Using digital signatures only with trusted applications

One of the main differences between a digital signature and a written signature is that the user does not “see” what he signs. The user application presents a hash code to be signed by the digital signing algorithm using the private key. An attacker who gains control of the user’s PC can possibly replace the user application with a foreign substitute, in effect replacing the user’s own communications with those of the attacker. This could allow a malicious application to trick a user into signing any document by displaying the user’s original on-screen, but presenting the attacker’s own documents to the signing application.

To protect against this scenario, an authentication system can be set up between the user’s application (word processor, email client, etc.) and the signing application. The general idea is to provide some means for both the user application and signing application to verify each other’s integrity. For example, the signing application may require all requests to come from digitally signed binaries.

——

To obtain your Digital Signature Certificate, please visit http://www.digitalsignature.in or contact our Kolkata office for more details or call +91-9432644547