digital signature
10 ResultsDictionary
digital signature
A digital guarantee that information has not been modified, as if it were protected by a tamper-proof seal that is broken if the content were altered. The two major applications of digital...
Dictionary
Definition: digital signature
A digital guarantee that information has not been modified, as if it were protected by a tamper-proof seal that is broken if the content were altered. The two major applications of digital signatures are for setting up a secure connection to a Web site and verifying the integrity of files transmitted (more below).
An Encrypted Digest
The digital signature is an encrypted digest of the file (message, document, driver, program) being signed. The digest is computed from the contents of the file by a one-way hash function, such as MD5 and SHA-1, and then encrypted with the private part of a public/private key pair (see RSA). To prove that the file was not tampered with, the recipient uses the public key to decrypt the signature back into the original digest, recomputes a new digest from the transmitted file and compares the two to see if they match. If they do, the file has not been altered in transit by an attacker. See MD5.
An Encrypted Digest
A digital signature is an encrypted digest of a file. The digest was created with a one-way hash function from the file's contents.
Signed Certificates
The first major application for digital signatures is digital certificates. "Signed" digital certificates are used to verify the identity of an organization or individual. They are widely used to authenticate a Web site in order to establish an encrypted connection for credit card and other confidential data (see SSL and digital certificate).
Signed Files
The second major application for digital signatures is "code signing," which verifies the integrity of executable files downloaded from a Web site. Code signing also uses signed digital certificates to verify the identity of the site (see code signing and digital certificate). Also see digital envelope and electronic signature.
The Illustrations Below
The following two illustrations show how digital signatures are used for data integrity in both non-private and private exchanges. Because of the requirement of disseminating keys, the following methods are used mostly between two parties that communicate with each other on a regular basis and not by the public in general. The references to the man and woman are used to help explain the concept; however, all functions are automatically performed by the software.
Integrity, But No Privacy
The woman makes her message tamper proof by encrypting the digest into a \"digital signature,\" which accompanies the message. At the receiving side, the man uses her public key to verify the signature. However, the message text is sent \"in the clear\" and could be read by an eavesdropper.
Message Integrity and Privacy
In this example, the woman signs her message and also encrypts the signature and message with the man's public key for privacy (confidentiality). When he receives the encrypted signed message, he decrypts it with his private key to expose the text he can now read along with the signature. He then verifies the signature to ensure the message was not tampered with.
THIS DEFINITION IS FOR PERSONAL USE ONLY
All other reproduction is strictly prohibited without permission from the publisher.
© 1981-2010 The Computer Language Company Inc. All rights reserved.
Sponsored White Papers, Webcasts & Resources
-
Retail in the Smarter City
Retail could be so much smarter, imagine getting the deals you want, when and where you want them. Check out this video, Retail in the Smarter City, to learn how retail can do more.
-
Sign documents digitally in the cloud
Cloud storage service provider SurDoc is giving out a digital pen to help user execute contracts in the cloud without having to print them out and rescan them.
-
Adobe buys EchoSign, aims to make digital signatures the norm
Anyone that has printed out PDFs, signed them and scanned or faxed the document somewhere may rejoice over Adobe's acquisition of EchoSign.
-
Why do email Digital Signatures have to be such a pain in the ass?
Digital Signing of email doesn't need to be a major chore using PC operating systems and webmail sites, but it is.
-
Ariba, DocuSign partner to offer e-signatures on business docs
For the past five months, I've been trying to sell a house in the Washington DC area. Sure, there are so many other things I could say about that in a blog post - but that's for a different blog...
-
US proposes DNS fix: digital signatures
The Commerce Department is considering deploying digital signatures to make DNS less susceptible to hacking, ComputerWorld reports. Under the proposal, DNS records would be signed by DNSSEC...
-
-
Today's Debate: Does Elcomsoft hack kill digital signatures?
One possible solution is to use real keys, to embed a digital signature in a stick memory that the doctor or pharmacist carries around.
-
Digital signatures at heart of health care reform debate
Maintain encryption keys in a central store, than have doctors, pharmacists, and drug companies authenticate themselves to the store in order to reach the keys.
-
Confirming the flat-earther's myths doesn't serve anyone
My colleague David Berlind just can't seem to stop barking up the wrong tree when it comes to email security. In his latest blog, Berlind accuses me of a "reality distortion field" which really...
-
Safeguard your Office 2007 files with encryption, document protection, and digital signatures
Microsoft Office 2007 has a number of data protection features that help to protect the confidentiality and integrity of files created with Microsoft Word, Excel, PowerPoint, and Outlook. This...
-
Secure your customers' online payments
Reports of stolen credit card information deter consumers from buying goods online. So, Visa developed its own authenticated payment system. Other options include digital signatures, a shopping...
Additional Results
-
iTunes Match is a hidden gem for your music listening pleasure
For just $24.99 a year, you can listen to your music on any device and from anywhere
-
Digital Lumens updates LED lighting management platform
Web-based software dashboard helps facility managers assess the potential impact of settings changes or daylight harvesting applications.
-
Huawei asks EU to intervene in InterDigital patent dispute
Huawei has called on European antitrust regulators to investigate InterDigital, after it claims the company is pushing up the license fees of industry-standard patents.
-
TiVo streaming coming to iOS this summer
If you own a TiVo Premiere you'll soon be able to stream programs to your iPad or iPhone with an external transcoder device.
-
Digital foreplay, virtual houseflies among Carnegie Mellon work (videos)
End-of-term projects from Golan Levin's Interactive Art and Computational Design class give us a peek at what kinds of technological mischief our future geniuses are getting up to in school.
-
Microsoft to charge customers $99 to remove OEM 'crapware'
So, the OEMs make money from installing crapware onto PCs, and now Microsoft is making money removing it. Makes you realize why more and more people are buying Apple hardware.
-
Anatomy of an iTunes Store account hack
An inside look at what happens when hackers get a hold of your iTunes Store account credentials.
-
As the online and physical blur, digital citizenship is now paramount
For good or ill, as what defines us as people warps and no lines remain between physical and digital, what do we need to teach the next generation?
-
iPad trick: Searching digital handwriting (how-to)
This simple method allows taking handwritten notes on the iPad and having the ink searchable. Never again will that handwritten note disappear, never to be seen again.
-
A new kind of digital wallet (complete with physical card)
iCache's new Geode iPhone cover comes with a fingerprint sensor and a transformable card, bringing new meaning to mobile payments.
The best of ZDNet, delivered
ZDNet Newsletters
Get the best of ZDNet delivered straight to your inbox





