Hash values and integrity verification.
Hash Values and Integrity Verification
1. Introduction
A hash value is a unique-looking digital value generated from electronic data by applying a mathematical algorithm known as a hash function. Hashing is widely used in cybersecurity, digital forensics, electronic discovery, document management, and legal proceedings to determine whether a digital file has been altered.
Integrity verification means checking whether electronic evidence or a digital document remains in the same state as when it was originally collected, stored, or produced.
For example, if a PDF file is collected during an investigation, investigators may calculate its SHA-256 hash value. If the same file later produces the same hash value, this provides strong evidence that the file has not changed.
2. Meaning of a Hash Value
A hash function converts data of arbitrary size into a fixed-length string of characters.
For example:
Document → Hash Algorithm → Hash Value
A small alteration to the document—such as changing one character—will ordinarily produce a substantially different hash value.
Common hashing algorithms include:
- MD5
- SHA-1
- SHA-256
- SHA-512
For modern evidence-handling purposes, SHA-256 or stronger algorithms are generally preferable, particularly because MD5 and SHA-1 have known collision weaknesses.
3. Hashing Is Not Encryption
Hashing and encryption are different.
| Hashing | Encryption |
|---|---|
| Primarily used to verify integrity | Primarily used to protect confidentiality |
| Normally one-way | Designed to be reversible with the appropriate key |
| Produces a fixed-length digest | Produces encrypted/ciphertext data |
| Useful for evidence verification | Useful for secure communication/storage |
Therefore, a hash value does not by itself prove that the underlying information is confidential.
4. Importance in Digital Evidence
Digital evidence can be easily copied, transferred, edited, renamed, compressed, or otherwise manipulated.
Hash values help investigators demonstrate that:
- the original electronic file was identified;
- the evidence was acquired;
- its hash was calculated;
- the evidence was preserved;
- subsequent copies correspond to the original;
- the evidence has not been altered during handling.
This makes hashing an important part of digital chain of custody.
5. Hash Values and Chain of Custody
A proper chain of custody records the movement and handling of evidence from collection to presentation.
For digital evidence, a record may contain:
- case/reference number;
- date and time of acquisition;
- device or source;
- person who collected the evidence;
- acquisition method;
- hash algorithm;
- original hash value;
- subsequent verification hashes;
- storage location;
- persons accessing the evidence;
- dates of transfers;
- forensic software/hardware used.
The hash value acts as a digital fingerprint for the relevant data.
6. Integrity Verification Process
A basic forensic process may operate as follows:
Step 1: Identify the Evidence
The investigator identifies the relevant:
- computer;
- mobile phone;
- hard drive;
- email;
- PDF;
- photograph;
- database;
- cloud file;
- log file.
Step 2: Forensic Acquisition
Where appropriate, the investigator creates a forensic image or otherwise obtains the relevant data using a documented procedure.
Step 3: Calculate the Hash
A cryptographic hash is calculated for the acquired data.
Step 4: Preserve the Original
The original evidence should be protected against alteration.
Step 5: Work on a Copy
Investigators ordinarily analyse a forensic copy rather than unnecessarily manipulating the original evidence.
Step 6: Recalculate the Hash
At relevant stages, the hash can be recalculated.
Step 7: Compare the Values
If the relevant hash values match, this supports the proposition that the data has remained unchanged.
7. Hash Matching and Its Evidentiary Meaning
A matching hash value provides strong technical evidence of data integrity, but it does not automatically establish every fact about the evidence.
For example, a matching hash can help establish that:
"This copy contains the same digital content as the previously hashed file."
It does not necessarily establish:
"The person accused of creating the document actually created it."
Questions of authorship, ownership, possession, attribution, and authenticity may require additional evidence.
8. Hash Values in Indian Evidence Law
Electronic evidence in India is governed principally by the Bharatiya Sakshya Adhiniyam, 2023 (BSA), which replaced the Indian Evidence Act, 1872.
The legal framework recognises electronic and digital records as evidence, subject to applicable statutory requirements.
Hash values can be relevant because they help demonstrate that an electronic record produced before a court corresponds to the data originally acquired or preserved.
