A digital signature is the electronic equivalent of a tamper-evident seal plus a signature on paper, but mathematically much stronger. It proves three things about a message, file or piece of software: integrity (it has not changed since it was signed), authentication of origin (it came from the holder of a particular private key), and non-repudiation (the signer cannot credibly deny signing, because only they hold that key). Digital signatures protect software updates, email, documents, code, DNS records and the certificates that underpin HTTPS. They are also becoming a legal instrument: many jurisdictions accept properly implemented electronic signatures on contracts, and auditors rely on signed logs and records. Understanding exactly what a signature proves, and what it does not, keeps you from over- or under-trusting it.
Keep reading for free
Create a free StudyToCert account to read the rest of this lesson: 7 more sections, 6 key terms, a real-world example, an exam tip and self-check questions. Every lesson, lab and practice test is free with an account.