Hashing and digital signatures · การแฮชและการลายเซ็นดิจิทัล
Hashing protects integrity
- We hashed passwords for secrecy. Hashing also protects integrity — proving data was not changed.
- Change even one character of the input, and the hash changes completely.
การแฮชปกป้องความสมบูรณ์
- เราแฮชรหัสผ่านเพื่อ ความลับ การแฮชยังปกป้อง ความสมบูรณ์ — ยืนยันว่าข้อมูลไม่ถูกแก้ไข
- เปลี่ยนตัวอักษรเดียวของอินพุต และค่าแฮชจะเปลี่ยนไปทั้งหมด
import hashlib
print(hashlib.sha256(b"hello").hexdigest()[:16])
print(hashlib.sha256(b"hellp").hexdigest()[:16]) # totally different
Checking a download
- Websites publish the hash of a file. After downloading, you hash your copy and compare.
- If the two hashes match, the file arrived intact. If not, it was corrupted or tampered with.
ตรวจสอบการดาวน์โหลด
- เว็บไซต์เผยแพร่ค่าแฮชของไฟล์ หลังจากดาวน์โหลดแล้ว คุณแฮชสำเนาของคุณและเปรียบเทียบ
- หากค่าแฮชทั้งสองตรงกัน ไฟล์มาถึงอย่าง สมบูรณ์ หากไม่ตรงกัน ข้อมูลอาจเสียหายหรือถูกดัดแปลง
Digital signatures
- A digital signature proves who sent something and that it was not changed.
- The sender hashes the message and encrypts that hash with their private key.
- Anyone can check it with the sender's public key — only the real sender could have made it.
ลายเซ็นดิจิทัล
- ลายเซ็นดิจิทัล ยืนยันว่า ใคร ส่งสิ่งนั้น และ ว่าไม่มีการเปลี่ยนแปลง
- ผู้ส่งแฮชข้อความแล้วเข้ารหัสค่าแฮชนั้นด้วย คีย์ส่วนตัว ของตน
- ทุกคนสามารถตรวจสอบได้ด้วย คีย์สาธารณะ ของผู้ส่ง — มีเพียงผู้ส่งจริงเท่านั้นที่จะสร้างมันได้
Your turn
- Compare the hashes of an original and a received message.
Truemeans the message is intact.
Covers: A-Level 17.1 (digital certification), 6.2 (integrity).
ถึงเวลาฝึกฝน
- เปรียบเทียบค่าแฮชของต้นฉบับและข้อความที่ได้รับ
Trueหมายความว่าข้อความสมบูรณ์
ครอบคลุม: A-Level 17.1 (การรับรองดิจิทัล), 6.2 (ความสมบูรณ์).
Common mistakes
- A hash is one-way — you cannot get the original back from it.
- A digital signature proves who sent a message and that it was not changed.
ข้อผิดพลาดที่พบบ่อย
- การแฮชเป็นทางเดียว — ไม่สามารถดึงข้อมูลต้นฉบับกลับมาได้จากมัน
- ลายเซ็นดิจิทัลยืนยันว่าใครส่งข้อความและว่าไม่มีการเปลี่ยนแปลง
Hashing & signatures · การแฮช & การลายเซ็น
A hash is one-way and avalanches — perfect for fingerprints. · แฮชมีลักษณะ ทางเดียว และเกิด avalanche — เหมาะสำหรับการสร้างลายนิ้วมือ
Check whether a received message is unchanged. Hash both original and received with SHA-256 and print whether the two digests are equal (True or False). · ตรวจสอบว่าข้อความที่ได้รับไม่มีการเปลี่ยนแปลง Hash ทั้ง original และ received ด้วย SHA-256 และ print ว่าไดเจสต์ทั้งสองเท่ากันหรือไม่ (True หรือ False)
Click Run to see the output here. · คลิก Run เพื่อดูผลลัพธ์ที่นี่
This time an attacker edited the message in transit. Hash both versions and print TAMPERED if the digests differ, else OK — one changed character is enough to catch. · ครั้งนี้ผู้โจมตีแก้ไขข้อความระหว่างส่ง แฮชทั้งสองเวอร์ชันและพิมพ์ TAMPERED หากนิรภัยต่างกัน, ถ้าไม่ก็พิมพ์ OK — การเปลี่ยนแปลงเพียงหนึ่งตัวอักษรก็足以ตรวจจับได้แล้ว
Click Run to see the output here. · คลิก Run เพื่อดูผลลัพธ์ที่นี่