Mastodon Mastodon Mastodon Mastodon

Digital Signature

Updated: · CyberSecureFox Editorial Team

A digital signature is a cryptographic mechanism that proves who created or approved a piece of data and that it has not been changed since it was signed.

How digital signatures work

Digital signatures use public-key cryptography. The signer calculates a hash of the document or file and transforms it with their private key; the result is the signature. Anyone can verify it with the matching public key: if the data was altered even by one bit, or if a different key was used, verification fails. Common algorithms are RSA, ECDSA and EdDSA; post-quantum alternatives such as ML-DSA were standardised by NIST in 2024.

To know whose public key it is, signatures rely on certificates issued by certificate authorities. Note that signing is not encryption: a signed message can still be readable by everyone.

Where digital signatures are used

  • Code signing – operating systems and app stores check signatures on software and drivers; updates are signed so that devices accept only genuine ones.
  • TLS and HTTPS – servers prove their identity during the handshake.
  • Email and documents – S/MIME, PGP and signed PDFs; in the EU, qualified electronic signatures under eIDAS have the same legal effect as handwritten ones.
  • Blockchain transactions and secure boot chains.

Why it matters for security

Signatures are the foundation of trust in software. That is why attackers steal code-signing keys: Stuxnet used drivers signed with certificates stolen from two Taiwanese hardware makers, and signed malware or compromised build systems are central to many supply chain attacks. Users also often ignore warnings about invalid signatures.

Best practices

  • Store signing keys in hardware security modules and limit who can use them.
  • Revoke compromised certificates immediately.
  • Verify signatures and checksums of downloaded software and updates.
Synonyms:
cryptographic signature