Signature
In short: A cryptographic method used to prove that data really comes from the stated sender (authenticity) and hasn’t been altered since it was signed (integrity).
In more detail: A digital signature is created with the sender’s private key (often over the hash of the data, not the data itself — faster) and can be verified by anyone using their public key. Unlike a handwritten signature, a digital signature is different for every message, since it depends on the content. Certificates use this principle: the certificate authority signs the certificate with its private key.
In Depth
The process of a digital signature runs in two clearly separated steps:
Signing (sender, with the private key):
1. Compute the hash of the message
2. Encrypt the hash with the private key -> this is the signature
Verifying (recipient, with the public key):
1. Decrypt the signature with the public key -> yields the original hash
2. Compute the hash of the received message yourself
3. Compare both hashes -> if they match, the message is genuine and unaltered
The crucial point: it’s not the message itself that gets signed, only its (much shorter) hash — asymmetric encryption is computationally expensive, and for large files, directly signing every single byte would be impractically slow. Since even a minimal change to the message completely changes the hash (see Hashing), checking the hash is enough to reliably detect any tampering.
Digital signatures solve a problem that encryption alone doesn’t solve: encryption provides confidentiality (no one but the recipient can read along), but says nothing about who actually sent the message. A signature, by contrast, proves origin and integrity, but says nothing about confidentiality — which is why in practice both are often combined (e.g. with signed and encrypted emails via PGP/GPG, or with TLS certificates, which are signed by the issuing authority while the actual connection is separately encrypted).
Common signature schemes
In practice you mainly encounter two families of signature schemes: RSA-based signatures (mathematically related to RSA encryption, but a standalone scheme) and signatures based on elliptic curves (ECDSA, or the more modern Ed25519). Elliptic-curve schemes achieve the same security as RSA with considerably shorter key lengths, and are also faster to compute — a 256-bit Ed25519 key offers comparable security to a 3072-bit RSA key, which is why modern systems (e.g. ssh-keygen -t ed25519) are increasingly switching to it.
Practical use cases
Software updates are almost always signed: before an operating system or app installs an update, it checks the signature against the manufacturer’s public key — without a valid signature, the installation is refused, which prevents an attacker from injecting tampered updates via a compromised download server. Git commits can also be signed (git commit -S), to cryptographically prove that a commit really comes from the stated person, not just “signed” with their name/email address (which can be forged arbitrarily). Blockchain transactions are another example: every transaction is signed with the sender’s private key, allowing the network to verify that the wallet’s owner really authorised the transfer, without a central authority having to check it.
See also: Certificate, Private key, Hashing