However, a hash value should not be treated as a substitute for every statutory requirement concerning admissibility or proof of electronic records.
9. Important Case Laws
1. Anvar P.V. v. P.K. Basheer, (2014) 10 SCC 473
The Supreme Court laid down important principles concerning the admissibility of electronic evidence under the then-existing Section 65B of the Indian Evidence Act.
The Court emphasised compliance with the statutory requirements for electronic records.
Relevance to integrity verification: Technical evidence such as hash values can support the identification and preservation of electronic material, but technical integrity does not by itself eliminate statutory requirements concerning admissibility.
Principle: Electronic evidence must satisfy the applicable evidentiary framework; authenticity and integrity cannot simply be assumed.
2. Arjun Panditrao Khotkar v. Kailash Kushanrao Gorantyal, (2020) 7 SCC 1
The Supreme Court reaffirmed and clarified the principles governing electronic evidence and Section 65B of the Evidence Act.
The Court recognised the importance of proper certification and procedural compliance when electronic records are produced.
Relevance to hashing: A hash value can strengthen the technical demonstration that an electronic record has remained unchanged, but it should be considered alongside the statutory requirements for proving electronic evidence.
Principle: Reliability of electronic evidence involves both technical integrity and compliance with the applicable evidentiary law.
3. Tomaso Bruno v. State of Uttar Pradesh, (2015) 7 SCC 178
The Supreme Court recognised the increasing importance of electronic evidence in criminal investigations and proceedings.
The case concerned the significance of electronic material, including CCTV evidence, and the duty to properly consider relevant electronic evidence.
Relevance to integrity verification: Where electronic evidence is relied upon, proper preservation and handling become important to ensure that the evidence presented corresponds to the original material.
Principle: Modern investigations must appropriately consider reliable electronic evidence rather than relying exclusively on traditional forms of evidence.
4. Sonu @ Amar v. State of Haryana, (2017) 8 SCC 570
The Supreme Court considered issues concerning the admissibility and proof of electronic evidence under Section 65B.
The case illustrates that objections concerning electronic evidence may involve questions of procedure and timing as well as substantive reliability.
Relevance to hash values: A properly documented technical process, including preservation and integrity verification, can assist in demonstrating reliability, although hashing alone does not determine admissibility.
Principle: Electronic evidence must be handled and proved in accordance with the applicable evidentiary requirements.
5. Shafhi Mohammad v. State of Himachal Pradesh, (2018) 2 SCC 801
The Supreme Court considered the difficulties surrounding production and certification of electronic evidence.
Although aspects of the decision were subsequently clarified by the Constitution Bench in Arjun Panditrao Khotkar, the case remains relevant to the development of Indian electronic-evidence jurisprudence.
Relevance: The case demonstrates the importance of practical access to electronic evidence and the procedural mechanisms through which its authenticity can be established.
6. State (NCT of Delhi) v. Navjot Sandhu, (2005) 11 SCC 600
The Supreme Court dealt extensively with electronic records in the context of the then-existing evidentiary framework.
The case is historically significant in the development of Indian jurisprudence concerning electronic evidence.
Relevance to integrity: Electronic material must be connected with reliable methods of proving its authenticity and evidentiary value.
The later decision in Anvar P.V. substantially changed the approach to the statutory certification requirements.
7. Dharambir v. Central Bureau of Investigation, 148 (2008) DLT 289
The Delhi High Court considered issues relating to computer-generated evidence and forensic examination.
The case is relevant to the treatment of electronic material and the importance of preserving the integrity of computer data.
Principle: Digital evidence requires appropriate technical and evidentiary safeguards because electronic information can potentially be altered without obvious physical signs.
8. Rakesh Kumar Singha v. State of Himachal Pradesh
Indian courts have repeatedly recognised the importance of establishing the authenticity and reliability of electronic records when digital material is relied upon.
The broader principle is that courts should examine the provenance, preservation, authenticity and reliability of electronic evidence rather than assuming that every digital record is automatically genuine.
