New Issue: Orbital Catastrophe Ahead? Read Now

Are Digital Signatures Safe?

Join Our Community of Science Lovers!

The success of e-commerce relies on one thing, really: companies must be able to guarantee that confidential information--credit card numbers, say--are kept unaltered as they travel through cyberspace. A widely-used technique is the Digital Signature Algorithm (DSA), designed by the National Security Agency and approved under the Digital Signature Standard from the National Institute of Standards and Technology. This so-called public-key encryption method generates a numerical "signature," which in theory makes it possible for software at the receiving end of a transaction to verify a message's integrity.

In practice, though, a scientist at Bell Labs--the research and development arm of Lucent technologies--has now discovered that DSA will be vulnerable to tampering in the near future. "While e-commerce is not currently threatened," says Daniel Bleichenbacher, "a good cryptosystem should always have a comfortable security margin. That is, it should be secure even in 10 or 20 years from the day it is used, assuming the usual progress in hardware development. Without a fix, DSA would not have that security margin."

Indeed, Bleichenbacher found a significant flaw in part of the system that generates virtually random numbers. Instead of churning out different digits with equal probability, the program is twice as likely to select numbers within a certain range. And this bias makes the numbers--and hence the numerical signature--easier to crack using a supercomputer.


On supporting science journalism

If you're enjoying this article, consider supporting our award-winning journalism by subscribing. By purchasing a subscription you are helping to ensure the future of impactful stories about the discoveries and ideas shaping our world today.


"NIST commends Dr. Bleichenbacher for his work and agrees that the weakness due to the bias of the random key generation that he has discovered should be fixed to preserve the future security of the DSA," says Edward Roback, chief of the Computer Security Division in NIST's Information Technology Laboratory. "In the meantime, those who are using DSA can continue to use it with confidence that DSA signatures done under the present standard will remain secure for many more years." NIST is preparing a revision of DSA, which will be proposed in February.

Subscribe to Support Independent Journalism

Great science journalism requires human expertise, time, effort and creativity. And it costs money. That’s why I and the journalists here at Scientific American hope you’ll join our community.

When you subscribe, you are supporting staff and freelance journalists who are passionate about telling science stories that are true, important and compelling. Our editors and reporters are often experts in their fields, which means they understand the nuances of big discoveries and can untangle the breakthroughs from the hype. With a subscription, you are also supporting rigorous fact-checking to ensure the words we publish are precise and accurate. And you’re supporting original illustrations, graphics and photos that bring you closer to an advanced laboratory, an ice sheet in Antarctica or a space mission in orbit. You’re helping us craft other types of high-quality journalism as well: Our newsletters are carefully written, edited and curated by staffers you have or will come to know and love. Our Science Quickly podcast is based on original reporting, collaboration with editors and scientists and exacting production.

Subscriptions keep this engine running so we can continue to deliver thoughtful, rigorous and independent science journalism to you. In an era of viral misinformation, this work is crucial. If you value what we do, I hope you’ll consider joining us as a subscriber

Thank you,

Jeanna Bryner, Editor in Chief, Scientific American

Subscribe