Overview
A digital signature is a mathematical scheme for verifying the authenticity of digital messages or documents. A valid digital signature on a message gives any recipient confidence that the message came from a sender known to the recipient. In contrast, a message authentication code only gives confidence to a specific recipient that the message came from a known sender.
Digital signatures are a type of public-key cryptography, and are commonly used for software distribution, financial transactions, contract management software, and in other cases where it is important to detect forgery or tampering.
A digital signature on a message or document is similar to a handwritten signature on paper, but it is not restricted to a physical medium like paper—any bitstring can be digitally signed—and while a handwritten signature on paper could be copied onto other paper in a forgery, a digital signature on a message is mathematically bound to the content of the message so that it is infeasible for anyone to forge a valid digital signature on any other message.
5 sources for this section
- 1Digital signature — Wikipedia, revision 1373960950
- 2Goldwasser, Shafi; Bellare, Mihir (July 2008). "Chapter 10: Digital signatures" (PDF). Lecture Notes on Cryptography. p. 168. Archived (PDF) from the original on 2022-04-20. Retrieved 2023-06-11.
- 3Boneh, Dan; Shoup, Victor (January 2023). "13. Digital Signatures". A Graduate Course in Applied Cryptography (PDF) (Version 0.6 ed.).
- 4"§ 7.5. Package signing in Debian". Securing Debian Manual. Debian Project. Archived from the original on 2025-06-11. Retrieved 2025-07-17.
- 5"Distributing your app to registered devices". Apple Developer Documentation. Apple, Inc. Archived from the original on 2024-03-13. Retrieved 2025-07-17.
Definition
Here 1^(n) refers to a unary number in the formalism of computational complexity theory.
A digital signature scheme is secure if for every non-uniform probabilistic polynomial time adversary A,
where A^(S(sk, · )) denotes that A has access to the oracle, S(sk, · ), Q denotes the set of the queries on S made by A, which knows the public key, pk, and the security parameter, n, and x ∉ Q denotes that the adversary may not directly query the string, x, on S.
1 source for this section
History
In 1976, Whitfield Diffie and Martin Hellman first described the notion of a digital signature scheme, although they only conjectured that such schemes existed based on functions that are trapdoor one-way permutations. Soon afterwards, Ronald Rivest, Adi Shamir, and Len Adleman invented the RSA algorithm, which could be used to produce primitive digital signatures (although only as a proof-of-concept – "plain" RSA signatures are not secure). The first widely marketed software package to offer digital signature was Lotus Notes 1.0, released in 1989, which used the RSA algorithm.
Other digital signature schemes were soon developed after RSA, the earliest being Lamport signatures, Merkle signatures (also known as "Merkle trees" or simply "Hash trees"), and Rabin signatures.
In 1988, Shafi Goldwasser, Silvio Micali, and Ronald Rivest became the first to rigorously define the security requirements of digital signature schemes. They described a hierarchy of attack models for signature schemes, and also presented the GMR signature scheme, the first that could be proved to prevent even an existential forgery against a chosen message attack, which is the currently accepted security definition for signature schemes.
The first such scheme which is not built on trapdoor functions but rather on a family of function with a much weaker required property of one-way permutation was presented by Moni Naor and Moti Yung.
9 sources for this section
- 1Digital signature — Wikipedia, revision 1373960950
- 6Diffie, W.; Hellman, M. (1976). "New directions in cryptography" (PDF). IEEE Transactions on Information Theory. 22 (6): 644–654. Bibcode:1976ITIT...22..644D. doi:10.1109/TIT.1976.1055638.
- 7Signature Schemes and Applications to Cryptographic Protocol Design
- 8Rivest, R.; Shamir, A.; Adleman, L. (1978). "A Method for Obtaining Digital Signatures and Public-Key Cryptosystems" (PDF). Communications of the ACM. 21 (2): 120–126. doi:10.1145/359340.359342. S2CID 2873616. Archived from the original (PDF) on 2008-12-17. Retrieved 2025-07-02.
Method
One digital signature scheme (of many) is based on RSA. To create signature keys, generate an RSA key pair containing a modulus, N, that is the product of two random secret distinct large primes, along with integers, e and d, such that e d ≡ 1 (mod φ(N)), where φ is Euler's totient function. The signer's public key consists of N and e, and the signer's secret key contains d.
Used directly, this type of signature scheme is vulnerable to key-only existential forgery attack. To create a forgery, the attacker picks a random signature σ and uses the verification procedure to determine the message, m, corresponding to that signature. In practice, however, this type of signature is not used directly, but rather, the message to be signed is first hashed to produce a short digest, that is then padded to larger width comparable to N, then signed with the reverse trapdoor function.
This forgery attack, then, only produces the padded hash function output that corresponds to σ, but not a message that leads to that value, which does not lead to an attack. In the random oracle model, hash-then-sign (an idealized version of that practice where hash and padding combined have close to N possible outputs), this form of signature is existentially unforgeable, even against a chosen-plaintext attack.
There are several reasons to sign such a hash (or message digest) instead of the whole document.
3 sources for this section
- 1Digital signature — Wikipedia, revision 1373960950
- 7Signature Schemes and Applications to Cryptographic Protocol Design
- 14Bellare, Mihir; Rogaway, Phillip (1996). "The Exact Security of Digital Signatures-How to Sign with RSA and Rabin". In Maurer, Ueli (ed.). Advances in Cryptology — EUROCRYPT '96. Lecture Notes in Computer Science. Vol. 1070. Berlin, Heidelberg: Springer. pp. 399–416. doi:10.1007/3-540-68339-9_34. ISBN 978-3-540-68339-1.
Applications
As organizations move away from paper documents with ink signatures or authenticity stamps, digital signatures can provide added assurances of the evidence to provenance, identity, and status of an electronic document as well as acknowledging informed consent and approval by a signatory. The United States Government Printing Office (GPO) publishes electronic versions of the budget, public and private laws, and congressional bills with digital signatures.^([failed verification]) Universities including Penn State, University of Chicago, and Stanford are publishing electronic student transcripts with digital signatures.
The source notesEvidence & further reading15 sources
- Digital signature — Wikipedia, revision 1373960950 Wikipedia contributors · Reference source · accessed 2026-09-22
- Goldwasser, Shafi; Bellare, Mihir (July 2008). "Chapter 10: Digital signatures" (PDF). Lecture Notes on Cryptography. p. 168. Archived (PDF) from the original on 2022-04-20. Retrieved 2023-06-11. cseweb.ucsd.edu · Reference source · link imported 2026-09-22
- Boneh, Dan; Shoup, Victor (January 2023). "13. Digital Signatures". A Graduate Course in Applied Cryptography (PDF) (Version 0.6 ed.). toc.cryptobook.us · Reference source · link imported 2026-09-22
- "§ 7.5. Package signing in Debian". Securing Debian Manual. Debian Project. Archived from the original on 2025-06-11. Retrieved 2025-07-17. debian.org · Reference source · link imported 2026-09-22
- "Distributing your app to registered devices". Apple Developer Documentation. Apple, Inc. Archived from the original on 2024-03-13. Retrieved 2025-07-17. docs.developer.apple.com · Reference source · link imported 2026-09-22
- Diffie, W.; Hellman, M. (1976). "New directions in cryptography" (PDF). IEEE Transactions on Information Theory. 22 (6): 644–654. Bibcode:1976ITIT...22..644D. doi:10.1109/TIT.1976.1055638. www-ee.stanford.edu · Reference source · link imported 2026-09-22
- Signature Schemes and Applications to Cryptographic Protocol Design dspace.mit.edu · Reference source · link imported 2026-09-22