TIOL-DDT 1365 · Monday, 24 May 2010 · story 1 of 2

E - Filing? - Alertness in slumber is better than intellectual inaction

-19 05 2010, we tried to explain the security features of the e-filing of Income Tax returns and the absence of digital signature in the CBEC website. The DDT feature was based on what little information I could collect from different sources, but we wanted a more authentic and authoritatively technical write up on the subject.

This is what I got from an expert on the subject.

CBDT appears to be alert even in their slumber. Reports in a section of media that e-filing of IT returns is suspended temporarily testify their slumber as well as their alertness. Instead of making efforts to renew the certificate well in advance before its validity expired, they started efforts to renew it only after its expiry. However, we should appreciate them that they have informed public about suspension of e-filing facility. Their quick and responsible efforts resulted in fast renewal of their digital certificate on 17th May, even before publication of the news (press note) of suspension in the media.

In contrast, their sister Board CBEC happily immersed in deep sleep and continues to do so. Although it was accepting e-filing of returns for a long time, it never thought of securing its e-filing websites with trusted technology that is available. This, in spite of the fact, that the CBEC itself was a Certifying Authority. While many Government organisations like CBDT, CBEC, DGFT, RoC , etc., have advised / mandated their assessees / users to use digital signatures to communicate electronic documents, none of them except CBEC was given Certifying Authority licence by the Controller of Certifying Authorities. Surprisingly, all the organisations except CBEC are accepting digitally signed documents. CBEC has never given serious thought to securing its systems and transactions in spite of serious frauds like drawback embezzlement. Had it mandated use of digital signatures in electronic transactions, these frauds would not have taken place. When the CA licence was granted to it way back in 2004, everybody thought that there would be a great transformation in its electronic transactions by mandating digital signatures for all its staff and assessees.

Digital Certificates are issued by the licenced Certifying Authorities to individuals as well as Web servers. Webserver having a Digital certificate is secure in its communication. Users' 'Request' that goes to and the 'Response' that comes from the webserver is encrypted and cannot be seen by the third parties, even if it is picked up by them. When a user inputs certain data, e.g., user name / password that data is encrypted before it leaves the user's computer and reaches the webserver where it is decrypted. After completion of the verification process and recognition of the user as a genuine one, the webserver responds by sending the required data in an encrypted format again. This encryption / decryption depends on the algorithm contained in the digital certificate. The web browser understands this processes and helps in display of decrypted content on the user's desktop.

Digital certificates are issued for a specific period and after expiry of the certificate, this encryption / decryption process does not happen and the content is communicated in the unencrypted format making it easy for any spoofers to pick up and modify the data.

While various Departmental formations in CBEC which are part of ACES project are connected by MPLS and VPN connectivity, assessees have to access the ACES website through normal internet connectivity only. Their data moves in unsecured communication lines and is absolutely prone to spoofing. As per the existing instructions, users need not digitally sign the electronic documents. It is not clear whether this is an omission on the part of the project consultants or lack of understanding on the part of the top management of the Systems Directorate that the e-filed documents are accepted without any authenticity.

There are some officers who are complacent that the user name and password given to the assessees provide sufficient authenticity to the electronic documents. It is not correct. The user name and password just authorise the users to access the ACES website. They do not serve the purpose of achieving authenticity of electronic documents, integrity of data transmitted and subsequent non-repudiation on the part of the sender of the data.

Those who filed Income Tax returns online are well aware of the security measures taken by CBDT. If the assessee appends his digital signature, well and good. If he does not have digital signature, he has to generate a one-page acknowledgement and send the same to the Central Processing Unit after duly appending his physical signature. In order to rebuff any future repudiation by the assessee, the department has taken a wonderful care by way of printing on the acknowledgement the IP address of the system on which the acknowledgement was generated. When CBDT is working with perfect planning as far as online filing is concerned, CBEC is giving scant importance to it.

