high assurance, for e-commerce; issued only on your personal appearance before the CA
  • A DSC carries your public key, name and e-mail, expiry date, serial number, and the CA's own digital signature
  • An E-TOKEN is a USB device holding your DSC, safer than keeping it on the computer
The CCA has since discontinued Classes 1 and 2, so certificates are now issued as Class 3. So Class 3 is the high-assurance certificate.
पीकेआई रिपोर्ट प्रमाणपत्र की चार श्रेणियाँ गिनाती है।
  • क्लास 0: केवल प्रदर्शन और परीक्षण के लिए
  • क्लास 1: आपका नाम और ई-मेल पता पुष्ट करता है; क्लास 2: आपके विवरण मान्य उपभोक्ता डेटाबेसों से जाँचता है
  • क्लास 3: उच्च आश्वासन, ई-कॉमर्स के लिए; केवल सीए के सामने आपकी व्यक्तिगत उपस्थिति पर जारी
  • डीएससी में आपकी सार्वजनिक कुंजी, नाम और ई-मेल, समाप्ति तिथि, क्रम संख्या, और सीए का अपना डिजिटल हस्ताक्षर होता है
  • ई-टोकन आपका डीएससी रखने वाला यूएसबी उपकरण है, जो उसे कंप्यूटर पर रखने से सुरक्षित है
सीसीए ने तब से क्लास 1 और 2 बंद कर दिए हैं, इसलिए प्रमाणपत्र अब क्लास 3 में जारी होते हैं। अर्थात् क्लास 3 उच्च-आश्वासन प्रमाणपत्र है।
Report an error on this pageइस पेज में गलती बताएँ
Read it — now test yourself. पढ़ लिया — अब खुद को परखें। Take the free Mock CBTफ्री Mock CBT दें