Network and Cyber SecurityUnit 49 min read
Hash Functions & Digital Signatures: How Data Integrity & Authenticity Work
Unit 4 of Network and Cyber Security explores hash functions (how data is condensed into fixed-size fingerprints) and digital signatures (how to prove authenticity and non-repudiation), including their cryptographic principles, attacks, and real-world applications in security protocols like TLS and blockchain.
TAKEAWAYS:
- Hash functions convert any input into a fixed-length hash (e.g., SHA-256), ensuring data integrity and collision resistance.
- Digital signatures use asymmetric cryptography (RSA/ECDSA) to sign data, proving authenticity and non-repudiation.
- Common attacks (collision, preimage, birthday) exploit weaknesses in weak hash functions (e.g., MD5, SHA-1).
- Real-world uses: Password storage (bcrypt), blockchain (Bitcoin), and secure file verification (PGP).
- TLS/SSL uses hashes (HMAC) and signatures to secure web traffic (HTTPS).
- Exam focus: Compare hash functions, explain RSA signing, and trace a digital signature verification process.
1. Hash Functions: The Digital Fingerprint
A hash function takes any input (file, message, password) and produces a fixed-length hash value (e.g., 256-bit for SHA-256). Key properties:
- Deterministic: Same input → same hash.
- Fixed-length: Output is always the same size (e.g., 256 bits).
- Preimage resistance: Hard to reverse (given hash, find input).
- Collision resistance: Hard to find two different inputs with the same hash.
How Hash Functions Work
Example: Storing passwords securely.
- Bad practice: Store plaintext passwords (e.g.,
password123). - Good practice: Store hashes (e.g.,
5f4dcc3b5aa765d61d8327deb882cf99for SHA-256 ofpassword). - Even better: Use salted hashes (add random data to prevent rainbow table attacks).
Common Hash Functions
| Algorithm | Output Size | Security Level | Use Cases |
|---|---|---|---|
| MD5 | 128-bit | Broken | Legacy systems (avoid) |
| SHA-1 | 160-bit | Weak | Deprecated (collision attacks) |
| SHA-256 | 256-bit | Secure | Bitcoin, TLS, file verification |
| bcrypt | Variable | Secure | Password storage (slow hashing) |
Hash Function Attacks
- Preimage Attack: Given
H(x), findx(e.g., cracking MD5 hashes). - Second Preimage Attack: Find
x'such thatH(x) = H(x'). - Collision Attack: Find any two inputs
x ≠ ywithH(x) = H(y).- Example: SHA-1 collisions used to forge certificates (e.g., SHA-1 collision attack in 2017).
Worked Example: Detecting File Tampering
- Scenario: You download a software file (
app.exe) from a website. How do you verify it’s not corrupted? - Solution:
- Website provides a SHA-256 hash of the original file:
a1b2c3.... - You download
app.exeand compute its hash locally. - If your hash ≠ website’s hash → file is tampered with.
- Website provides a SHA-256 hash of the original file:
2. Digital Signatures: Proving Authenticity
A digital signature uses asymmetric cryptography (public/private keys) to:
- Sign data (prove you created it).
- Verify signatures (prove sender’s identity).
- Ensure non-repudiation (sender can’t deny sending).
How Digital Signatures Work (RSA Example)
sequenceDiagram
participant Alice as Alice (Sender)
participant Bob as Bob (Receiver)
participant Hash as Hash Function
participant RSA as RSA Algorithm
Alice->>Hash: Compute H(M) (hash of message M)
Alice->>RSA: Encrypt H(M) with private key → Signature (S)
Alice->>Bob: Send (M, S)
Bob->>RSA: Decrypt S with Alice's public key → H'(M)
Bob->>Hash: Compute H(M) (hash of received M)
Bob->>Bob: Compare H(M) == H'(M) → VerifySteps:
- Signing:
- Alice hashes the message (
H(M)). - Encrypts the hash with her private key → signature (S).
- Sends
(M, S)to Bob.
- Alice hashes the message (
- Verification:
- Bob decrypts
Swith Alice’s public key →H'(M). - Bob hashes
M→H(M). - If
H(M) == H'(M)→ signature is valid.
- Bob decrypts
Real-World Example: Bitcoin Transactions
- Problem: How does Bitcoin ensure transactions are authentic?
- Solution:
- A transaction is hashed (e.g., SHA-256).
