Digital Signatures: Proving Who Signed and That Nothing Changed
A signature is asked to establish four things: that a named holder of one private key signed, that they meant to sign, that nothing in the document changed afterwards, and that all of it can still be shown years later. A digital signature carries the first and third mechanically. The fourth is not a property of the signature at all. The record that survives is something somebody has to keep.
Consider the last thing anybody signed, and ask who the signature was actually for. The signer was there and the person across the table was there, so neither of them needed convincing. A signature is written for a stranger in the future. Somebody who was not in the room, who has no reason to take anybody's word for anything, and who is holding the document years later when the office has moved, the officer has retired and everybody's memory of that afternoon has gone soft. Every property a signature is asked to carry is a property that stranger needs. The subject gets much easier the moment the question stops being what a signature is and starts being what that person, on that later day, will actually be able to check.
What is a signature actually being asked to prove?
Four things, and they are worth pulling apart before any mechanism appears. A mechanism only carries some of them, and finding out which ones it quietly drops is the useful part.
| No. | The property | The question it answers for the stranger in the future |
|---|---|---|
| 1 | Identity | Who signed this, and can that be tied to a named person rather than to a description of one? |
| 2 | Intent | Did they mean to sign, or did the signature happen as a side effect of something else they were doing? |
| 3 | Integrity | Is this the same document that was signed, down to the last clause and the last figure? |
| 4 | The record that survives | Can all of the above still be shown today, years after the signing, by somebody who was not there? |
Read that fourth row again. The fourth row is doing something the other three are not. Properties 1, 2 and 3 are about the moment of signing. Property 4 is about every day after it. The first three are settled in an afternoon and the fourth is settled over a decade. An institution can get the first three perfectly right and still find itself unable to prove anything at all.
An everyday version, and it is exact rather than loose. Somewhere in most households there is a photograph of a wedding. Everybody in it can be named, so identity holds. Nobody has cut anything out of it or pasted anything into it, so integrityThe property that nothing in the document changed after it was signed, so the thing being read now is the thing that was agreed then. holds. Somebody meant to take it, so intentThe property that the signer meant to sign. No mechanism produces it on its own; it comes from the circumstances of the act. holds. Then a grandchild asks which year it was, and the room goes quiet. Nobody ever wrote it on the back. Nothing about the photograph has decayed. The one fact that decayed is the year, known to everybody in the room on the day and written down by nobody.
Which of the four properties is not settled at the moment of signing at all?
Is a typed name at the bottom of an agreement a digital signature?
No, and the difference is not one of strength. A typed name and a digital signature are two different artefacts that answer different questions, and a reader who treats them as a weak version and a strong version of one thing will make the same mistake an institution makes when it buys the first and reports it as the second.
An electronic signatureA typed name, a tick box or an image of a signature, which carries intent at best and nothing mechanical about identity or integrity. is the broad category. A typed name at the foot of a printed sheet. A tick in a box beside the words I agree. A scanned image of a handwritten signature dropped into a file. The squiggle drawn with a fingertip on a delivery agent's handheld screen. Almost everybody has produced one and almost nobody would recognise their own.
The four questions can be put to that squiggle. Identity: the screen recorded a finger movement and has no way to attach a name to it, so it establishes nothing. Integrity: nothing either. The delivery note could be reprinted with different contents tomorrow and the squiggle would sit under it just as happily. Intent: this one it does carry, and honestly. The person knew they were accepting the parcel and meant to do it. An electronic signature carries property 2 at best, and carrying property 2 is not nothing. In an enormous number of ordinary situations intent is the only thing in dispute.
A digital signatureA private key operation over a fingerprint of a document, which stops matching the moment anything in the document changes. is a much narrower thing. The mark it leaves is a private key operation over a fingerprint of the document. A private key is set out under digital assets and tokenisation, where it does the job of controlling an asset. The same object does a completely different job here, producing a mark that only one holder could have produced and that is tied to one exact document. A mark of that construction carries properties 1 and 3 mechanically, meaning without anybody's memory, testimony or good faith being involved.
A customer types their name at the bottom of an agreement and ticks a box saying they agree. What has been established?
How does a private key operation show that nothing changed?
Signing is the one part of the subject where people expect mathematics, and there is none needed. Three steps, and all three fit on the back of an envelope.
Step one, a fingerprint of the document is computed. A fixed, published procedure reads every byte of the agreement and returns a short value. The important property is not that the value is short. The value is brittle in a very particular way: change one character anywhere in the document, add one space, alter a single digit in a figure, and the value that comes back is not slightly different, it is wholly different. There is no near miss. There is no partial match. A document that has moved by one comma produces a fingerprint that looks nothing like the original one.
Step two, the private key operation is applied to that fingerprint. Not to the document, to the fingerprint. That operation produces the mark that only the holder of that one key could have produced, and it is why a signature made this way is a fixed size whether the document runs to one sheet or four hundred.
Step three, and this is the step that does the work, anybody can repeat step one later. Running the same published procedure over the document handed over today produces a fingerprint. Taking the signature and, using the public counterpart of the signing key, recovering the fingerprint that was signed produces a second one. The two then sit side by side. If they match, the document in hand is the document that was signed, and it is the document that was signed by that key holder. If they do not match, something moved, and nothing says what moved or by whom, only that the two are no longer the same thing.
The check requires very little. The signer is not needed. The institution that arranged the signing is not needed. No records of the transaction are needed either, and no trust in the person handing the file over. A self contained check of that kind is exactly what carrying properties 1 and 3 mechanically means.
One word of the agreement is changed after signing. What happens to the check?
So what is the signature actually asserting?
Three things, and it is worth saying plainly that this is the whole list. Everything else people believe a signature says is something they brought to it themselves.
Claim one, who signed. A mark that only one key holder could have produced sits on this document, and a certificate names that holder. Claim two, that nothing changed since. The document in hand is byte for byte the document that mark was made over. Claim three, when. Unlike the other two, the time is not contained in the signature at all. The time has to be supplied from outside, and everything difficult about old signatures follows from that.
Each claim has its own failure, and a claim that cannot be broken is a claim that is not understood.
Claim one fails when the key and the person come apart. The mechanism proves a key was used. The mechanism does not prove a person used it. When a colleague is handed a credential so they can finish something while the holder is travelling, every signature they make is mechanically perfect and attributed to the holder. The split between key and person is not hypothetical at Sumeru Bank Limited, an invented mid-sized Indian bank running a retail loan intake chain. Of the four numbered arrangements the bank considered for moving customer data, set out under data sharing in finance, arrangement 1 was refused at design and never used. Under arrangement 1 a customer hands over a credential and the recipient signs in as them, and after that nobody can tell the two apart in any record.
Claim two fails at the edge of the document. The check covers what was inside the fingerprint and nothing else. An annexure that was referred to but never attached, a rate table that lived on a separate screen, a term the customer read in one version of the wording and not another: none of that is inside the sealed bytes, so none of it is protected, and the check will pass happily on a document that is missing the very sheet the argument is about.
Claim three fails silently, and silence is what makes it the dangerous one. The other two failures are visible on inspection. A missing time is invisible on the day, invisible for years, and then arrives all at once on the afternoon somebody finally asks. Claim three is where the rest of the difficulty sits.
What does a signature never prove, however strong it is?
Three things, and every one of them is something people routinely assume it covers.
A signature does not prove the signer read the document. Nothing in a key operation touches a pair of eyes. A person who scrolled to the bottom in four seconds produces a signature that is byte for byte as strong as one produced by a person who spent an hour on it, and no examination of the artefact could ever separate the two.
A signature does not prove the signer understood the document. Understanding is a separate limit from reading, and worth keeping separate. A person can read every word of a term and still have no idea what it will do to them in month fourteen. The signature is silent about comprehension in exactly the way it is silent about reading.
A signature does not prove the signer had the authority to sign. A perfectly valid signature can be made by somebody with no standing to bind anybody. Permission to act is a separate layer altogether, layer 4 of the four identity layers set out under digital identity, and it lives in the institution's own records of who holds what mandate. The mechanism has no opinion on it whatsoever.
The consent record earns its keep here. Field 9 of its nine numbered fields, set out under consent management, records what was actually on the screen when the customer agreed. Field 9 exists because a signature answers who and what and never how it was presented, so an institution that wants any evidence at all about the second question has to capture it deliberately and separately. A signature and a record of what was shown are answers to two different questions, and holding a perfect one of the first kind says nothing about the second.
