cryptographic signing

Designs, implements, and evaluates systems and protocols that create, attach, verify, and manage cryptographic digital signatures to ensure authenticity, integrity, and non‑repudiation of digital objects. This includes building signature algorithms and libraries, signing/verification toolchains and APIs, key and certificate management, and analysing the security properties and threat models of signing uses such as code signing for software artifacts.

cryptographicsigning

Recent Skill Trend

Momentum and market value over time
Trending
Score
No comparison yet
-0.06
Oct 01, 2026Oct 01, 2026
Career
Value
No comparison yet
$212K/year
Oct 01, 2026Oct 01, 2026

Must-Read Papers

Most classic and influential ideas
View more

Blockchain Signatures to Ensure Information Integrity and Non-Repudiation in the Digital Era: A comprehensive study

Oct 26, 2025
KB
Kaveri Banerjee
🏛️ Adamas University | Nopany Institute of Management Studies

Blockchain systems must simultaneously ensure data integrity and non-repudiation; however, existing digital signature schemes face multiple challenges in decentralized settings—including inefficient aggregation, malleability vulnerabilities, limited native support for multi-signature protocols, and lack of post-quantum security. This paper systematically compares mainstream signature schemes—ECDSA, BLS, and threshold signatures—through rigorous cryptographic analysis, evaluating their underlying security assumptions, computational overhead for signing and verification, and practical suitability for consensus mechanisms and smart contract execution. Our key contribution is a novel, scenario-driven signature selection framework tailored to distinct on-chain use cases: high-throughput payments, auditable governance, and post-quantum migration. The framework explicitly characterizes trade-offs among performance, security guarantees, and scalability, and provides concrete implementation optimizations and evolutionary pathways toward quantum-resilient, efficient, and interoperable blockchain authentication.

Analyzing cryptographic properties and security assumptions of schemesComparing suitability for consensus, scalability, and attack resistanceSurveying digital signature schemes for blockchain non-repudiation

An Industry Interview Study of Software Signing for Supply Chain Security

Jun 12, 2024
KG
Kelechi G. Kalu
🏛️ Purdue University

Increasing complexity in software supply chains is compounded by low adoption rates and inconsistent implementation of software signing practices, undermining trust in software provenance and integrity. Method: We conducted semi-structured interviews with 18 security practitioners across 13 organizations and applied thematic coding alongside cross-organizational comparative analysis. Contribution/Results: We systematically identify technical, organizational, and human barriers to signing adoption; propose the first practice-oriented “Software Supply Chain Factory Signing Model”; reveal industry-wide divergences in perceived necessity of signing; and demonstrate how internal/external security incidents and evolving compliance requirements dynamically shape adoption decisions. Our four core findings provide empirical grounding for optimizing standards, guiding tool development, and strengthening enterprise governance—advancing software signing from superficial compliance toward substantively effective assurance.

CybersecuritySoftware SigningSoftware Supply Chain

Centralized package registries (e.g., PyPI, npm) strengthen security controls, yet their authority collapses at distribution boundaries—including mirrors, corporate proxies, repackaging, and air-gapped transfers—rendering them insufficient for source authentication, integrity assurance, and accountability. Method: This paper proposes a trust extension model tailored to modern software distribution, formally characterizing the necessity and adaptability requirements of cryptographic signing across mirrors, proxies, and offline environments; it evaluates the synergistic defensive efficacy of centralized registries and end-to-end signing through historical practice and trust boundary theory. Contribution/Results: We establish software signing as a foundational trust primitive that transcends registry-level governance, providing a verifiable, traceable, and auditable technical basis for cross-boundary trusted distribution—thereby enabling robust provenance verification, tamper-evident integrity, and enforceable accountability across heterogeneous deployment contexts.

Registry security alone cannot guarantee trust across distribution boundariesSigning provides essential defense layer for software supply chain assuranceSoftware signing ensures artifact integrity and verifies producer identity

This study addresses the usability–security trade-off in electronic signature systems by conducting the first controlled user experiment (N=20) empirically comparing hardware-token-based and remote-signature systems. Usability and security perceptions were assessed via task completion rates, Likert-scale questionnaires, semi-structured interviews, and statistical tests (t-tests and non-parametric tests). Results indicate that remote signing is significantly more usable (p < 0.01), whereas token-based signing is significantly more trusted (p < 0.01). Although no statistically significant overall preference emerged, 65% of participants favored remote signing—revealing a practical, convenience-driven adoption trend. The study fills an empirical gap in jointly evaluating end-user perceived usability and security in electronic signature systems, providing critical human factors evidence for system design and regulatory policy.

Compares user perception of security and convenienceEvaluates usability of token-based vs remote e-signaturesIdentifies trade-offs between usability and security

Latest Papers

What's happening recently
View more

This work addresses the interoperability challenges in digital credential ecosystems, which stem from heterogeneous standards and independent evolution, and which traditional approaches fail to fully explain—particularly regarding incompatibilities that persist even under shared data models and the precise trust requirements of verifiers. To resolve this, the paper proposes a verifier-centric conceptual model that decomposes credential verification into three layers: signature validation (L1), semantic interpretation (L2), and validity assessment (L3). It further introduces two orthogonal planes—institutional and logistical—to construct a five-function framework within a three-dimensional deployment space. Building on this foundation, the authors design the Shinken framework, which integrates trust declarations, verification material exchange, and deployment strategies to enable cross-stack analysis. Evaluations across four learner credential stacks and an accreditation federation demonstrate that the model effectively elucidates and mitigates key issues including interoperability barriers, verification overhead, privacy risks, and terminological ambiguity.

digital credentialecosysteminteroperability

This study addresses the lack of authenticity verification in Git commit authorship, where identity resolution relies solely on unverified claims. Leveraging the World of Code V2604 dataset, this work presents the first large-scale analysis of cryptographic signatures (PGP, SSH, and X.509) across 5.8 billion commits, introducing A2trust—a novel four-tier identity trust labeling framework that distinguishes declared identities from cryptographically bound ones. The contributions include the release of c2sigFull, a large-scale signed-commit dataset; the construction of an author-key graph that disambiguates organizational and personal keys; and the generation of a high-precision alias gold standard for 17.59% of signed commits. These resources establish cryptographic anchors for software identities, enabling trustworthy identity linkage and reproducible research in software provenance.

attested identitycode provenancecryptographic signature

This work addresses a central challenge in system security: formally verifying that system designs and implementations satisfy intended safety properties and support security certification. The authors propose a systematic approach grounded in proof assistants, integrating interactive theorem proving and formal methods to precisely model and machine-check critical security properties across diverse domains—including system security, language-level security, secure compilation, and cryptography. By enabling rigorous, machine-verifiable proofs of correctness, this methodology significantly strengthens the formal assurance of security properties and provides a unified theoretical framework and toolchain for constructing verifiable and certifiable secure systems.

language-based securityproof assistantssecure compilation

Hot Scholars

VS

Vineeth Sai Narajala

Security Engineer, Meta | Amazon Web Services | Nordstrom | University of Washington - Seattle
CybersecurityGenAI
QW

Qin Wang

ETH Zurich
Domain AdaptationComputer Vision
KD

Kasun De Zoysa

Deputy Director/Professor in Computer Science at University of Colombo School of Computing (UCSC)
Information SecurityCryptographyDigital ForensicICT4D
ML

Miguel L. Pardal

INESC-ID, Instituto Superior Técnico, Universidade de Lisboa, Portugal
CybersecurityInternet of ThingsCloud ComputingBlockchain
SE

Samih Eisa

INESC-ID, Instituto Superior Técnico, Universidade de Lisboa
Digital TwinsVVUQMultimodal AIContinual Learning