Tamga Network

Chapter 2 · 1/8

Cryptography in plain words

A hash is a fingerprint, a key pair is a lock and its key: the two basic tools of digital trust.

5 min

Behind digital trust there is mathematics, but you do not need maths to use it. You only need two tools: the hash and the key pair. Everything else in this learning path is built on them.

HASH · FINGERPRINTMerhabaSHA-2567fdc9f47…8c17c9c058merhabaSHA-2564c6bcdd5…8849b4d61bKEY PAIRPrivate keykept by the owner; signsPublic keypublic; checks signatures
Change one letter and the fingerprint changes completely. The private key signs, the public key checks.

A hash: the fingerprint of data

A A one-way calculation that turns data of any size into a fixed-length fingerprint. Tamga uses SHA-256. turns any data into a short, fixed-length fingerprint. One page of text and a thousand-page book both become a fingerprint of the same length. It has three properties:

  • Same data, same fingerprint.The fingerprint of "Merhaba" is the same on every computer.
  • Small change, completely different fingerprint.Lowercase just the first letter ("merhaba") and the fingerprint changes completely. The figure shows the start and end of the two words' real SHA-256 fingerprints.
  • No way back. You cannot recover the data from the fingerprint, just as you cannot draw a face from a fingerprint.

That makes a hash the shortest way to prove a document has not changed: keep its fingerprint, recompute it later and compare. If even one character changed, the fingerprints will not match.

A key pair: the seal and its imprint

The second tool is a Two mathematically linked keys: the private key signs, the public key checks the signature., two keys that belong together:

  • The private keyis held only by its owner. It sits on an institution's server or in the secure area of a person's phone and never leaves.
  • The public key is public. Anyone may know it; it can be published and written into lists.

Only the public key of the same pair can check what the private key did. Think of the private key as a seal and the public key as a sample of its imprint that everyone holds: only the owner can press the seal, but anyone can compare an imprint with the sample.

The two together

Combine a hash and a key pair and you get a digital signature: the document's fingerprint is signed with the private key, and anyone checks it with the public key. The next page explains exactly that.

Summary

  • A hash is a short fingerprint of data; change one character and it changes completely.
  • In a key pair the private key stays with its owner, the public key is public.
  • Together they make the digital signature.

Go deeper

Technical details and binding rules: