How digital signatures work, step by step
Hash, sign with a private key, verify with a public key: what digital signatures prove, where you meet them every day, and how India's DSCs and eSign work.
On this page 12 sections
- What a digital signature proves
- Signing and verifying, step by step
- Try it: signing a fee receipt
- Signature algorithms you'll meet
- Signatures vs encryption
- Digital certificates and DSCs in India
- What a DSC is in practice
- Verifying a DSC-signed PDF
- Where you meet signatures every day
- What signatures can't tell you
- Key takeaways
- Frequently asked questions
A digital signature works in three steps: software computes a hash, a short fingerprint of the document; the signer's private key turns that hash into a signature; and anyone with the matching public key can check that the signature fits the document. If even one character changes, the check fails. A valid signature proves which key signed and that nothing changed afterwards, while a certificate, such as an Indian Digital Signature Certificate (DSC), links that key to a named person or organisation.
What a digital signature proves
A valid digital signature tells the recipient two things:
- Integrity: the document is exactly what was signed. Not a comma has moved.
- Origin: it was signed with one particular private key. Combined with a certificate that names the key's owner, that becomes proof of who signed.
It does not hide anything. A signed PDF or app update stays fully readable; signing and encryption are separate jobs.
It is also not a picture of a signature. Many "signed" fee receipts, offer letters and certificates in circulation carry a scanned signature image pasted into a PDF. Anyone can copy that image onto another document. A digital signature is a number calculated from the document itself, so it can't be lifted onto anything else.
Signing and verifying, step by step
Signing, on the signer's side:
- Hash the document. A hash function such as SHA-256 turns any file, whether a one-page receipt or a 2 GB video, into a fixed 32-byte fingerprint. Change the input slightly and the fingerprint changes completely.
- Sign the hash. The signing algorithm combines the hash with the private key to produce the signature. Only the holder of that private key can produce it.
- Attach it. The signature, usually with the signer's certificate, travels with the document.
Verifying, on anyone's side:
- Hash the received document with the same function.
- Check the signature against that hash using the signer's public key. The maths confirms the pair matches, or it doesn't.
- Check the certificate: that it chains to a trusted authority, was valid when the document was signed, and hasn't been revoked.
Try it: signing a fee receipt
You can watch this happen with OpenSSL 3. Take a small text file, receipt.txt, containing "Receipt 1042: Rs 18,000 received from A. Sharma" (an illustrative example), and run:
# Create a key pair (Ed25519)
openssl genpkey -algorithm ed25519 -out private.pem
openssl pkey -in private.pem -pubout -out public.pem
# Sign the receipt with the private key
openssl pkeyutl -sign -inkey private.pem -rawin -in receipt.txt -out receipt.sig
# Anyone with public.pem can verify it
openssl pkeyutl -verify -pubin -inkey public.pem -rawin -in receipt.txt -sigfile receipt.sig
The last command prints "Signature Verified Successfully". Now edit the receipt to say Rs 1,800 and run the verify command again: it prints "Signature Verification Failure". The signature file is 64 bytes, and it would be 64 bytes for a 500-page PDF too. Ed25519 hashes the message internally, which is why the whole file goes in.
Signature algorithms you'll meet
| Algorithm | Based on | Signature size | Where you see it |
|---|---|---|---|
| RSA (PKCS #1 v1.5 or PSS) | Factoring large numbers | 256 bytes with a 2,048-bit key | Certificates, Indian DSCs, older systems |
| ECDSA with P-256 | Elliptic curves | About 64 bytes | TLS certificates, Indian DSCs |
| Ed25519 | Elliptic curves | 64 bytes | SSH keys, software and package signing |
| ML-DSA-44 | Lattices (post-quantum) | 2,420 bytes | Early adoption; standardised in FIPS 204 |
For DSCs, the Controller of Certifying Authorities lists RSA and ECDSA with the P-256 curve, both with SHA-2 hashes, as the allowed signature types. ML-DSA is NIST's main post-quantum signature standard, published in 2024. It is far bigger, but it survives the quantum attacks that would break RSA and elliptic-curve signatures; our guide to post-quantum cryptography covers the timeline.
Signatures vs encryption
| Aspect | Encryption | Digital signature |
|---|---|---|
| Goal | Keep content secret | Prove origin and integrity |
| Key that does the work | The recipient's public key (or a shared key) | The signer's private key |
| Key that checks or opens it | The recipient's private key | The signer's public key |
| Content hidden? | Yes | No, it stays readable |
| Typical use | HTTPS traffic, stored data | App updates, certificates, contracts |
You may have read that signing means "encrypting the hash with the private key". That is a loose description of textbook RSA only. ECDSA and Ed25519 don't encrypt anything, and real RSA libraries use different padding for signing and for encryption. Treat them as separate operations with separate keys. India's DSC rules do the same: an individual's signing and encryption certificates are kept separate.
Two near relatives are easy to confuse with signatures:
- A plain hash proves nothing about origin, because anyone can recompute it. See our explainer on hashing.