- The sender signs the hash with their private key.
- The signature is broadcast to the network.
- Nodes verify the signature using the sender’s public key (stored in the blockchain).
- Why it matters: Prevents double-spending and fraud.
Digital Signature Algorithms (DSAs)
| Algorithm | Key Size | Use Case |
|---|---|---|
| RSA | 2048–4096 | TLS, code signing |
| ECDSA | 256–521 | Bitcoin, lightweight apps |
| DSA | 1024–3072 | Legacy systems |
Advantages:
- Authenticity: Only the private key holder can sign.
- Integrity: Any tampering breaks the signature.
- Non-repudiation: Sender can’t deny sending.
Disadvantages:
- Computationally heavy (slower than symmetric encryption).
- Key management is critical (lose private key → lose access).
3. Hash Functions vs. Digital Signatures
| Feature | Hash Functions | Digital Signatures |
|---|---|---|
| Purpose | Data integrity, checksums | Authenticity, non-repudiation |
| Input | Any data (file, message) | Hash of data + private key |
| Output | Fixed-length hash | Encrypted hash (signature) |
| Verification | Compare hashes | Decrypt signature with public key |
| Security | Preimage/collision resistance | Asymmetric cryptography |
| Example Use | Password storage, file checks | Code signing, TLS, blockchain |
4. Applications in Real World
In Nepal
eSewa & Khalti Payments
- Hashing: Transactions are hashed to ensure no tampering.
- Digital Signatures: Merchants sign transactions with private keys; eSewa verifies with public keys.
- Why it matters: Prevents fraud in online payments.
Nepal Rastra Bank (NRB) Digital Transactions
- Digital signatures are used in NEFT/RTGS transfers to authenticate senders.
- Example: When you transfer money via an app, the bank verifies your signature to confirm the transaction is from you.
NEPSE (Nepal Stock Exchange)
- Hashing: Used to verify trade orders (e.g., SHA-256 for order books).
- Digital signatures: Brokers sign trades to prevent forgery.
Globally
WhatsApp End-to-End Encryption
- Hashing: Used to verify message integrity.
- Digital signatures: Used in Signal Protocol to authenticate users.
- Example: When you send a message, WhatsApp signs it with your private key; the recipient verifies it with your public key.
Git Version Control
- Hashing: Every commit is assigned a SHA-1 hash (e.g.,
a1b2c3...). - Why it matters: Ensures no one alters the code history.
- Hashing: Every commit is assigned a SHA-1 hash (e.g.,
YouTube Video Authenticity
- Digital signatures: Used to verify video uploads (prevent deepfake spoofing).
5. Exam Tip: How to Score Full Marks
Define Clearly:
- "A hash function is a deterministic, fixed-length function that maps input to a hash value with preimage/collision resistance."
- "A digital signature is a mathematical scheme for verifying authenticity using asymmetric cryptography."
Compare Hash Functions:
- Always mention MD5/SHA-1 (broken) vs. SHA-256/SHA-3 (secure) in exams.
- Example answer:
"MD5 is vulnerable to collision attacks, while SHA-256 is collision-resistant and used in Bitcoin. SHA-1 is deprecated due to practical collision attacks in 2017."
Trace a Digital Signature Process:
- Signing: Hash → Encrypt with private key.
- Verification: Decrypt with public key → Compare hashes.
- Example:
"Alice signs a contract by hashing it (SHA-256) and encrypting the hash with her RSA private key. Bob verifies by decrypting with Alice’s public key and comparing hashes. If they match, the signature is valid."
Real-World Applications:
- Link to eSewa (payments), Bitcoin (transactions), or TLS (HTTPS).
- Example:
"In TLS, digital signatures ensure a website’s certificate is authentic. The browser verifies the signature using the CA’s public key."
Attack Scenarios:
- Weak hash: "MD5 is broken; use SHA-256 for passwords."
- Collision attack: "SHA-1 collisions can forge certificates (e.g., 2017 Shattered attack)."
Diagrams:
- Draw a hash function process (input → hash → verification).
- Draw a digital signature sequence diagram (signing → verification).
Final Note: Hash functions and digital signatures are the backbone of secure communications. Master their definitions, processes, and real-world uses to ace the exam!
Based on the PU BE Computer (PU) syllabus for Network and Cyber Security (CMP426), unit 4.
Discussion
Loading…