A signed agreement is produced in a dispute and the customer says they never understood one of the terms. Does the signature settle that?
Why might a signature that verifies today fail to verify in five years?
Because of a small object sitting beside the signature that most people never think about at all: the certificateThe record naming the holder of a key. It has a life of its own, is issued for a period, and can lapse while the signatures made under it remain untouched..
The mark on the document proves that one particular key was used. On its own that is a statement about a key and not about a person, and a separate record naming the holder of that key is what turns the first into the second. The certificate is issued for a period, and it ends. Ending is not a fault, and it is not the result of anything going wrong: a record that never ended would be a record nobody could ever correct.
Here is the everyday version, and it is uncomfortably close. Somebody hands over a note and an identity card, and the card ran out four years ago. The note is genuine. The handwriting is theirs. Nothing about the note has changed. Nothing on the table answers whether the note was written while the card was still good, and the gap is not about honesty, it is about the absence of one small fact. If the note had a date somebody else had recorded, the whole difficulty would evaporate in a second.
A lapseThe moment a certificate stops being current. Signatures made before it are untouched, but showing they were made before it now needs a preserved time. does not reach back and spoil a signature that was made while the certificate was current. A lapse removes the ability to show it. Losing the proof is not the same as losing the fact, and it feels identical to whoever is holding the file.
So whether an old signature still stands comes down to two questions asked in order, and the second only matters because of the first.
A signature was valid when it was made, and the certificate naming the key holder has since lapsed. What is needed for the signature to still stand?
What happened when the invented bank pulled 500 old agreements?
Everything above this line is craft. Here is what it looked like when somebody actually tested it.
At month 12, before the annual re-approval, Neelima Rao in the risk function ran the independent validation of the intake chain at Sumeru Bank Limited. She did not build any part of it, and building none of it is what makes a validation independent. Among a great many other things she pulled 500 signed agreements out of the archive and tried to verify each one.
Six of the 500 could not be verified, being 1.2 per cent. Not six that were forged. Not six where a clause had been altered. Six where the signing certificate had lapsed and no timestamp of the moment of signing had been preserved, so nothing in the file could establish that the signature had been made while the certificate was still current.
Sit with what that means for a second. The shape of it is unusual. In all six, properties 1, 2 and 3 held. The signatures were valid when they were made. The key holders were named. The documents were intact, byte for byte, exactly as they had been on the day. Property 4, the record that survives, is the one that broke, and it broke without anybody doing anything wrong at the moment of signing.
Scaled to a month, 1.2 per cent of the invented bank's signed agreements is about 59. The month's signed agreements are a floor of 4,902, being the count of applications the scoring model accepted with nobody touching the file, and it is a floor rather than a total because the outcomes of the 3,010 files routed to a person are not recorded anywhere in this case. So the honest sentence is: at least 4,902 signed agreements in the month, of which about 59 would already fail this test after a year.
How would a firm find out whether its own old signatures still verify?
What does a failure rate of about one in a hundred a year do over ten years?
Care matters at this step. The invented bank measured one hand check at one moment: 6 of 500, being 1.2 per cent. The bank did not measure a trend, and nobody has watched this rate over a decade. A measured point and a projected curve are two very different objects, so the 1.2 per cent a year is carried forward as an assumption and labelled as an assumption every time it is used.
On that assumption, 98.8 per cent of a month's agreements survive the first year. Then 98.8 per cent of what is left survives the second, and so on. Compounding on a shrinking base is what makes this a curve rather than a straight line. Multiplying 0.988 by itself ten times gives 0.886. So after ten years about 88.6 per cent of that month still re-verifies and 11.4 per cent does not.
Everybody nods at 1.2 per cent. Almost nobody predicts 11.4 per cent. The gap between the two reactions is the whole of the difficulty, and it is the same shape as the interest on a small recurring debt that nobody servicing it ever quite sees coming.
Before the control below is moved: 1.2 per cent of signed agreements fail to re-verify in a year. On the same assumption, what share still verifies after ten years?
Move the years, and watch the space between the two lines open up
One control: the number of years since signing, from 0 to 20. Two consequences are drawn together. The curve is the share of one month of signed agreements that still re-verifies, and the flat line above it is what the same month does when a timestamp of the signing moment was preserved. Beneath them the same month is drawn as one bar splitting into what can still be proved and what cannot. At the default of 10 years, 88.6 per cent still re-verify, being 4,344 of a floor of 4,902 signed agreements, and about 558 do not. The assumption of 1.2 per cent a year comes from one hand check of 500 agreements at the month 12 validation, in which 6 could not be verified.
Years since signing: 10.0. The assumed failure rate is held at 1.2 per cent a year throughout.
Educational illustration. Figures are the invented bank's own and describe one deployment. Assumptions held on screen: a floor of 4,902 signed agreements in the month; a failure rate of 1.2 per cent a year, taken from one hand check of 500 agreements in which 6 could not be verified and carried forward as an assumption rather than as a measured trend; compounding, so the share is 0.988 raised to the number of years; and a flat line assuming a preserved timestamp at signing. The flat line holds at 4,902 because the failure being drawn cannot happen once the signing moment is recorded. Counts of agreements still re-verifying are rounded down to whole agreements, so the count that can no longer be proved is never understated.
How many agreements is that, and against what base?
Percentages are easy to nod at, so put the same month in front of yourself twice.
On the day they were made, a floor of 4,902 signed agreements all verify. Every one of them. Ten years later, on the assumption above, about 4,344 of them still verify and about 558 do not. Nothing was done to those 558 in the intervening decade. Nobody edited them, lost them, mishandled them or disputed them. The 558 sat in the archive being perfectly correct, and the ability to prove them drained away underneath.
The gap between the same month read at two moments is the entire subject of property 4, and no measurement taken on the day of signing can see it.
Say the base carefully. An institution quietly overstates itself right here. The 4,902 is a floor and not a total. The figure counts applications in month 6 that the scoring model accepted with nobody touching the file, being 57.0 per cent of the 8,600 that completed onboarding and reached the decision engine. Files routed to a person can also end in a signed agreement, and this case records no outcome for those 3,010, so the true monthly count is higher by an amount nobody here can state. Which means the 558 is a floor too. Where a case records a floor, every number built on it stays a floor, and an account that quietly promotes one to a total has invented a figure.
What has to be preserved at the moment of signing?
Four things, and the list is short enough to be slightly embarrassing when set beside what its absence costs.
Keep the document exactly as it was signed, down to the byte. A reformatted copy is a different document to the check even when it is the same agreement to a reader. Keep the signature. Keep the certificate as it stood on the day, rather than assuming somebody else will still be publishing it in a decade. And keep evidence of when the signing happened, recorded by something other than the signer. The moment then survives the certificate that named them.
The fourth item is the preserved timestampEvidence of when a signing happened, recorded at the time and kept separately, so the moment outlives the certificate that named the key holder., and it is the whole of the fix. With it, re-verificationChecking an old signature again years later. It is the only test that exercises the fourth property, and nothing else reveals whether it holds. ten years later asks a question that can be answered: was this made while the certificate was current, yes, here is the record of when. A preserved timestamp at signing holds the line flat at the full 4,902 for as long as anybody cares to ask, and the invented bank did not specify one.
What does holding the line actually cost?
The cost is the part that stings. The intake chain at the invented bank cost Rs 2,40,00,000/- to build once and Rs 65,00,000/- a year to run, and both figures are the bank's own. Against those, a preserved timestamp is not a system. A preserved timestamp is a line in a specification saying what the archive keeps, and this case records no separate cost for it at all.
But it has a deadline, and the deadline is brutal in a way most controls are not. Almost everything else in this sequence can be fixed late. A second route for wrongly refused applicants can be built in month 9 and it helps everybody who arrives in month 10. A missing consent field can be added to the record and every consent captured afterwards carries it. A preserved timestamp cannot be added to a signature that has already been made. The fact it preserves stopped existing the moment nobody wrote it down.
So every agreement signed before the specification is corrected is permanently outside the fix. The bank can hold the line flat from tomorrow, and it can do nothing whatsoever about the months already in the archive. A deadline like that is a very unusual property for a control that costs nothing, and it is why a preserved timestamp belongs in a specification rather than in a plan to improve things later. The omission is the same class as item 7 of the eight numbered data requirement items, the item asking what may be retained and for how long: nobody had written down what happens after the day, so nothing happened after the day.
The fix is a preserved timestamp at signing. When does it have to be specified?
How this gets used by somebody who is not building anything
Somebody in a control or audit function has one move here and it is not reading a policy. Pull a sample of old signed agreements and try to verify each one. The first three properties are checked constantly by ordinary use and the fourth is checked by nobody until the afternoon it is needed, so pulling that sample is the only test that exercises property 4. The invented bank found its six because Neelima Rao did exactly that at month 12, and nothing else in the annual review would have surfaced them.
Somebody assessing an arrangement from outside asks two questions instead of one. Everybody asks which signing method is being used, and the answer settles properties 1 and 3. Ask instead what is preserved at the moment of signing, and ask how long the agreement has to stand up against how long the certificate lives. A loan running twenty years and a certificate issued for a period measured in a couple of years are on very different clocks, and the mismatch between those two clocks is the whole risk in one sentence.
And there is something a household can use directly. When something is signed electronically, the document is not the only thing worth saving. Save whatever acknowledgement came back carrying a time on it, from somebody other than the signer: the message, the receipt, the reference number with a date attached. The acknowledgement belongs with the agreement rather than in a mailbox that will be cleared out. Keeping it is the household version of the same four item list, and it costs nothing but the decision.
The error that gets made, and what it costs
The specification for the intake chain said how agreements would be signed. The specification was detailed, it was reviewed, and on the mechanism it was right: properties 1 and 3 were carried, and the invented bank could show who had signed and that nothing had changed. The specification never said what the archive should keep afterwards, and nobody noticed the omission because nothing about it produces a symptom on the day.
An error of this kind has no incident, no alert and no unhappy customer at the moment it is made, and that is precisely why it survives every review that looks for problems rather than for absences. A control that fires when something goes wrong announces itself. A record nobody kept announces nothing at all, for years.
The cost, stated in the invented bank's own figures and on its own assumption of 1.2 per cent a year: about 59 agreements from a single month already fail this test after one year, on a floor of 4,902 signed agreements. By year ten it is about 558 from that one month, and every later month is stacking its own share behind it. Not one of those agreements is faulty. Every one of them was signed properly by a named person who meant to sign, over a document that has not moved by a comma since. The 558 are simply agreements nobody can now attach a time to, and no amount of money spent afterwards buys that time back.
Named, and to be read at the source
The Reserve Bank of India at rbi.org.in states what a signature is worth for a lender, sets out the recognised routes for signing, and says what a regulated lender is expected to retain and for how long. Where the institution is a market intermediary rather than a lender, the equivalent expectations sit with the Securities and Exchange Board of India at sebi.gov.in. Where the question is what a board is accountable for in keeping the records of a company, that sits with the Ministry of Corporate Affairs at mca.gov.in. The international standards that national expectations on record keeping descend from are published by the Bank for International Settlements at bis.org, and what India actually does is stated by the Indian authorities rather than by the standard. No authority publishes those four properties as a single definition, and the words used for them differ from one rule to the next. Every one of those must be read at the source named, on the day it matters.
Covered elsewhere. The authorities named above set what a firm is required to obtain a signature for and which routes are recognised, and both are covered separately. The consent record, its nine numbered fields and why the record of what was on the screen exists are set out under consent management. Private keys used to control an asset are set out under digital assets and tokenisation, where the same object does a different job. How any learned component is fitted, validated or evaluated is established elsewhere.
Sources
| Source | Document | Site |
|---|---|---|
| Reserve Bank of India | Expectations on a regulated lender covering record keeping, digital lending and the retention of customer documentation | rbi.org.in |
| Securities and Exchange Board of India | Equivalent expectations where the institution taking the signature is a market intermediary | sebi.gov.in |
| Ministry of Corporate Affairs | Material on what a board is accountable for in maintaining the records of a company | mca.gov.in |
| Bank for International Settlements | International material on record keeping and operational resilience that national expectations descend from | bis.org |
Sumeru Bank Limited, its retail loan intake chain and Neelima Rao are invented.
Educational material. Not advice on any investment, tax, budget or market position.