- An HMAC uses a shared secret key. It suits payment webhooks and signed URLs, but since both sides hold the key, either could have produced it, so it can't prove to a third party who signed. Our guide to HMAC explains when that's enough.
Digital certificates and DSCs in India
A public key on its own is just a number. A digital certificate binds it to an identity, and a certificate authority signs that binding after checking the identity. How those authorities are trusted is the subject of our guide to PKI and certificate authorities.
India built its legal framework on exactly this model. Section 3 of the Information Technology Act, 2000 lets a subscriber authenticate an electronic record with a digital signature, using an "asymmetric crypto system and hash function". According to the Controller of Certifying Authorities (CCA), appointed under Section 17 of the Act, digital signatures are accepted at par with handwritten ones. The CCA runs the Root Certifying Authority of India and licenses the certifying authorities (CAs) that issue DSCs to individuals and organisations.
What a DSC is in practice
- Issued by a licensed CA after identity checks such as Aadhaar eKYC, paper documents or video verification.
- Kept on a hardware token. Under the CCA's identity verification guidelines (version 2.6, June 2026), individual signing DSCs are issued as Class 3 certificates whose private key is generated on a FIPS 140-2 Level 2 or 3 validated crypto token. A Class 3 certificate also qualifies wherever Class 2 is asked for.
- Used where law or process demands it. Government e-procurement portals, for example, require bidders to register a DSC held on an e-token before they can submit bids.
- eSign as an alternative. The CCA's eSign service lets you sign online after Aadhaar eKYC by OTP or biometric. The provider creates a key pair in a hardware security module, signs only the document's hash, and destroys the key after that single use.
Verifying a DSC-signed PDF
If a PDF reader shows a DSC signature as "unknown" rather than valid, it usually doesn't trust the India PKI root. The CCA says Microsoft products carry the Root Certificate of India, and it can be downloaded from cca.gov.in for other systems. Signatures are judged against the moment of signing: a document signed while the certificate was valid stays valid after the certificate expires. For records you must keep for years, the CCA recommends timestamps and long-term signature formats such as PAdES.
This is general information, not legal advice. For your situation, speak to a lawyer.
Where you meet signatures every day
- Every app install and update. Android rejects unsigned apps and installs an update only if its signing certificate matches the installed version. With Play App Signing, required for new apps since August 2021, Google holds the app signing key and you hold an upload key that can be reset if lost. For an institute's branded app, that key is what proves an update really came from you.
- Every HTTPS connection. The certificate carries a CA's signature, and the server signs the handshake to prove it holds the matching key. Our guide to how SSL/TLS works shows where.
- Login tokens. Most JSON Web Tokens are signed, not encrypted, so anyone can read them but no one can alter them unnoticed. Our comparison of JWTs and sessions covers what that means for logins.
- Software and operating system updates, code commits and package registries, where a signature separates the real release from a tampered copy.
What signatures can't tell you
- Whether the content is true or safe. A signature proves who signed, not that they were right. Malware has been signed with genuine keys that were stolen or misused.
- Whether the key holder actually signed. It proves the key was used. As the CCA itself warns, a private key that isn't stored securely can be used without its owner's knowledge.
- Whether the name is the one you expect. A valid certificate for a look-alike organisation is still valid. Read the name, not just the green tick.
- Whether the algorithm will last. Signatures built on MD5 or SHA-1 hashes can no longer be trusted, and RSA and ECDSA will eventually need post-quantum successors.
Key takeaways
- A digital signature is a hash of the document transformed with a private key, checked with the matching public key.
- It proves integrity and origin; it doesn't keep anything secret.
- A certificate ties the key to an identity; in India, licensed CAs issue DSCs under the IT Act and the CCA.
- Class 3 DSCs keep the private key on a hardware token; eSign signs online with a single-use key.
- Signatures prove which key signed, so guarding that key matters as much as the maths.
Frequently asked questions
What is digital signature and how it works?
A digital signature is a value computed from a document and the signer's private key. The signer's software hashes the document and signs the hash; a verifier hashes the received document and checks the signature with the signer's public key. If the document changed, or a different key signed it, verification fails. A certificate from a trusted authority tells the verifier whose public key it is.
What is digital signature in cryptography?
In cryptography, a digital signature is an asymmetric scheme with three parts: key generation, signing with a private key, and verification with the public key. Common algorithms are RSA, ECDSA and Ed25519, with ML-DSA as the new post-quantum standard. A signature provides integrity and authentication, and supports non-repudiation because only the private-key holder could have produced it. It provides no confidentiality.
What is digital signature certificate (DSC)?
A DSC is an electronic certificate issued in India by a certifying authority licensed by the Controller of Certifying Authorities. It links your identity, verified through Aadhaar eKYC, documents or video, to a public key, while the private key stays on a hardware token. You use it to sign documents, e-tender bids and statutory filings, and a signature made with it is legally recognised under the IT Act, 2000.
What is digital signature in simple words?
It is a tamper-proof electronic seal. When you sign a file, your computer creates a unique code from the file's contents and your secret key. Anyone can use your public key to check the seal. If someone changes even one letter of the file, or tries to reuse the seal on another file, the check fails. It works nothing like a scanned signature image.