About this interactive
A digital signature proves two things about a document: that it has not changed since it was signed (integrity) and that it came from the person who signed it (authenticity). It does that by combining the two tools the module has introduced, hashing and a key pair.
Susan signs. She runs the document through a hash function to get its hash, the document's fingerprint. She encrypts that hash with her private key, which only she has, and sends the document and the encrypted hash to David. Her public key goes to David inside her digital certificate.
David checks. He first makes sure the certificate really is Susan's, by having it validated through public key infrastructure: a certificate authority they both trust. He decrypts the encrypted hash with Susan's public key, which gives him the fingerprint Susan made. Then he hashes the document he received with the same algorithm and compares the two fingerprints.
If they match, the document has not changed, because even a small change would give a different fingerprint, and it came from Susan, because only her private key could have produced a hash that her validated public key opens correctly. If they do not match, something is wrong: the document was altered, or it was not signed with Susan's private key.
The step people most often get backwards is the keys. When you encrypt something to keep it secret, you use the recipient's public key. When you sign, the signer uses their own private key, and everyone else checks it with the signer's public key. Every item here is one of these steps, with one word missing.
About TechKnowSurge
TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.
Explore free tools and programs →