This article was originally written as an academic paper and is republished here as a knowledge-sharing resource. It has been lightly formatted; statutory references reflect the law as it stood at the time of writing.
Raj Deepak Chaudhary, Research Scholar & Dr Nitesh Srivastava, Asst. Prof.
School of Legal Studies, Babu Banarsi Das University (BBDU)
Raj95chaudhary@gmail.com, Niteshyes@bbdu.ac.in
Abstract-
In the context of today’s digital economy, data security has emerged as a critical priority across all sectors. With the escalating frequency and severity of cybercrimes, there is an urgent need to reform the criminal justice system to address these challenges effectively. The lack of coherent legal frameworks governing digital forensics and the admissibility of digital evidence has inadvertently created a permissive environment for cyber criminals. This research paper examines contemporary methodologies and tools utilized in digital forensics, alongside an exploration of the privacy implications associated with digital evidence. Additionally, it seeks to identify prospective solutions by analysing current trends, judicial rulings, and relevant legislation within this rapidly evolving landscape.
Index Terms- Digital Evidence, Digital Forensics tools, Data Security, Indian Laws, Privacy Solutions.
Introduction
A civilised society is built on the foundation of the rule of law; any offence against it is punishable by the established criminal justice system. To remain civilised, free and fair, independent and objective investigation of crime is essential. Collecting evidence has always been a crucial part of this investigation. While the collection and use of physical evidence have been refined over the centuries, the collection and application of digital evidence in criminal investigations have emerged only in the last century due to the rapid proliferation of electronic devices (computing and GPS devices, internet, smartphones, smartwatches, cloud storage and social media) in every aspect of life. Also, valuable information about crimes and the behaviour of suspects can be found in his digital footprint.
This widespread and obsessive dependence on technology has compelled the courts and law enforcement agencies to integrate digital evidence into their proceedings. However, the challenges regarding the authenticity, admissibility, and reliability of digital evidence have persisted, leaving a gap in the effectiveness of the criminal justice system. Therefore, there is a need for a robust framework to collect, preserve, and analyse digital evidence and the adoption of international standards to ensure uniformity in digital forensics in India so that confidence in the judicial system remains firm.
Digital Forensics
According to the definition given by Mr. Gary Palmer, MITRE Corporation Cyberforensics Science & Technology Center at the very first Digital Forensics Research Workshop (DFRWS) Conference, digital forensics includes “the use of scientifically derived and proven methods towards the preservation, collection, validation, identification, analysis, interpretation, and presentation of digital evidence derived from digital sources for the purposes of facilitating or furthering the reconstruction of events found to be criminal or helping to anticipate the unauthorised actions shown to be disruptive to planned operations”. Simply put, in digital forensic investigation, a digital forensic investigator attempts to collect and analyse all digital evidence related to a crime at hand.
During this process, in addition to potential evidentiary files, the seized storage media may also contain private data belonging to the owner, such as personal photographs, videos, business plans, email, medical records, financial documents etc. Thereby raising a significant threat to the data privacy of the accused/offender as no well-defined rules or guidelines exist to assist an investigator in deciding which files are relevant to the investigation. Hence, the fate of the privacy of the person being investigated rests in the hands of the investigator, which has often been found to be overlooked for the sole reason of the criminal nature of the purpose of the investigation. Therefore, clear law & legal assistance is necessary to safeguard the data privacy of suspects and victims during investigations and subsequent court proceedings.
Law Relating To Digital Evidence In India
As there is no clear law/ rule or regulation regarding the collection of digital evidence, therefore, with its usage in judicial proceedings, and various legal and ethical concerns about privacy, the possibility of tampering/ manipulation has also cropped up, from time to time. Thus, the legal system must evolve to strike a balance between the individual right to privacy and the successful use of digital data in criminal investigations. In the year 2000, the Information Technology Act (IT Act) modelled after the UNCITRAL Model Law on Electronic Commerce was passed to modernise the country’s legal structure, recognise electronic transactions and accommodate digital evidence.
