Digital Signature
- In Turkish
- Dijital İmza
In short
A digital signature is a cryptographic value made with a private key that proves who produced a message or file and that it hasn't changed since it was signed.
What is a digital signature?
A digital signature does for data what a handwritten signature and a tamper-evident seal do for paper, but with mathematical guarantees. The signer uses their private key to produce a signature for a specific message, file, or software release. Anyone with the matching public key can verify the signature, which proves two things: the data came from the holder of the private key, and not a single bit has changed since it was signed.
Signing is built on public-key cryptography and hashing. The software typically computes a hash of the data, a short fingerprint, and applies the private key to that hash to produce the signature; verification uses the public key to check that the signature matches a fresh hash of the received data. Common algorithms include Ed25519, ECDSA, and RSA, and post-quantum algorithms such as ML-DSA are being adopted to resist future quantum computers. Because only the private key can create a valid signature, signatures also support non-repudiation, meaning the signer can't easily deny having signed.
Digital signatures are everywhere: certificate authorities sign TLS certificates, servers sign JWTs so they can trust their claims later, operating systems and app stores check signatures on software updates, and Git commits and packages can be signed to prove where they came from. Think of a wax seal pressed with a unique ring: anyone can recognize the seal, only the owner of the ring can make it, and a broken seal shows the letter was opened.
A digital signature is often confused with encryption. Encryption hides content so that only the intended reader can see it, while a signature leaves the content readable and proves its origin and integrity, and the two are often combined. A signature also differs from a plain hash or checksum, which detects accidental changes but proves nothing about who created the data, and from an HMAC, which uses one shared secret key, so either side could have created it.
Key takeaways
- A digital signature proves who signed data and that it hasn't been altered.
- It is created with a private key and verified with the matching public key.
- Signing usually applies the private key to a hash of the data.
- It is used in TLS certificates, JWTs, software updates, and signed commits and packages.
- Encryption provides secrecy; a signature provides authenticity and integrity.
Example
from cryptography.hazmat.primitives.asymmetric.ed25519 import Ed25519PrivateKey
from cryptography.exceptions import InvalidSignature
private_key = Ed25519PrivateKey.generate() # kept secret by the signer
public_key = private_key.public_key() # shared with everyone
message = b"release v2.4.0, sha256=9f86d08..."
signature = private_key.sign(message)
public_key.verify(signature, message) # passes silently: authentic and unchanged
try:
public_key.verify(signature, b"release v2.4.0, sha256=tampered")
except InvalidSignature:
print("Rejected: the data was changed or signed by someone else")Readers ask
What is the difference between a digital signature and encryption?
Encryption keeps data secret so only someone with the right key can read it. A digital signature keeps data readable but proves who signed it and that it hasn't changed; the signer uses their private key, while encryption to a recipient uses the recipient's public key.
What is the difference between a digital signature and an electronic signature?
An electronic signature is a broad legal term for any electronic sign of agreement, such as a typed name or a click on an I agree button. A digital signature is a specific cryptographic technique that mathematically proves identity and integrity, and it is often used to make electronic signatures more trustworthy.
Can a digital signature be forged?
Not with sound algorithms and properly protected keys, because forging one would require the private key. In practice, signatures fail when private keys are stolen or weak, which is why keys are kept in secure hardware and rotated.
See also
- Public-Key CryptographySecurity, p. 30Public-key cryptography is a method that uses a pair of linked keys, a public key anyone can see and a private key kept secret, to encrypt and sign data.
- HashingSecurity, p. 14Hashing is the process of turning any input into a fixed-length value with a one-way function, used to verify data integrity and store passwords safely.
- Certificate AuthoritySecurity, p. 5A certificate authority is a trusted organization that issues digital certificates confirming a public key belongs to a specific website, company, or person.
- JWTSecurity, p. 19A JWT is a compact, signed token that carries claims like a user ID and expiry time, letting a server verify requests without looking up a session.
- EncryptionSecurity, p. 12Encryption is the process of scrambling data with a key so that only someone holding the correct key can turn it back into its original, readable form.
- Supply Chain AttackSecurity, p. 43A supply chain attack compromises software through something it relies on, like an open-source package, a build tool or an update server, not the app itself.
Spotted a mistake or something missing on this page?Suggest an edit