{"id":78,"date":"2016-07-14T04:10:21","date_gmt":"2016-07-14T04:10:21","guid":{"rendered":"http:\/\/www.talkcrypto.org\/blog\/?p=78"},"modified":"2017-04-21T01:54:04","modified_gmt":"2017-04-21T01:54:04","slug":"digital-signatures-and-the-blockchain","status":"publish","type":"post","link":"https:\/\/www.talkcrypto.org\/blog\/2016\/07\/14\/digital-signatures-and-the-blockchain\/","title":{"rendered":"Digital signatures and the blockchain"},"content":{"rendered":"<h4>Introduction<\/h4>\n<p>Understanding how digital signatures work is fundamental to understanding how blockchain technologies work. Let&#8217;s first draw a comparison to paying a restaurant bill with a credit card.<\/p>\n<h4>Paying a bill at a restaurant<\/h4>\n<p>Think of what happened the last time you paid your bill at the restaurant with your credit card. Here is a snapshot:<\/p>\n<ol>\n<li>You pull the card from your wallet and you might have a photo ID on the card. This proves you own* the card.<\/li>\n<li>You sign the bill in front of the waiter. The proves you are the &#8220;rightful&#8221; owner of the card.<\/li>\n<li>You check the receipt against the bill. You prove that the amount charged hasn&#8217;t been altered somewhere in the process.<\/li>\n<\/ol>\n<p>* It actually proves possession of the card but the entire process\u00a0serves to illustrate a simplistic view and is not without it&#8217;s flaws.<\/p>\n<p>These 3 points illustrate 3 key properties:<\/p>\n<ol>\n<li>Ownership. The card belongs to you.<\/li>\n<li>Transaction authentication and non-repudiation. The waiter can verify that the owner signed the bill and the owner cannot deny the signing.<\/li>\n<li>Data Integrity.\u00a0The amount charged was accurate.<\/li>\n<\/ol>\n<p>How can this be performed in a digital world where both parties hide behind a screen, do not know each other and therefore do not trust each other. Enter public\/private keys.<\/p>\n<h4>Public\/private keys<\/h4>\n<p>Back in the 70&#8217;s and 80&#8217;s cryptographers invented a way to fulfil the 3 key properties mentioned above. This is achieved by the use of what is known as a public\/private key pair.<\/p>\n<p>A public key is something that can be distributed or known to the public and the private key is something that the owner must keep securely.\u00a0They are mathematically linked so that only the public key can decrypt what the private key has encrypted and vice versa.<\/p>\n<h4>How it works?<\/h4>\n<p>There are 5 steps involved:<\/p>\n<ol>\n<li>Generate a public\/private key pair<\/li>\n<li>Create a message digest<\/li>\n<li>Encrypt the message digest with the private key to create a signature<\/li>\n<li>Append the signature to the document<\/li>\n<li>Place it on the blockchain<\/li>\n<\/ol>\n<p>There are numerous tutorials on how this can be done. Here we outline the general process.<\/p>\n<h6>Step 1:\u00a0Generate a public\/private key pair<\/h6>\n<p>This can be done using software such as Putty for windows or via\u00a0the ssh-keygen command for Mac or Ubuntu.<\/p>\n<p><img fetchpriority=\"high\" decoding=\"async\" class=\"size-medium wp-image-81 aligncenter\" src=\"https:\/\/www.talkcrypto.org\/blog\/wp-content\/uploads\/2016\/07\/keys-300x246.png\" alt=\"keys\" width=\"300\" height=\"246\" srcset=\"https:\/\/www.talkcrypto.org\/blog\/wp-content\/uploads\/2016\/07\/keys-300x246.png 300w, https:\/\/www.talkcrypto.org\/blog\/wp-content\/uploads\/2016\/07\/keys-768x630.png 768w, https:\/\/www.talkcrypto.org\/blog\/wp-content\/uploads\/2016\/07\/keys-700x574.png 700w, https:\/\/www.talkcrypto.org\/blog\/wp-content\/uploads\/2016\/07\/keys.png 1000w\" sizes=\"(max-width: 300px) 100vw, 300px\" \/><\/p>\n<h6>Step 2: Create a message digest.<\/h6>\n<p>We take some information we want to sign. This could be a house title, a will, digital rights to a song, or even a simple IOU and we run it through some software that applies a hash function and creates a message digest.<\/p>\n<p><img decoding=\"async\" class=\"aligncenter wp-image-87\" src=\"https:\/\/www.talkcrypto.org\/blog\/wp-content\/uploads\/2016\/07\/hash-300x131.png\" alt=\"hash\" width=\"501\" height=\"218\" srcset=\"https:\/\/www.talkcrypto.org\/blog\/wp-content\/uploads\/2016\/07\/hash-300x131.png 300w, https:\/\/www.talkcrypto.org\/blog\/wp-content\/uploads\/2016\/07\/hash-768x334.png 768w, https:\/\/www.talkcrypto.org\/blog\/wp-content\/uploads\/2016\/07\/hash-700x305.png 700w, https:\/\/www.talkcrypto.org\/blog\/wp-content\/uploads\/2016\/07\/hash.png 800w\" sizes=\"(max-width: 501px) 100vw, 501px\" \/><\/p>\n<p>A <a id=\"hash\"><\/a>hash function takes an arbitrary input and produces\u00a0a seemingly random string of characters that is unique for that input. This is called the message digest. What this means is that if even one character is changed in the input, the message digest\u00a0will be totally different. You should be thinking data integrity here.<\/p>\n<h6>Step 3: Create the signature<\/h6>\n<p>The message digest is then encrypted with the owners private key. The output of this is the digital signature.<\/p>\n<h6><img decoding=\"async\" class=\"aligncenter wp-image-90 size-large\" src=\"https:\/\/www.talkcrypto.org\/blog\/wp-content\/uploads\/2016\/07\/digital-signatures-1024x296.png\" alt=\"digital signatures\" width=\"700\" height=\"202\" srcset=\"https:\/\/www.talkcrypto.org\/blog\/wp-content\/uploads\/2016\/07\/digital-signatures-1024x296.png 1024w, https:\/\/www.talkcrypto.org\/blog\/wp-content\/uploads\/2016\/07\/digital-signatures-300x87.png 300w, https:\/\/www.talkcrypto.org\/blog\/wp-content\/uploads\/2016\/07\/digital-signatures-768x222.png 768w, https:\/\/www.talkcrypto.org\/blog\/wp-content\/uploads\/2016\/07\/digital-signatures-700x202.png 700w, https:\/\/www.talkcrypto.org\/blog\/wp-content\/uploads\/2016\/07\/digital-signatures.png 1892w\" sizes=\"(max-width: 700px) 100vw, 700px\" \/><\/h6>\n<h6>Step 4:\u00a0Append the signature to the document<\/h6>\n<p>The signature is placed with the document.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-93\" src=\"https:\/\/www.talkcrypto.org\/blog\/wp-content\/uploads\/2016\/07\/signed-1-300x287.png\" alt=\"signed\" width=\"199\" height=\"191\" srcset=\"https:\/\/www.talkcrypto.org\/blog\/wp-content\/uploads\/2016\/07\/signed-1-300x287.png 300w, https:\/\/www.talkcrypto.org\/blog\/wp-content\/uploads\/2016\/07\/signed-1-768x735.png 768w, https:\/\/www.talkcrypto.org\/blog\/wp-content\/uploads\/2016\/07\/signed-1-1024x980.png 1024w, https:\/\/www.talkcrypto.org\/blog\/wp-content\/uploads\/2016\/07\/signed-1-700x670.png 700w, https:\/\/www.talkcrypto.org\/blog\/wp-content\/uploads\/2016\/07\/signed-1-32x32.png 32w, https:\/\/www.talkcrypto.org\/blog\/wp-content\/uploads\/2016\/07\/signed-1.png 1034w\" sizes=\"(max-width: 199px) 100vw, 199px\" \/><\/p>\n<h6>Step 5:\u00a0Place the document on the blockchain<\/h6>\n<p>This makes the document publicly available, because the blockchain is just a globally distributed, publicly accessible database. More importantly though, it timestamps the document effectively proving an event has occurred.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-95 size-full\" src=\"https:\/\/www.talkcrypto.org\/blog\/wp-content\/uploads\/2016\/07\/signing-on-the-block.png\" alt=\"signing on the block\" width=\"400\" height=\"331\" srcset=\"https:\/\/www.talkcrypto.org\/blog\/wp-content\/uploads\/2016\/07\/signing-on-the-block.png 400w, https:\/\/www.talkcrypto.org\/blog\/wp-content\/uploads\/2016\/07\/signing-on-the-block-300x248.png 300w\" sizes=\"(max-width: 400px) 100vw, 400px\" \/><\/p>\n<h4>Using the public key<\/h4>\n<p>The public key can now\u00a0be used by anyone to decrypt the digital signature to reveal the message digest. Successful decryption proves authenticity of the document. That is, does it really belongs to the person who is claiming ownership?<\/p>\n<p>The integrity can also be determined by the receiver creating a message digest of the received document and comparing it to the digest provided within the document. If the 2 match, then the receiver can be confident that the message was not tampered with.