Unit-1
Introduction to Cyber space
• Cyberspace was introduced by William Gibson in his 1984 book,
Neuromancer.
• Any time the Internet is used, it creates cyberspace.
• Cyberspace is as broad as the human imagination.
• It has gained popularity as a medium for social interaction.
• Cyberspace is always evolving and promises to be more diverse in the
years to come.
• Cyberspace refer to the virtual computer world and more specially is an
electronic medium used to form a global computer to facilitate online
communication.
• It is large computer network made up by many worldwide computer
network that employ TCP/IP protocol to aid in communication and data
exchange activites.
• In effect cyber space can be thought of as the interconnection of human
begins through computer and telecommunication without regard of
physical geography.
Threats in cyber space:
Cyber crime
Hacking
Cyber terrorism
Cyber espionage
Advantage of cyberspace:
• Unlimited communication
• Abundant information and resources
• Easy sharing
• Online services and E-commerce
Disadvantage of cyberspace:
• Software vulnerabilities
• Data vulnerabilities
• Interruption of privacy
• Remote access
• Assists crime
Cyberlaw:
o Cyber law is the law governing cyber space.
o Cyber law, also known as internet law or digital law, signifies the
legal regulations and frameworks governing digital activities.
o Cyber space is a very wide term and includes computers,
networks, software, data storage devices, the internet,
websites, emails and even electronic devices such as cell
phones, ATM machines etc.
o It covers a large range of issues, including online
communication, e-commerce, digital privacy, and the
prevention and prosecution of cybercrimes
o To define the different arms of cybersecurity two main acts are
considered in India, they are
The Indian penal code,1860
The Information Technology act,2000
Cyber law encompasses laws relating to:
o Cyber crimes
o Electronic and digital signatures
o Intellectual property
o Data protection and privacy
UNCITRAL Model law:
The UNCITRAL Model Law on Electronic Commerce, adopted in 1996,
plays a significant role in the realm of cyber law by providing a legal
framework for electronic transactions.
The advantage of UNCITRAL law is that it provides a uniform set of rules
for international trade.
Here are some key aspects:
1. Legal Recognition of Electronic Transactions
- The Model Law establishes that electronic communications and documents
should have the same legal validity as traditional paper documents, promoting
the use of digital transactions.
2. Formation of Contracts
- It outlines how contracts can be formed electronically, including the
requirements for offer, acceptance, and confirmation in a digital context.
3. Time and Place of Dispatch and Receipt
- The Model Law addresses when and where electronic communications are
considered sent and received, which is crucial for determining the timing of
contractual obligations.
4. Functional Equivalence
- The principle of functional equivalence suggests that electronic records and
signatures can replace their traditional counterparts, as long as they serve the
same purpose.
[Link] Protection
- While the Model Law primarily focuses on facilitating electronic commerce,
it also recognizes the need for consumer protection in electronic transactions.
6. International Harmonization
- By providing a uniform legal framework, the Model Law aims to harmonize
laws across different jurisdictions, making it easier for businesses to operate
internationally.
Impact on Cyber Law
The UNCITRAL Model Law has influenced many countries to modernize their
legal frameworks regarding electronic commerce, leading to increased
confidence in digital transactions and fostering innovation in the digital
economy.
Information Technology ACT,2000
• The Information Technology Act, 2000 (IT Act) is on act of Indian
parliament on 17 October 2000.
• It is the primary law in India dealing with cybercrime and electronic
commerce. It is based on the UNICITRAL model law.
• This legal framework, also known as IT Act 2000, comes with 94
sections, divided into 13 chapters and 2 schedules.
Importance of IT Act 2000
• The Act provides legal recognition to electronic records, resulting in the
growth of e-commerce and digital transactions in India.
• It has established electronic signatures as the legal equivalent of physical
signatures.
• The Act established the Controller of Certifying Authorities (CCA), a
government body responsible for issuing and securing digital signatures
and certificates.
• The Act requires companies to get consent from consumers before
collecting or using their personal information.
• With the Act in effect, individuals can seek compensation if their
personal data is damaged or misused by unauthorized parties.
• The Act allows the Government of India to criminalize cybercrime,
hacking, and spreading computer viruses.