If anybody gives a glance at Central Excise Circular No. 919, dated 23rd March, 2010, these things are elaborately clear. They have categorically clarified in the circular that wherever the returns are submitted through ACES there will not be any requirement to submit signed hard copy separately. Surprisingly, the circular asks the new assessee seeking registrations in Central Excise and Service Tax to submit to the jurisdictional Range officer, a printout of the application form submitted online duly signed by the authorized signatory. Board feels that authenticity is required in case of application for Registration while it is not required for the periodical return in which quantities, values and duties are declared. One is at loss to understand this philosophy as to why the Board is asking for signed copy of the Regn application when there is the concept of physical verification by the Range Officer, while asking assessees not to file physical copies of the returns file electronically. In fact physical signed copies of the returns like ER-1, ST-3, etc., are required as these are the basis on which any demands are raised. What will happen to the Board if any intelligent assessee subsequently repudiates his return? What evidence will be produced before the court of law to prove the authenticity of electronic transactions?

It is understood that the original design of ACES was to have a button on all the screens to 'SIGN & SUBMIT' enabling the user (either assessee or officer) to digitally sign the electronic document before submitting it. Due to inability of the Directorate to implement it, now the button contains only 'SUBMIT'. The Board should immediately plan to accept the digital signatures obtained from other CAs or draw a scheme to obtain simple signed acknowledgements from the assessees in token of filing of the returns as is being done by CBDT.

CBEC is the only Certifying Authority in India that was closed without using / renewing the licence granted to it. CA licence was granted to CBEC by the Controller of Certifying Authority on 9th December, 2004 for a period of 5 years and the licence expired on 18th January, 2010. Since the certificate was not renewed, the CCA revoked the CA licence on 19th January, 2010 for the reason of 'Cessation of Operation'

While the Directorate of Systems pushed a number of communications in the beginning about the certifying authority licence, formation of Registration Authorities and asking Commissioners to form Verification Authorities in all the Commissionerates, it was conspicuously silent when the licence expired and CA was closed. If the Board felt that there is no need for the iCERT CA (Certifying Authority of CBEC), they should have at least informed the field formations about it. What will be the Board's response if any Commissionerate accepts the application for digital signature from an assessee, basing on the instructions given in the beginning? None of the field formations have the knowledge of closure of iCERT CA.

They have simply issued a small press note about the closure and kept quiet. In fact, this press note is conspicuously not available anywhere in CBEC website or icegate website. However, it is available on the website of Controller of Certifying Authorities.

(http://cca.gov.in/rw/resource/ICert%20Press%20Note.pdf?download=true).

In fact, ICEGATE website still provides a link to https://icert.gov.in website (website of the CBEC certifying authority) closed long ago. If the Board is not in a position to renew its CA licence and issue digital signatures, it should at least advise the assessees to obtain it from any of the Certifying Authorities and use it for filing returns online.

There should be a probe into all these security aspects: Why the CA licence has not been made use of? Is it due to lack of technical know-how or lack of proper infrastructure? If there is paucity of technical-know how or infrastructure, what was the Directorate doing all these more than five years? Will the Board continues to accept the returns online without any authenticity? What is its plan in case of repudiation by the assessees? Is there any plan to provide a secure communication channel to the assessees? Is there any plan to avoid frauds like Drawback frauds, other than issuing simple letters to field formations to secure passwords?

It is not difficult to find out whether the website is running on a secure webserver or not, whether its digital certificate is valid or not. When the user tries to access a website, especially an e-commerce website, if the site's digital certificate is valid, the address bar of the web browser (Internet Explorer) as well as the security status bar on its right side appear in green colour and it means that the communication between your computer and the webserver is encrypted and that the Authority who has issued certificate confirms that the website is owned / run by a business that is legally organised . If it is in red colour , it means that the certificate is invalid or out of date or revoked. If it is in yellow, it means that the authenticity of the certificate cannot be verified as there is a problem in accessing the website of the certification authority which issued the certificate. Additionally, websites like those of Banks, e-commerce websites, etc., run on secure protocol which is represented by 'https' in the beginning of the URL, instead of 'http'. While home pages of most of these URLs start with 'http', 'https' is visible only after login. Certificate's status can also be viewed by clicking on the lock image in the security status bar.

cited in this story