In India, the term "Public Key Infrastructure" is used in the context of

Updated 11 Apr 2026 · From UPSC Prelims GS Paper I 2020, Q103

Contents16
UPSC Prelims GS2020Science and Technology
  1. ADigital security infrastructure
  2. BFood security infrastructure
  3. CHealth care and education infrastructure
  4. DTelecommunication and transportation infrastructure
Show answer

Answer: (A) Digital security infrastructure

This is a straightforward factual question.

Public Key Infrastructure (PKI) is a system used for digital security.

It uses a pair of cryptographic keys — a public key and a private key — to verify the identity of users and devices online.

Think of it like a digital ID card system that ensures secure communication on the internet.

PKI has nothing to do with food security, healthcare, education, or telecom/transport infrastructure.

Answer: A (Digital security infrastructure).

Key Takeaway: PKI = digital security.

It's about encryption and authentication online.

Why this was asked

PKI uses paired cryptographic keys (public and private) to verify digital identities and secure online communications across government and banking systems.

Digital India initiatives and increasing cyber threats made PKI implementation a key policy focus around 2019-20, bringing this technical term into UPSC's scope.

Public Key Infrastructure (PKI)

Science And Technology Public Key Infrastructure

Public Key Infrastructure (PKI): Digital Security System

Must know

PKI uses public-private key pairs for digital security and authentication

Public key encrypts data, private key decrypts it - ensures secure communication

Good to know

PKI enables digital signatures and identity verification online

Used in HTTPS websites, email security, and digital certificates

What is PKI

Public Key Infrastructure (PKI) is a digital security framework that uses cryptographic key pairs to secure online communications. Think of it as a digital ID card system that proves who you are on the internet and keeps your data safe from hackers.

Key Components

Component

Function

Example

Public Key

Encrypts data, shared openly

Website's SSL certificate

Private Key

Decrypts data, kept secret

User's personal decryption key

Digital Certificate

Proves identity of key owner

Bank's verified certificate

Certificate Authority (CA)

Issues and validates certificates

VeriSign, DigiCert

How PKI Works

%%{init: {"flowchart": {"wrappingWidth": 460}}}%%
flowchart TD
  s1["`**User generates key pair**
Creates linked public and private keys`"]
  s2["`**Certificate Authority verifies identity**
CA checks user's credentials and issues digital certificate`"]
  s3["`**Public key shared openly**
Others use this key to encrypt messages to the user`"]
  s4["`**Private key decrypts messages**
Only the user can decrypt with their secret private key`"]
  s1 --> s2
  s2 --> s3
  s3 --> s4

Real-world Applications

HTTPS websites - the padlock icon shows PKI securing your browsing

Email encryption - ensures only intended recipient can read messages

Digital banking - authenticates transactions and protects financial data

Government portals - secures citizen data on official websites

E-commerce - protects credit card details during online shopping

Question Context

This UPSC question tested basic understanding of cybersecurity terminology. PKI is purely about digital security infrastructure - it has nothing to do with food, healthcare, education, or physical infrastructure like telecom/transport.

Exam traps

Don't confuse PKI with physical infrastructure - it's purely digital/cyber security

Telecommunication infrastructure is a distractor - PKI uses telecom networks but isn't telecom itself

Remember the key pair concept - public + private keys working together is PKI's core

Cryptographic Keys & Encryption

Science And Technology

Cryptographic Keys & Encryption Methods

Must know

Symmetric encryption uses same key for encryption and decryption

Asymmetric encryption uses different keys - public and private key pairs

Good to know

Digital signatures prove message authenticity and prevent tampering

Types of Encryption

Encryption converts readable data into coded form to prevent unauthorized access. There are two main approaches - symmetric (same key) and asymmetric (different keys), each with distinct advantages.

Symmetric vs Asymmetric

Aspect

Symmetric Encryption

Asymmetric Encryption

Keys Used

Same key for both operations

Public key + Private key pair

Speed

Fast processing

Slower due to complex math

Key Distribution

Difficult - must share secret key

Easy - public key shared openly

Use Case

Bulk data encryption

Secure key exchange, digital signatures

Example

AES, DES algorithms

RSA, PKI systems

Encryption Applications

# Cryptographic Encryption
## Data Protection
- File encryption
- Database security
- Cloud storage
## Communication Security
- HTTPS websites
- Email encryption
- Messaging apps
## Authentication
- Digital signatures
- Identity verification
- Access control
## Financial Security
- Online banking
- Digital payments
- Cryptocurrency

Digital Signatures Process

Sender uses their private key to sign the message

Receiver uses sender's public key to verify the signature

Tampering detection - any change in message breaks the signature

Non-repudiation - sender cannot deny sending the signed message

Exam traps

Don't mix up key types - public key encrypts, private key decrypts in PKI

Symmetric ≠ Asymmetric - symmetric uses same key, asymmetric uses key pairs

Digital signature uses reverse logic - private key signs, public key verifies

Cybersecurity Infrastructure in India

Science And Technology

India's Cybersecurity Infrastructure & Initiatives

Must know

CERT-In is India's nodal agency for cybersecurity incident response

National Cyber Security Strategy 2020 guides India's cyber defense approach

Good to know

Digital Personal Data Protection Act 2023 regulates data security

India's Cyber Landscape

With Digital India pushing online services, India faces growing cyber threats. The government has built a multi-layered cybersecurity infrastructure involving specialized agencies, policies, and technical frameworks.

Key Cybersecurity Bodies

Organization

Full Form

Primary Role

CERT-In

Computer Emergency Response Team

Incident response, threat analysis

NCSC

National Cyber Security Coordinator

Policy coordination, strategy

NTRO

National Technical Research Organisation

Cyber intelligence, surveillance

NIC

National Informatics Centre

Government IT infrastructure

Cybersecurity Challenges

# India's Cyber Threats
## Financial Crimes
- Banking frauds
- UPI scams
- Cryptocurrency theft
## State-Sponsored
- Cross-border attacks
- Critical infrastructure
- Data espionage
## Individual Targeting
- Identity theft
- Social media fraud
- Phishing attacks
## Business Impact
- Ransomware
- Data breaches
- Supply chain attacks

Recent Policy Developments

Digital Personal Data Protection Act 2023 - comprehensive data privacy law

National Cyber Security Strategy 2020 - 5-year roadmap for cyber defense

Cybercrime reporting portal - citizens can report cyber incidents online

Critical Information Infrastructure protection for essential services

Exam traps

CERT-In reports to MeitY (Ministry of Electronics & IT), not Home Ministry

Don't confuse NCSC with NSC - different cyber and security coordination bodies

Data Protection Act 2023 is separate from IT Act 2000 - both are relevant