• The Information Technology Act 2000 also established the Cyber
Appellate Tribunal to handle appeals against decisions made by
Adjudicating Officers.
• It includes provisions to protect critical information infrastructure, such
as communication networks and power grids.
Objectives of the Information Technology Act 2000
• Promote efficient electronic delivery of government services and digital
transactions between businesses and individuals.
• Impose penalties for cybercrimes like data theft, identity theft, and
cyberstalking to ensure a secure online environment.
• Establish rules to monitor cyber activities and electronic communications
and commerce.
• Encourage growth and foster innovation in the Indian IT/ITES sector.
Jurisdictional issues
• Jurisdictional issues in cyberspace refer to the complexities and
challenges in determining which laws, regulations and authorities
apply to activities conducted online, across different countries and
regions. Here are some key jurisdictional issues in cyberspace:
[Link] Nature of the Internet:
The internet crosses borders, making it hard to apply laws based
on geography.
[Link] Sovereignty vs. Global Connectivity:
Countries control their own laws, but the internet connects
everyone, so actions in one country can affect others.
[Link] Fragmentation:
Different countries have different laws on data protection, privacy,
and cybersecurity, causing confusion and difficulty in enforcing
laws across borders.
[Link] Reach:
Some countries apply their laws to actions done outside their
borders, which can lead to legal conflicts with other countries.
[Link] Localization:
Some countries require data to be stored within their borders,
which creates problems for global companies since the internet
doesn’t have borders.
[Link]-Border Data Flows:
The free flow of data between countries is crucial for businesses.
Restrictions can cause issues for global communication and trade.
[Link] and Law Enforcement:
Investigating cybercrimes that cross borders is difficult due to
differences in legal systems across countries.
[Link] Treaties and Agreements:
Global treaties and agreements are important to address
cybercrimes like hacking and fraud. Countries cooperate to
improve enforcement, investigations, and extradition.
[Link] and National Security Concerns:
Cyber threats can originate anywhere, challenging countries’
ability to respond. International collaboration is needed to address
these issues.
[Link] Sovereignty and Rights:
There are challenges in managing cyberspace while respecting
both national sovereignty and individual rights globally.
Digital signatures
Definition: A digital signature is a cryptographic method used to verify the
authenticity and integrity of a digital document or message.
It ensures that the sender is who they say they are and that the content hasn't
been altered during transmission.
Purpose:
-Integrity: They ensure that the document or data has not been tampered with
during transmission. Even a small change in the document would result in a
completely different signature.
- Non-repudiation: The sender cannot deny having signed the document, as
the signature is mathematically tied to their private key.
- Efficiency: Digital signatures are efficient and can be used to sign electronic
documents quickly and without the need for physical paperwork.
Uses of Digital Signature
• E-filling,
• E-tender and
• E-procurement
• Income Tax
• Sales Tax
• Patent and trade marks registration
• Oil & Natural Gas Corporation (ONGC)
How It Works:
• Key Pair: Involves a pair of keys: a private key (kept secret by the signer)
and a public key (shared with others).
• Signing Process: The sender creates a hash of the message and encrypts
it with their private key, creating the digital signature.
• Verification: The recipient decrypts the signature using the sender's
public key and compares the hash to verify authenticity.
Uses: Commonly used in e-commerce, email communication, software
distribution, and legal documents to ensure secure transactions.
Benefits:
• Ensures security and integrity of data.
• Prevents unauthorized access and forgery.
• Facilitates secure online transactions and communications.
Regulation of certifying authorities (CAs)
The regulation of certifying authorities (CAs) in cyber law ensures secure digital
communications and transactions. CAs issue digital certificates that verify
identities within public key infrastructure (PKI).
1. Legal Framework:
National laws like the US E-SIGN Act, EU eIDAS, and India's IT Act govern CA
operations.
International standards (ISO, ITU) guide security and operational practices for
CAs.
2. Licensing and Accreditation:
CAs must be licensed or accredited, meeting strict security, operational, and
financial requirements.
Regular compliance audits, often by government or third parties, ensure
adherence to regulations.
3. Operational Standards:
CAs implement strong security measures, key management, and incident
response to protect against breaches.
They operate transparently, publishing security practices and audit results to
maintain trust.
