TechKnowSurge
NIST 800-53 SC-13 Cisco CCST Cybersecurity 1.4 CompTIA Tech+ 6.6 ISC2 CC 5.1 NIST 800-53 SC-17 NIST NICE K1203 NIST NICE S0657
InteractiveSecurityFree

How a Digital Signature Works

Type the missing word at each step of signing a document and checking the signature: whose key, which key, and what a match proves.

⚑ Complete this interactive to capture a CTF flag worth 5 points.

About this interactive

A digital signature proves two things about a document: that it has not changed since it was signed (integrity) and that it came from the person who signed it (authenticity). It does that by combining the two tools the module has introduced, hashing and a key pair. Susan signs. She runs the document through a hash function to get its hash, the document's fingerprint. She encrypts that hash with her private key, which only she has, and sends the document and the encrypted hash to David. Her public key goes to David inside her digital certificate. David checks. He first makes sure the certificate really is Susan's, by having it validated through public key infrastructure: a certificate authority they both trust. He decrypts the encrypted hash with Susan's public key, which gives him the fingerprint Susan made. Then he hashes the document he received with the same algorithm and compares the two fingerprints. If they match, the document has not changed, because even a small change would give a different fingerprint, and it came from Susan, because only her private key could have produced a hash that her validated public key opens correctly. If they do not match, something is wrong: the document was altered, or it was not signed with Susan's private key. The step people most often get backwards is the keys. When you encrypt something to keep it secret, you use the recipient's public key. When you sign, the signer uses their own private key, and everyone else checks it with the signer's public key. Every item here is one of these steps, with one word missing.

What you'll learn

Aligned to

NIST 800-53
SC-13 Cryptographic Protection
SC-17 Public Key Infrastructure Certificates
Cisco CCST Cybersecurity
1.4 Explain encryption methods and applications
CompTIA Tech+
6.6 Explain common uses of encryption
ISC2 CC
5.1 Understand data security
NIST NICE
K1203 Knowledge of Public Key Infrastructure (PKI) libraries
S0657 Skill in implementing Public Key Infrastructure (PKI) encryption

Key terms

Digital Signature
A cryptographic mechanism used to verify the authenticity and integrity of a digital message or document.
Hash Function
A mathematical algorithm that converts input data of any size into a fixed-size output value used to verify data integrity.
Private Key
A secret cryptographic key used in asymmetric encryption to decrypt data or create digital signatures.
Public Key
A cryptographic key that can be shared openly and is used to encrypt data or verify digital signatures.
Digital Certificate
An electronic document that uses a digital signature to bind a public key with an identity.
Certificate Authority
CA
A trusted entity that issues digital certificates used to verify the identity of individuals, organizations, or devices.
Integrity
The assurance that data has not been tampered with and remains accurate and complete.
Authenticity
The assurance that information or a communication originates from the claimed source and has not been fabricated or impersonated. Digital signatures and certificates are common mechanisms for establishing authenticity.

Topics

Digital Signatures Hashing Public Key Infrastructure Interactive Fill In

About TechKnowSurge

TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.

Explore free tools and programs →