Chapter 2 · 2/8
Digital signatures
A digital signature answers two questions: who signed this, and has it changed since?
4 min
A handwritten signature can be forged, and a scanned signature proves nothing; anyone can paste an image into another document. A digital signature is different: it is mathematically bound to the content of the document.
How is it signed?
When an institution issues a credential, it first takes the document's fingerprint (hash), then signs that fingerprint with its The key held only by the institution, used to sign.. The signature is attached to the document. In Tamga, credentials are signed with A widely used elliptic-curve signature algorithm (ECDSA P-256 + SHA-256), also used in the EU digital identity framework., the same algorithm the EU digital identity framework uses.
How is it checked?
The verifier does three things:
- Recomputes the document's fingerprint.
- Opens the signature with the institution's public key and compares the two fingerprints.
- Checks in the trust list that the public key really belongs to that institution.
If the fingerprints match, two questions are answered: the document has not changed since it was signed and it was signed by that institution. Change one character and the fingerprint no longer matches; the signature fails.
How it differs from an e-signature
The "e-signature" we see on documents is a person signing, say, a contract; in many countries a An electronic signature defined in law as equivalent to a handwritten one. counts the same as a handwritten one. The signature in a verifiable credential is the institution saying "this information is correct". Same technology, different purpose; both can rely on the same trust lists.
Summary
- A digital signature is bound to the content; change one character and it fails.
- The verifier checks it with the public key, without asking the issuer.
- The trust list says whose public key it is.
Go deeper
Technical details and binding rules: