Hashing and digital signatures · 哈希与数字签名
Hashing protects integrity
- We hashed passwords for secrecy. Hashing also protects integrity — proving data was not changed.
- Change even one character of the input, and the hash changes completely.
哈希保护完整性
- 我们用哈希来保护密码的保密性。哈希也能保护完整性 —— 证明数据未被改动。
- 哪怕只改输入中的一个字符,哈希也会完全不同。
import hashlib
print(hashlib.sha256(b"hello").hexdigest()[:16])
print(hashlib.sha256(b"hellp").hexdigest()[:16]) # totally different
Checking a download
- Websites publish the hash of a file. After downloading, you hash your copy and compare.
- If the two hashes match, the file arrived intact. If not, it was corrupted or tampered with.
校验下载
- 网站会公布文件的哈希值。下载之后,你对自己的副本做哈希再比对。
- 如果两个哈希相同,文件就是完好送达的。如果不同,它要么损坏了,要么被篡改了。
Digital signatures
- A digital signature proves who sent something and that it was not changed.
- The sender hashes the message and encrypts that hash with their private key.
- Anyone can check it with the sender's public key — only the real sender could have made it.
数字签名
- 数字签名既能证明是谁发送了某物,也能证明它没有被改动。
- 发送方对消息做哈希,再用自己的私钥加密这个哈希。
- 任何人都能用发送方的公钥来验证它 —— 只有真正的发送方才可能做出它。
Your turn
- Compare the hashes of an original and a received message.
Truemeans the message is intact.
Covers: A-Level 17.1 (digital certification), 6.2 (integrity).
轮到你了
- 比较原始消息和收到消息的哈希。
True表示消息是完好的。
涵盖:A-Level 17.1(数字认证)、6.2(完整性)。
Common mistakes
- A hash is one-way — you cannot get the original back from it.
- A digital signature proves who sent a message and that it was not changed.
常见错误
- 哈希是单向的——无法从中还原原文。
- 数字签名证明谁发送了消息,以及消息未被篡改。
Hashing & signatures · 哈希与签名
A hash is one-way and avalanches — perfect for fingerprints. · 哈希是单向的、会雪崩——非常适合做指纹。
Check whether a received message is unchanged. Hash both original and received with SHA-256 and print whether the two digests are equal (True or · 或 False). · 检查收到的消息是否未被改动。用 SHA-256 对 original 和 received 都做哈希,并 print 出两个摘要是否相等(True 或 False)。
Click Run to see the output here. · 点击“运行”查看此处输出。
This time an attacker edited the message in transit. Hash both versions and print TAMPERED if the digests differ, else OK — one changed character is enough to catch. · 这次攻击者在传输途中改动了消息。对两个版本都做哈希:摘要不同就打印 TAMPERED,否则打印 OK —— 哪怕只改了一个字符也逃不掉。
Click Run to see the output here. · 点击“运行”查看此处输出。