This article was accepted into the corpus but its outbound wikilinks were never NER-processed — typical at the deepest BFS hop or when the run's entity cap was reached. No expansion funnel to show.
| DSA (Digital Signature Algorithm) | |
|---|---|
| Name | DSA (Digital Signature Algorithm) |
| Type | Asymmetric key algorithm |
| Designers | National Institute of Standards and Technology, David A. McGrew, Phil Zimmermann |
| Published | 1991 |
| Derived from | ElGamal encryption |
| Key size | 1024–3072 bits |
| Signature size | variable |
| Status | Published standard |
DSA (Digital Signature Algorithm) DSA (Digital Signature Algorithm) is a Federal Information Processing Standard for digital signatures originally specified by the National Institute of Standards and Technology and adopted as a part of FIPS publications, designed to provide authentication and integrity for messages in contexts like Secure Sockets Layer, Transport Layer Security, Pretty Good Privacy, and IPsec. The algorithm derives its mathematical basis from discrete logarithm problems studied in the context of ElGamal encryption, Diffie–Hellman key exchange, and advances by researchers associated with institutions such as MIT, Bell Labs, and IBM. DSA has been incorporated into standards promulgated by organizations like the Internet Engineering Task Force and used in products from vendors such as Microsoft, Apple Inc., Red Hat, and Oracle Corporation.
DSA was proposed by the National Institute of Standards and Technology in 1991 during deliberations that involved contributors from United States Department of Defense, researchers from Stanford University, University of California, Berkeley, and cryptographers influenced by work at MIT and Bell Labs. The standardization occurred amid debates including participants from RSA Security, CipherTrust, and advocates like Phil Zimmermann who referenced earlier signature methods including RSA (cryptosystem), ElGamal encryption, and signatures from Lamport signatures. Political and technical discussions intersected with events involving the Cryptography Research and Evaluation Committees and policy debates in the era of the Clipper chip and the Electronic Frontier Foundation.
The algorithm specifies modular arithmetic operations on prime fields and relies on parameters including a large prime p, a prime q dividing p−1, and a generator g of a subgroup of order q, linking to mathematical research from Évariste Galois-inspired group theory developed at École Normale Supérieure and modern computational number theory labs at CWI and INRIA. Specification text in the standard describes hashing with functions like Secure Hash Algorithm 1 and successors, and modular exponentiation informed by algorithms from researchers at Princeton University and ETH Zurich. The structure mirrors proofs and reductions used by theoreticians at UC Berkeley and University of Cambridge to relate security to the hardness of the discrete logarithm problem studied at Université Paris-Sud.
Key generation requires choosing parameters p, q, and g; p is a prime of specified length, q is a prime divisor, and g is computed to generate a subgroup of order q, reflecting number-theoretic practices seen in work at Los Alamos National Laboratory and National Security Agency-adjacent research groups. Private keys are random integers in [1, q−1], a method influenced by standards committees including ANSI, ISO/IEC, and contributors from NIST panels. Parameter selection and domain parameter generation reference entropy sources and random oracles discussed at University of Waterloo and Rutherford Appleton Laboratory workshops, and use randomness practices recommended by IETF and IEEE.
Signature generation computes values using ephemeral per-message secrets (k) and modular inverses modulo q, techniques whose correctness proofs echo algebraic number theory results from researchers at Harvard University and Columbia University. Verification uses public keys to confirm congruences mod p and q, paralleling verification algebra in Cambridge University Press-documented texts and algorithmic implementations by teams at Google and Mozilla Corporation. Implementations must ensure unique k per message as highlighted by incidents involving recovery attacks analyzed at Technische Universität Berlin and University College London.
Security is based on the difficulty of the discrete logarithm problem in prime fields, a topic investigated by mathematicians at Max Planck Society and applied cryptographers at INRIA; advances in index calculus algorithms from groups at École Normale Supérieure and University of Bonn affect parameter recommendations. Cryptanalysis includes side-channel attacks reported by teams at Cambridge University and KU Leuven, fault-injection studies performed at University of Birmingham, and state-level considerations discussed in forums tied to European Union Agency for Cybersecurity and US Department of Homeland Security. Quantum computing research from IBM Quantum, Google Quantum AI, and D-Wave Systems raises implications via algorithms like Shor's algorithm studied at University of Bristol.
DSA appears in standards including FIPS 186, X.509, and IETF RFCs implemented by software projects such as OpenSSL, GnuTLS, Bouncy Castle, and libraries in OpenJDK and LibreSSL. Hardware and firmware implementations exist from vendors like Intel Corporation, ARM Holdings, and Broadcom, often audited by firms like KPMG and Ernst & Young. Compliance testing and certification programs involve agencies like Underwriters Laboratories and evaluation schemes under Common Criteria at testing centers such as NIAP.
DSA is used in protocols and products including SSH, S/MIME, PGP, TLS 1.2, and legacy systems interoperating with Kerberos and LDAP directories maintained by organizations like The Apache Software Foundation and Mozilla Foundation. Interoperability work between implementations is coordinated in standards meetings at IETF and industry consortia including OWASP and CISPE, while migration planning references guidance from NIST and regional bodies like ENISA.
Category:Cryptographic algorithms