Indian Evidence Act,
Section 3 of the Evidence Act of 1872 provides for the definition of “Evidence” means and includes – (1) all statements which the court permits or requires to be made before it by witnesses, in relation to matters of fact under inquiry; such statements are called oral evidence; (2) all documents in including electronic records produced for inspection of the Court; such documents are called documentary evidence. The phrase ‘including electronic records’ was added by Amendment Act of 2000 w.e.f. 17.10.2000. In State of Maharashtra v. Dr. Praful B. Desai 2003 (4) SCC 601, it was held that the term “evidence” in the Indian Evidence Act was broad enough to include electronic evidence. As per section 2(t) of the Information Technology Act, 2000, “electronic record” means data, record or data generated, image or sound stored, received or sent in an electronic form or micro film or computer generated micro fiche. The same definition has also been adopted under section 29-A of the Indian Penal Code, 1860. Whereas the term “data” has been defined under section 2(o) means a representation of information, knowledge, facts, concepts, or instructions which are being prepared or have been prepared in a formalised manner, and is intended to be processed, is being processed or has been processed in a computer system or computer network, and maybe in any form (including computer printouts, magnetic or optical storage, media, punched cards, punched tapes) or stored internally in the memory of the computer. Also, section 2(v) defines “information” includes data, message, text, images, sound, voice, codes, computer programmes, software and data bases or micro film or computer generated micro fiche; A combined reading of all the definitions establishes that any form of electronic data can be used as documentary evidence in criminal investigation. A new section, 22-A, was also added by the 2000 Amendment to address the issue regarding the relevancy of oral admission as to the content of electronic records, the section states that, unless the genuineness of the electronic record produced is in question, oral admission as to the contents of electronic records are not relevant. Section 39 provides that whenever any evidence is a digital record, the court should allow just the part of the record necessary to examine the nature, effect, and situations of the statement. Section 65-A states that the contents of electronic records may be proved in accordance with the provisions of Section 65–B.
According to section 65-B, Computer Output i.e., any information contained in the electronic record, which is printed on paper, stored, recorded or copied in optical or magnetic media produced by the computer is deemed to be documented and without further proof or production of original, the same shall be admissible in any proceeding, if the conditions provided in sub-section 65-B(2) are fulfilled, namely:
Computer output containing the information was produced by the computer in the period in which the computer was used regularly to store or process information for the purpose of any activities by the person having lawful control over the use of the computer.
During the said period, the information so derived was regularly fed into the computer in the ordinary course of said activities.
Throughout the material part of said period, the computer was operating properly or if was not operating properly then the accuracy of the content of the electronic record has not been affected.
The information contained in the electronic record reproduces or is derived from such information fed into the computer in the ordinary course of the said activities.
Sub-section 65-B (3) states that when the function of storing or processing information for the purpose of activities, regularly carried on was regularly performed by computers, whether in combination or different computers, operating in succession or any other manner, then all the computers used for that purpose during that period shall be treated for the purpose of this section as a single computer.
Sub-section 65-B (4) states that where it is desired to give a statement in evidence by virtue of this section, a certificate identifying the electronic record containing the statement or describing the manner in which it was produced with such particulars of device involved in the production of that record to show that the electronic record was produced by a computer to be signed by a person occupying a responsible official position in relation to the operation of relevant device or management of relevant activities shall be evidence.
Before admitting digital evidence, the court must determine its relevance, truthfulness, and authenticity. Additionally, the evidence must satisfy three key legal requirements: authenticity, reliability, and integrity. Section 65-B (4) of the Indian Evidence Act mandates a certificate for demonstrating the authenticity of electronic evidence. The certificate must confirm that the electronic record is genuine and offer information regarding the computer system used. If the procedural norms specified in Section 65-B are not adhered to, the electronic evidence will be rejected. In the landmark case of Anvar P.V. v. P.K. Basheer (2014) 10 SCC 473 the Supreme Court ruled that digital evidence, such as emails and phone records, must strictly comply with the procedural requirements of Section 65-B for it to be admissible in court, however, in the case of Shafi Mohammad v. State of Himachal Pradesh (2018) 2 SCC 801, it has been held that the requirement of certificate under section 65–B (4) being procedural, can be relaxed by the court wherever interest of justice, so justify. In Arjun Panditrao Khotkar v. Kailash Kushanrao Gorantyal AIR 2020 SC 4908, the Supreme Court reaffirmed the necessity of producing the certificate under Section 65B(4) to admit any electronic evidence. The judgment held that the certificate is mandatory unless it can be conclusively proven that obtaining it is impossible or impractical. Thus, the requirement of a certificate is not always mandatory.
Proviso to section 79A of the Information Technology (Amendment) Act of 2008 states that “electronic form evidence” means any information of probative value that is either stored or transmitted in electronic form and includes computer evidence, digital audio, digital video, cell phone and digital fax machines.
When in a proceeding, the court has to form an opinion on any matter relating to any information transmitted or stored in any computer resource or any other electronic or digital form, the opinion of the Examiner of Electronic Evidence referred to in section 79A of the IT Act, 2000 is a relevant fact. This section corresponds to the section 45-A of the Indian Evidence Act.
Bharatiya Sakshya Sanhita,
The Indian Evidence Act of 1872 was revised and was renamed Bharatiya Sakshya Sanhita (BSS) of 2023 to accommodate the inclusion of digital evidence, reflecting the increasing importance of technological advancements in legal proceedings. Key provisions under the BSS related to digital evidence include:
Digital Documentation and Contracts: The acceptability of digital signatures and electronic agreements as admissible evidence has been firmly established, facilitating the legitimacy of business transactions and electronic communications within judicial proceedings.
Authenticity and Admissibility of Electronic Records: Echoing Section 65B of the Indian Evidence Act, the BSS reinforces the necessity for certification in the authentication of digital evidence. However, it introduces modernized regulations that afford increased flexibility, particularly in situations where obtaining such certificates is problematic.
Focus on Cybercrime: In response to the rising prevalence of cybercrime, the BSS enhances the protocols for managing electronic evidence. It delineates explicit procedures for the collection, preservation, and presentation of digital evidence, ensuring the integrity and authenticity of the material are maintained throughout the legal process.
Streamlined Procedure for Digital Evidence in Court: The BSS introduces an updated framework for the submission and evaluation of digital evidence in court settings. This includes rigorous measures designed to thwart data tampering, hacking, or forgery, thereby safeguarding the integrity of the evidence.
Chain of Custody and Forensics: The BSS emphasizes the critical importance of maintaining an unassailable chain of custody for digital evidence. This ensures that both the provenance of the evidence and the protocols employed for its collection can be meticulously verified, reinforcing its reliability in a legal context.
The provisions of the Bharatiya Sakshya Adhiniyam, 2023, are aligned with those of the Indian Evidence Act of 1872. In all proceedings, whether civil or criminal, Section 63 mandates the submission of a certificate accompanying the electronic record.
The schedule of the Bharatiya Sakshya Adhiniyam, 2023, delineates the required format for this certificate. In this format, the expert is obliged to specify the hash value of the electronic or digital record as well as the algorithm used to obtain it. The hash value serves as a unique numeric representation of the file or data's contents. By comparing the hash value of the received data to that of the original data, one can ascertain if any alterations have occurred. Notably, SHA-256 is recognized as the standard algorithm recommended and officially approved by the National Institute of Standards and Technology.
Section 66 stipulates that an electronic signature must be demonstrated to be the signature of any subscriber who has affixed it to an electronic record, except in cases involving a secure electronic signature. Section 73 permits the Court to direct the individual, or the Controller or Certifying Authority, to produce the Digital Signature Certificate to verify that the digital signature purportedly affixed belongs to the stated individual, utilizing the public key detailed in the Certificate.
The Explanation of Section 81 clarifies that electronic records are considered to be in proper custody if they are maintained in the designated location and overseen by the individual responsible for their retention. Furthermore, no custody shall be deemed improper if its legitimate origin is established, or if the specific circumstances of the case are such as to render the origin probable.
Section 87 establishes a presumption regarding the accuracy of the information contained within an Electronic Signature Certificate, with the exception of subscriber information that has not been verified, provided that the certificate has been accepted by the subscriber unless evidence to the contrary is presented.
Section 90 establishes a presumption concerning an electronic message that has been forwarded by the originator via an electronic mail server to the intended addressee; it is assumed to correspond with the message as entered into the sender's computer for transmission. However, the Court is not to presume the identity of the individual responsible for sending such a message and Section 93 creates a presumption related to electronic records that are purporting to be or have been confirmed as five years old; when such records are produced from a custody deemed appropriate by the Court in a particular case, the Court may presume that the electronic signature, which appears to be that of a specified individual, was duly affixed by said individual or by an authorized representative.
Judicial View On Digital Evidence & Data Security
In Byju B.R v. State Of Kerala, Krishnaprasad. R v. State of Kerala on 29 January 2022 ruled that the prosecutor may access a suspect person’s mobile phone data in criminal proceedings without violating the right against self-incrimination. To justify its decision, the High Court cited the ruling from the Karnataka High Court in Virendra Khanna v. State of Karnataka and Others 2021 SCC Online Karnataka 5032 while accepting the binding the Supreme Court’s eleven-judge- bench ruling in State of Bombay v. Kathi Kalu Oghad AIR 1962 SC 1809 that approves of the verdict in M.P. Sharma v. Satish Chandra AIR 1954 SC 300.
In R. M. Malkani v State of Maharashtra AIR 1973 SC 157, police evidence was stolen, yet the court nevertheless accepted it. Despite the accuser’s contention that it is unlawful to interfere with telephone transmission, the Supreme Court ruled that the evidence may be admitted into court.
In Selvi v. State of Karnataka, 2010 (7) SCC 263 it has been held that the purpose of Article 20(3) read with Article 20(1) has been to safeguard a suspect’s mental secrecy. Since the provision of a passcode requires the accused to reveal private information, this practice is prohibited under Indian law. Although the Court may order fingerprints to be provided, it is within its discretion to disregard fingerprints as a “functional equivalent” of a password in making its determination.
In Mohd. Ajmal Mohammad Amir Kasab vs. State of Maharashtra, (2012) 9 SCC 1 production of transcripts of internet transactions helped the prosecution case a great deal in proving the guilt of the accused. Similarly, in the case of State (NCT of Delhi) vs. Navjot Sandhu @ Afsan Guru, (2005) 11 SCC 600 the links between the slain terrorists and the masterminds of the attack were established only through phone call transcripts obtained from the mobile service providers.
Encroachment by the state to access the information stored in mobile phones is hit by Articles 20 (3) and 21. Forceful decryption of a mobile phone is it a password, or face ID would lead to the disclosure of a whole lot of incriminatory information which could be used against the accused.
The Kathi Kalu Oghad case is not well equipped to deal with present-era technology challenges hence the applicability of law should resonate with technological advancements argues Ms. Jyothi Abraham in ‘The Impact of the Use of Digital Forensic Evidence, with Specific Reference to the Right against Self-Incrimination in India’.
According to section 165 of the CrPC, the police do not require a warrant to conduct a search if doing so is essential to avoid the loss or falsification of significant evidence in a case, on 12 February 2021, two people posing as Delhi Police officers broke into the home of environmental activist Shantanu Muluk, a suspect in the “toolkit case,” in which the police allege that Muluk edited a Google doc on protest strategies in violation of the law.
When dealing with digital evidence, the problems become much more severe as the current search legislation presumes a simple procedure: when a warrant is granted (or is not necessary), officers enter the location to be searched and remove the desired items. The CrPC doesn’t account for the reality that seizing digital records entails two steps: first, a search of the device’s physical space to seize any digital hardware; next, a search of the device’s electronic space to find any data that is when often the security of the private data of the suspect is breached.
In Tomaso Bruno v. State of Uttar Pradesh 2015 (7) SCC 178, the importance of digital evidence, particularly in cases where there is no direct witness testimony was highlighted. The court emphasized that digital evidence, such as CCTV footage, can play a crucial role in criminal investigations and should be handled with care to ensure its admissibility and accuracy.
Current Tools And Techniques
Digital forensics utilizes specialized tools and methodologies to uncover digital evidence. These instruments facilitate the secure acquisition, preservation, and analysis of such evidence. Through a forensically compliant process, investigators systematically gather digital information, conduct thorough analyses, and provide interpretations that can be utilized as evidence in legal proceedings. These tools collectively assist forensic examiners in acquiring and examining various forms of digital evidence, including emails, documents, chat logs, images, videos, and metadata, from digital devices and networks. Digital forensics employs specialized software tools for the purposes of data acquisition, analysis, and investigation. Among the most widely utilized tools in this field are:
Data Acquisition Tool: FTK Imager is used to create forensic images of storage devices. EnCase is a tool that allows the acquisition of digital evidence from various sources.
Data Analysis Tool: Autopsy is an open-source tool designed for comprehensive digital forensics analysis. X-Ways Forensics is a commercial tool used for advanced forensic analysis of digital evidence.
Network Forensics Tool: Wireshark is used to capture and analyse network traffic.
Memory Forensics Tool: Volatility is used to perform memory forensics analysis of running systems.
Mobile Device Forensics Tool: Cellebrite UFED is widely used for extracting data from mobile devices for forensic analysis.
Current Practices And Future Directions
In their paper titled “Data Privacy Perceptions About Digital Forensic Investigations In India”, Robin Verma, Jayaprakash, Govardhan Raj[1], and Gaurav Gupta conducted three surveys with stakeholders, including investigators, lawyers, and the general public, between 2013 and 2014. The survey responses reveal a lack of professional ethics among some investigators, insufficient legal support for lawyers to safeguard data privacy, and confusion among the general public regarding their data privacy rights. The results underscore the urgent need for a privacy-preserving digital forensic investigation framework. Accordingly, a simple yet efficient solution is proposed that protects privacy without impeding digital forensic investigations. Regarding accessing private files, six of the fifteen investigators reported that they viewed and copied private files related to the case being investigated, as well as files that were not linked to the case but appeared to be illegal or questionable. Four other investigators mentioned that they viewed and copied private files because these files were more likely to contain evidence relevant to the current case and to other potential cases. Four investigators noted that they had observed investigators at other laboratories copying non-malicious personal files belonging to entities under investigation. One investigator had not seen anyone copy such files; however, she did not see any issue with such copying. The remaining investigators had not witnessed any copying and felt that it was inappropriate. The survey findings reveal that individual privacy is jeopardized during digital forensic investigations, underscoring the critical necessity for the integration of robust data privacy protocols within the investigative framework. A comprehensive data privacy solution must safeguard the rights of the subjects under investigation without compromising the thoroughness of the inquiry or the integrity of the digital evidence collected. Additionally, it is imperative that such a solution also enhances investigator efficiency, ultimately streamlining the process to save time and reduce labour intensity.
Numerous researchers have sought to employ cryptographic methods to safeguard data privacy during digital forensic examinations. Law et al. [2] introduced a technique that encrypts data on an email server while simultaneously indexing keywords relevant to the case. The investigator provides keywords to the server administrator, who possesses the encryption keys and utilizes them to decrypt emails that contain the specified keywords, after which the emails are forwarded to the investigator.
Hou et al. [3] have suggested methods for securing data located at service provider storage facilities through the use of homomorphic, commutative encryption. These methods also ensure that the service provider remains unaware of the queries made by an investigator. Additionally, Hou et al. [4] offer a comparable solution for a remote server.
Shebaro and Crandall [5] have applied identity-based encryption to investigate network traffic data in a manner that preserves privacy. Gou et al. [6] have outlined generic privacy policies intended for network forensic investigations. Croft and Olivier [7] have introduced a method that categorizes data into varying levels of sensitivity, wherein less sensitive data is placed in the lower tiers and more sensitive data occupies the higher tiers. Access to confidential information by the investigator is managed by initially limiting entry to the lower tiers. The investigator must demonstrate their understanding and conduct in these lower tiers to gain access to the information located in the upper tiers.
Van Staden [8] has proposed a framework based on privacy-enhancing technology to protect the privacy of third parties during digital forensic investigations. (See Figure 1) This framework requires investigators to formulate precise queries when searching for possible evidence. It assesses whether the outcomes of a query might result in a privacy violation. Should a potential breach be identified, the investigator is prompted to submit a more specific query. If an investigator ignores the query results and attempts to access private information, the framework records the investigator’s actions securely.
The suggested data privacy approach by Van Staden does not affect the results of a digital forensic investigation. The privacy solution, illustrated in Figure 1, enhances transparency in the investigative process and boosts accountability among investigators.