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-97 size-full\" src=\"https:\/\/www.talkcrypto.org\/blog\/wp-content\/uploads\/2016\/07\/public-key.png\" alt=\"public key\" width=\"500\" height=\"243\" srcset=\"https:\/\/www.talkcrypto.org\/blog\/wp-content\/uploads\/2016\/07\/public-key.png 500w, https:\/\/www.talkcrypto.org\/blog\/wp-content\/uploads\/2016\/07\/public-key-300x146.png 300w\" sizes=\"(max-width: 500px) 100vw, 500px\" \/><\/p>\n<h4>Summary<\/h4>\n<p>Ownership is provided by having the private key in your possession. This is why with blockchain technologies, the private key is so important. If this is compromised, you&#8217;re in trouble. Someone else could impersonate you.<\/p>\n<p>The fact that the public key works means that the private key was used to sign the document and it also\u00a0ensures non-repudiation. The owner of the private key\u00a0cannot deny that they didn&#8217;t sign it.<\/p>\n<p>The message digest ensures data integrity. In other words, the if the document has been altered, the public key would no longer work.<\/p>\n<p>Now you can take any piece of information, such as a <a href=\"https:\/\/bitcoinmagazine.com\/articles\/first-blockchain-wedding-2-1412544247\" target=\"_blank\" rel=\"noopener noreferrer\">marriage certificate<\/a>\u00a0and understand how it all works on the blockchain.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Introduction Understanding how digital signatures work is fundamental to understanding<\/p>\n","protected":false},"author":1,"featured_media":90,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[3],"tags":[13],"class_list":["post-78","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-blockchain","tag-blockchain101"],"featured_image_urls":{"full":["https:\/\/www.talkcrypto.org\/blog\/wp-content\/uploads\/2016\/07\/digital-signatures.png",1892,546,false],"thumbnail":["https:\/\/www.talkcrypto.org\/blog\/wp-content\/uploads\/2016\/07\/digital-signatures-150x150.png",150,150,true],"medium":["https:\/\/www.talkcrypto.org\/blog\/wp-content\/uploads\/2016\/07\/digital-signatures-300x87.png",300,87,true],"medium_large":["https:\/\/www.talkcrypto.org\/blog\/wp-content\/uploads\/2016\/07\/digital-signatures-768x222.png",640,185,true],"large":["https:\/\/www.talkcrypto.org\/blog\/wp-content\/uploads\/2016\/07\/digital-signatures-1024x296.png",640,185,true],"1536x1536":["https:\/\/www.talkcrypto.org\/blog\/wp-content\/uploads\/2016\/07\/digital-signatures.png",1536,443,false],"2048x2048":["https:\/\/www.talkcrypto.org\/blog\/wp-content\/uploads\/2016\/07\/digital-signatures.png",1892,546,false],"chromenews-featured":["https:\/\/www.talkcrypto.org\/blog\/wp-content\/uploads\/2016\/07\/digital-signatures.png",1024,296,false],"chromenews-large":["https:\/\/www.talkcrypto.org\/blog\/wp-content\/uploads\/2016\/07\/digital-signatures.png",825,238,false],"chromenews-medium":["https:\/\/www.talkcrypto.org\/blog\/wp-content\/uploads\/2016\/07\/digital-signatures.png",590,170,false]},"author_info":{"info":["seandotau"]},"category_info":"<a href=\"https:\/\/www.talkcrypto.org\/blog\/category\/blockchain\/\" rel=\"category tag\">Blockchain<\/a>","tag_info":"Blockchain","comment_count":"2","_links":{"self":[{"href":"https:\/\/www.talkcrypto.org\/blog\/wp-json\/wp\/v2\/posts\/78","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.talkcrypto.org\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.talkcrypto.org\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.talkcrypto.org\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.talkcrypto.org\/blog\/wp-json\/wp\/v2\/comments?post=78"}],"version-history":[{"count":9,"href":"https:\/\/www.talkcrypto.org\/blog\/wp-json\/wp\/v2\/posts\/78\/revisions"}],"predecessor-version":[{"id":949,"href":"https:\/\/www.talkcrypto.org\/blog\/wp-json\/wp\/v2\/posts\/78\/revisions\/949"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.talkcrypto.org\/blog\/wp-json\/wp\/v2\/media\/90"}],"wp:attachment":[{"href":"https:\/\/www.talkcrypto.org\/blog\/wp-json\/wp\/v2\/media?parent=78"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.talkcrypto.org\/blog\/wp-json\/wp\/v2\/categories?post=78"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.talkcrypto.org\/blog\/wp-json\/wp\/v2\/tags?post=78"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}