Unit-III Digital Signatures and Certificates
Unit-III Digital Signatures and Certificates
Certificates
By
Dr. Gopalakrishnan C
Assistant Professor
Digital Signature
✓ A digital signature is a mathematical technique which validates
the authenticity and integrity of a message, software or digital
documents.
✓ It allows us to verify the author name, date and time of
signatures, and authenticate the message contents.
✓ The digital signature offers far more inherent security and
intended to solve the problem of tampering and impersonation
(Intentionally copy another person's characteristics) in digital
communications.
Digital Signature
✓ The computer-based business information authentication interrelates
both technology and the law.
✓ It also calls for cooperation between the people of different
professional backgrounds and areas of expertise.
✓ The digital signatures are different from other electronic signatures not
only in terms of process and result, but also it makes digital signatures
more serviceable for legal purposes.
✓ Some electronic signatures that legally recognizable as signatures may
not be secure as digital signatures and may lead to uncertainty and
disputes.
Application of Digital Signature
2. Non-repudiation
3. Integrity
Application of Digital Signature
➢ Authentication is a process which verifies the identity of a user who wants to access the
system. In the digital signature, authentication helps to authenticate the sources of
messages.
➢ Non-repudiation
➢ Integrity
➢ Integrity ensures that the message is real, accurate and safeguards from unauthorized user
modification during the transmission.
Algorithms in Digital Signature
✓ They are essential for activities such as online banking, secure email
communication, software distribution, and electronic document signing.
✓ Expiration dates.
✓ Copy of certificate holder’s public key. (used for decrypting messages and
digital signatures)
✓ Digital certificate is also sent with the digital signature and the message.
Advantages of Digital Certificate
NETWORK SECURITY:
✓ A complete layered strategy is required by modern cybersecurity methods, wherein
many solutions cooperate to offer the highest level of protection against attackers.
✓ An essential component of this puzzle is digital certificates, which offer strong defense
against manipulation and man-in-the-middle attacks.
VERIFICATION:
✓ Digital certificates facilitate cybersecurity by restricting access to sensitive data, which
makes authentication a crucial component of cybersecurity. Thus, there is a decreased
chance that attackers will cause disturbance.
✓ At many different endpoints, certificate-based authentication provides a dependable
method of identity verification. Compared to other popular authentication methods
like biometrics or one-time passwords, certificates are more flexible.
BUYER SUCCESS:
✓ Consumers demand complete assurance that the websites they visit are reliable.
✓ Because digital certificates are supported by certificate authority that users’ browsers
trust, they offer a readily identifiable indicator of reliability.
Disadvantages of Digital Certificate
Phishing Attacks:
✓ To make their websites look authentic, attackers can fabricate bogus websites and obtain
certificates.
✓ Users may be fooled into providing sensitive information, such as their login credentials, which the
attacker may then take advantage of.
Weak Encryption:
✓ Older digital certificate systems may employ less secure encryption methods that are open to
intrusions.
Misconfiguration:
✓ Websites and online interactions can be attacked due to incorrectly configured certificates.
Digital Certificate vs Digital Signature
Feature Digital Signature Digital Certificate