The approach emphasizes the analysis stage of a digital forensic investigation, where an investigator examines images of the storage media from seized digital devices. Besides the images, the solution methodology incorporates two other inputs: the acquired knowledge from analogous cases housed in a case profile database and the particulars of the current case. The case profile database consists of a collection of specific features from various cases that can be utilized to forecast potential evidence for the case at hand. This database includes a feature list derived from the content and metadata of evidence files, as well as insights from investigator assessments gathered from past case studies. Choosing the feature list for the database necessitates taxonomic information regarding private data and files present on computer systems. All inputs are analysed by a forensic tool that maintains privacy while identifying pieces of evidence pertinent to the current case. This tool must ensure a thorough investigation. Although it may produce false positives, it must never generate a false negative. If the tool finds that the investigator’s query results breach privacy, the investigator has two choices. The first choice is to submit a new query that complies with privacy regulations. The second choice is to bypass the privacy-filtering feature and carry out the investigation in a traditional way; in this scenario, the tool records all the investigator’s actions in secure storage to avoid tampering. Thus, the tool introduces an additional layer of scrutiny without enhancing knowledge or efficiency.
The suggested privacy-preserving approach would not undermine the authority of the investigator; rather, it enhances accountability and transparency within the investigative process. The investigator would gain a better understanding of data privacy obligations, and their performance would remain unaffected.
Conclusion
The preservation and handling of digital evidence by law enforcement agencies, investigators, and the public is essential. Training should be provided to facilitate proper evidence collection and processing, in line with established standards. It is also important to educate citizens about the appropriate submission of evidence to authorities to maintain the integrity of digital evidence.
Bridging the gap between law to address the new challenges and opportunities through legislative adoptions of international standards. For example, the General Data Protection Regulation (GDPR) of the European Union (EU). While also providing education and training in increasing public awareness and fostering innovation.
For effectively competing with cybercrimes, collaboration regarding information sharing and conducting joint investigations by law enforcement agencies with technological companies who work in the data security sector is the need of the hour.
References
[1] Robin Verma, Jayaprakash Govindaraj, Gaurav Gupta. Data Privacy Perceptions About Digital Forensic Investigations in India. 12th IFIP International Conference on Digital Forensics (DF), Jan 2016, New Delhi, India. pp.25-45, 10.1007/978-3-319-46279-0_2. hal-01758694.
[2] F. Law, P. Chan, S. Yiu, K. Chow, M. Kwan, H. Tse and P. Lai, Protecting digital data privacy in computer forensic examinations, Proceedings of the Sixth International Workshop on Systematic Approaches to Digital Forensic Engineering, 2011.
[3] S. Hou, R. Sasaki, T. Uehara and S. Yiu, Verifying data authenticity and integrity in server-aided confidential forensic investigations, Proceedings of the International Conference on Information and Communication Technology, pp. 312–317, 2013.
[4] S. Hou, R. Sasaki, T. Uehara and S. Yiu, Verifying data authenticity and integrity in server-aided confidential forensic investigations, Proceedings of the International Conference on Information and Communication Technology, pp. 312–317, 2013. S. Hou, S. Yiu, T. Uehara and R. Sasaki, Application of secret sharing techniques in confidential forensic investigations, Proceedings of the Second International Conference on Cyber Security, Cyber Peace fare and Digital Forensics, pp. 69–76, 2013.
[5] B. Shebaro and J. Crandall, Privacy-preserving network flow recording, Digital Investigation, vol. 8(S), pp. S90–S100, 2011.
[6] H. Guo, B. Jin and D. Huang, Research and review in computer forensics, in Forensics in Telecommunications, Information and Multimedia, X. Lai, D. Gu, B. Jin, Y. Wang and H. Li (Eds.), Springer, Berlin Heidelberg, Germany, pp. 224–233, 2011.
[7] N. Croft and M. Olivier, Sequenced release of privacy-accurate information in a forensic investigation, Digital Investigation, vol. 7(1-2), pp. 95–101, 2010.
[8] W. Van Staden, Protecting third party privacy in digital forensic investigations, in Advances in Digital Forensics IX, G. Peterson and S. Shenoi (Eds.), Springer, Berlin Heidelberg, Germany, pp. 19–31, 2013.
When To Call Sarvā Nyāy
You do not have to work this out alone. A short first conversation tells you what to preserve, where to file and whether you need us at all. No obligation, no pressure.
Response within 24 hours · Advocate-client confidentiality · Lucknow
