How can a message prove who really sent it?
A digital signature is mathematically bound to one exact message, so unlike a signature on paper, it can't be copied onto a different document and still pass.
▶ Start the storyIt carries a seal only the sender could have made. The sender signs the message with a private key that only they hold, and anyone can check that signature with the matching public key. Because it is computationally infeasible to produce a valid signature without that private key, a signature that checks out gives any recipient confidence that the message came from a sender known to them, whether it's an email, a software update or a financial transaction.
The idea sounds like a handwritten signature, but it behaves very differently. A signature on paper can be photocopied onto another document and still look convincing. A digital signature can't: it is mathematically bound to the content of the message, so it's infeasible for anyone to forge a valid signature on any other message. Change one word and the old signature no longer checks out.
Under the hood, a signature scheme runs on three steps. First, key generation picks a private key at random and produces a matching public key. Second, signing takes a message and the private key and produces a signature. Third, verifying takes the message, the public key, and the signature, and either accepts or rejects the claim. The whole scheme only works if producing a valid signature without the private key is computationally infeasible; otherwise anyone could forge anyone else's signature. Bitcoin relies on exactly this: to spend coins, owners sign transactions with their private key, and the network checks them with the public key.
The concept has a traceable birth: Whitfield Diffie and Martin Hellman first described the idea in 1976, though at the time they could only conjecture that such schemes existed. Soon after, Ronald Rivest, Adi Shamir, and Len Adleman's RSA algorithm could produce primitive signatures, though only as a proof of concept, since plain RSA signatures aren't secure. It took over a decade to reach ordinary desks: the first widely marketed software to offer digital signatures was Lotus Notes 1.0 in 1989, built on RSA.
1976
Diffie and Hellman describe the concept
Soon after
RSA offers a working proof of concept
1989
Lotus Notes 1.0 ships RSA-based signatures
Quiz me
0/3
Recap
Private key signs, public key verifies, and the signature is bound to the exact message.
Surprising fact · Unlike a paper signature, a digital one can't be copied onto a different document and still pass as valid.
Sources (2)
No source, no claim. Every fact in this lesson (12 claims) cites at least one of these.