✍️ Digital Signature Demo (ECDSA)

Step 1: Generate a key pair

Use the browser's built-in Web Crypto API to try the full workflow of ECDSA (Elliptic Curve Digital Signature Algorithm, P-256 curve): generating a key pair, signing a message, and verifying the signature. Everything runs entirely in your browser — the private key is never sent externally.

How to use

  1. Click "Generate key pair" to create a public/private key pair.
  2. Enter a message to sign and click "Sign".
  3. Enter a message to verify (the same one, or a deliberately changed one) and click "Verify" to see the result.

How the calculation works

A digital signature proves that a message came from the holder of a key (authenticity) and has not been changed (integrity). This tool uses the browser's Web Crypto API to demonstrate signing and verifying with ECDSA (the Elliptic Curve Digital Signature Algorithm). 1. Generate a key pair: a private and public key on the P-256 curve. 2. Sign: the SHA-256 hash of the message is signed with the private key. The signature is two 32-byte values, r and s, joined into 64 bytes (128 hex characters). 3. Verify: the public key, message and signature are used to check the signature. Only the private key holder can sign, but anyone with the public key can verify. Changing even one character of the message makes verification fail.

Worked example

1. Click "Generate keys" to create a key pair. 2. Sign "Hello, Heron Tools!" to get a 128-character hex signature. 3. Verifying with the same message shows "valid signature". 4. Change the message to "Hello, Heron Tools?" and verify: "invalid signature". ECDSA uses a random value each time it signs, so signing the same message again gives a different signature (and every one verifies).

Things to be aware of

  • Signatures here are r and s concatenated (IEEE P1363 format). OpenSSL and many other tools use DER encoding instead, so the formats are not directly interchangeable.
  • Keys exist only in memory while the page is open and disappear on reload.
  • Digital signatures are used in software distribution, e-contracts, TLS certificates and national ID card certificates.

FAQ

What are digital signatures used for?

They let anyone with the public key confirm that a message was genuinely created by the holder of the private key and hasn't been tampered with since. They're widely used for software distribution, TLS certificates, and more.

What happens if I change the message before verifying?

Verification will report "invalid" — since a signature is mathematically tied to the exact message content, changing even one character breaks the match. Try it to see for yourself.

Is the private key stored anywhere?

No — the key pair only exists in memory while the page is open and disappears on reload. It's never sent externally or persisted.