4. Liability and Accountability:
CAs are legally liable for issues like fraud or negligence related to digital
certificates, encouraging compliance.
Regulatory bodies can revoke or suspend a CA’s license for non-compliance or
security risks.
5. Cross-Border Recognition:
Countries often enter mutual recognition agreements (MRAs) to validate CAs
across borders, supporting international trade and transactions.
[Link] Rights and Protections:
Consumer Protection: Regulations protect users by requiring clear
terms, dispute resolution, and safeguards against fraud.
Data Privacy: Certifying Authorities (CAs) must follow data privacy
laws, protecting personal data during certification.
By following these rules, CAs help create a secure and trustworthy digital
environment for online services, e-commerce, and communications.
Cyber Regulation Appellate Tribunal (CRAT)
The Cyber Regulation Appellate Tribunal (CRAT) is a specialized judicial body
that handles disputes and appeals related to cyber laws, such as data
breaches, cyber fraud, and misuse of digital signatures.
Key aspects include:
1. Establishment and Jurisdiction:
Legal Basis: The CRAT is created through national laws, like India’s Cyber
Appellate Tribunal under the IT Act, 2000.
Scope of jurisdiction: It handles cases involving digital signatures, electronic
contracts, cybersecurity breaches, and IT regulatory decisions.
2. Structure and Composition:
Members and appointments: The tribunal includes a chairperson and
experts in law and IT, appointed by the government or relevant
authorities.
Technical and Legal Experts: The tribunal includes or consults technical
experts to analysis on complex cyber issues.
3. Functions and Powers
Hearing Appeals: CRAT hears appeals against decisions made by
regulatory bodies like cybersecurity agencies.
Dispute Resolution: It handles disputes related to cyber activities such as
unauthorized access, data breaches, and cyber fraud.
Enforcement: CRAT can enforce its rulings, including penalties, damages,
or corrective actions.
4. Procedure and Process
Filing Appeals: Parties can appeal decisions by submitting petitions,
supporting documents, and fees.
Hearings: Both sides present arguments, evidence, and expert opinions,
following a structured and fair process.
Decisions: CRAT may cancel previous orders, award compensation, or
issue specific corrective actions.
5. Role in Cyber Governance
Compliance: CRAT promotes adherence to cyber laws and standards.
Enhancing Trust: By resolving disputes fairly, it strengthens trust in the
digital ecosystem.
Human Rights Issues
1. Right to Privacy
Data Protection: Cyber laws must protect personal data from unauthorized
access by governments and companies.
Surveillance: Mass surveillance, often done for security reasons, can invade
privacy. Laws need to balance security and individual rights.
Consent and Control: People should control how their data is used, including
the right to give consent and request corrections or deletions.
2. Freedom of Expression
Censorship: Governments may use cyber laws to block websites, filter
content, or punish online speech, limiting free expression.
Platform Regulation: Social media regulation can impact freedom of
expression. While addressing hate speech and misinformation is
important, regulations should protect legitimate discourse and debate.
Whistleblowing: Cyber laws should protect whistleblowers who expose
wrongdoing, allowing them to communicate securely and anonymously
without fear of retaliation.
3. Access to Information
Digital Divide: Ensuring equitable internet access is a human rights issue.
Cyber laws should promote affordable and widespread internet access to
reduce social and economic inequality.
Information Censorship: Regulations must be transparent and fair to
prevent arbitrary censorship by governments or private entities.
4. Protection from Cybercrime
Cyber Harassment and Abuse: Laws should address online harassment,
including cyberbullying, stalking, and gender-based violence, ensuring
victims have access to justice.
Fraud and Identity Theft: Laws must protect individuals from
cybercrimes like fraud and identity theft.
Child Protection: Cyber laws should include measures to prevent online
child exploitation and the distribution of child sexual abuse material.
5. Due Process and Fair Trial
Legal Protections: Individuals accused of cybercrimes should have the
right to a fair trial, legal representation, and protection from arbitrary
punishment.
Transparency: Cyber laws and enforcement must be transparent with
safeguards to prevent abuse of power.
6. Digital Rights and Inclusion
Equality and Non-Discrimination: Cyber laws should protect digital
rights equally for all, regardless of race, gender, ethnicity, or
socioeconomic status.