You are here. See how this question connects to other ideas.
Select a node to open its page · Expand to read within the map
One question
What do hashes and signatures prove?
Checking whether a file changed is different from checking who signed it.
- ContentCalculate→
- Hash digestCompare with trusted digest→
- Version check
A test report arrives with a hash and a digital signature. Both help you check the report, but they answer different questions.
A hash is a digest calculated from content using a particular algorithm. Recalculating it and comparing it with a digest from a trusted source helps check that the content matches. If an attacker supplies both the file and the supposedly correct digest, a match establishes no trusted source. Hashing is not encryption: it does not hide the original file or make guessable content secret.
A digital signature connects content to a signing key. The private key is used to sign; the corresponding public key is used to verify. Assuming secure algorithms and keys, successful verification supports the conclusion that the content was signed with that private key and has not changed. It does not establish which testing organization owns the key or whether the operator had permission to sign.
Check the report in layers
| Question | Evidence needed |
|---|---|
| Does the file match the version supplied by a trusted source? | Hash comparison or signature verification |
| Is this public key recognized as the organization’s signing key? | Evidence linking the key to the organization and establishing whether it remains valid |
| Was the sample actually tested? | Measurement procedures, sample records and review |
An organization can sign a report containing an incorrect measurement. This is why successful signature verification cannot be treated as confirmation of the findings.
Book and verification sources
This lesson develops a question from 《区块链实战》, Chapters 1 and 6, with the references below. It is a new explanation, not a book excerpt.
- NIST IR 8202 · Blockchain Technology Overview: mechanism and scope.
- W3C · Verifiable Credentials Data Model 2.0: mechanism and scope.
Check your understanding
Can a report with incorrect findings pass both a hash comparison and signature verification?
Yes. These checks concern the file and its signing evidence, not whether its measurements are true. The key’s association with the issuer and the report’s evidence still need checking.
Continue along a learning path
- From records to evidenceStep 2 of 5