10. Hash Values in Employment and Workplace Investigations
Hash values are particularly useful in employment disputes involving:
- emails;
- attendance records;
- HR databases;
- disciplinary records;
- CCTV footage;
- employee complaints;
- WhatsApp exports;
- company laptops;
- access logs;
- payroll records;
- cloud documents;
- confidential files.
For example, suppose an employee is accused of deleting confidential company information.
The investigator can:
- preserve the relevant device/data;
- create a forensic copy;
- calculate its SHA-256 hash;
- record the hash in the investigation file;
- analyse the copy;
- preserve the original;
- verify the hash when required.
This creates a documented technical basis for demonstrating that the analysed evidence corresponds to the preserved evidence.
11. Hashing and Disciplinary Proceedings
In disciplinary proceedings, an employer should be careful not to assume that a matching hash automatically proves misconduct.
For example:
Hash proves:
The digital file examined is materially identical to the hashed file.
Hash does not necessarily prove:
Who created the file, who accessed it, who deleted it, or why it was created.
Those facts may require:
- access logs;
- authentication records;
- CCTV;
- email headers;
- system logs;
- witness testimony;
- device attribution;
- forensic analysis.
Thus, hashing is a supporting integrity mechanism, not a complete substitute for an investigation.
12. Limitations of Hash Values
A. Hash Collision
A collision occurs when two different inputs produce the same hash value.
Modern cryptographic practice therefore favours stronger algorithms such as SHA-256 over obsolete algorithms such as MD5 and SHA-1 for important integrity applications.
B. Hash Does Not Establish Authorship
A hash verifies data correspondence, not human identity.
C. Hash Does Not Prove Originality
A matching hash indicates that two datasets match; it does not independently prove which one was historically created first.
D. Poor Documentation Reduces Evidentiary Value
If investigators cannot explain:
- how the evidence was acquired;
- which algorithm was used;
- when the hash was calculated;
- where the evidence was stored;
the technical evidence may become less persuasive.
E. Hashing the Wrong Material
If the wrong file or altered source is hashed at the beginning, a matching hash later does not cure the original problem.
13. Best Practices
Organisations handling electronic evidence should:
- use a recognised cryptographic hash algorithm;
- preferably use SHA-256 or stronger for important evidence;
- document the acquisition process;
- record date and time;
- record the identity of the person collecting the evidence;
- preserve the original evidence;
- create forensic copies where appropriate;
- calculate and record hashes at relevant stages;
- maintain an auditable chain of custody;
- restrict access to preserved evidence;
- document every transfer;
- use reliable forensic tools;
- preserve relevant metadata;
- ensure that evidence is not unnecessarily modified;
- combine hash verification with other authentication evidence.
14. Example
Suppose an employee's company laptop contains a spreadsheet allegedly showing unauthorised manipulation of salary records.
The investigator creates a forensic copy and calculates:
SHA-256:
A1B2C3...XYZ
The same hash is recorded in the investigation report.
Later, before the disciplinary authority examines the evidence, the investigator recalculates the hash.
If the value remains identical, it supports the conclusion that the digital copy has not changed since the earlier hashing event.
But the investigator must still establish:
- how the laptop was obtained;
- who had access to it;
- whether the employee used the relevant account;
- when the spreadsheet was modified;
- whether system logs corroborate the allegation;
- whether the employee had authorisation to make the changes.
Therefore:
Hash = integrity evidence
Forensic logs + metadata + access records = attribution/context
Witnesses/documents = corroboration
15. Conclusion
Hash values are an important technical mechanism for integrity verification of electronic and digital evidence. They enable investigators, organisations and courts to compare digital data and determine whether the data has remained unchanged between documented stages of handling.
However, a hash value should not be misunderstood as a complete proof of authenticity, authorship or culpability. Its strongest legal value arises when it forms part of a properly documented chain of custody, supported by reliable acquisition procedures, appropriate forensic methods, statutory compliance and corroborating evidence.
In employment and disciplinary investigations especially, the safest approach is to treat hashing as a technical safeguard supporting the reliability of electronic evidence, while separately establishing the facts that connect the evidence to the alleged misconduct.

comments