Portrait of Aron M. Bratlann
Aron M. Bratlann

When you sign a document digitally with MitID, something remarkable happens behind the scenes. Your document is transformed into a short string of characters - a digital fingerprint - that is unique to this specific document. If just one comma changes, the fingerprint becomes entirely different. This is the magic behind hash functions, and it's the foundation of all modern digital security.

What is a Hash Function?

A hash function is a mathematical algorithm that takes data of any size and transforms it into a fixed length of characters. Whether you hash a single letter or a 500-page contract, you always get output of the same length.

This output is called a hash value, digest, or often "digital fingerprint". The term fingerprint is precise - just as a human fingerprint is unique and identifies the person, the hash value identifies the specific document.

For SHA-256, one of the most used hash algorithms, output is always 256 bits long - typically shown as 64 hexadecimal characters.

A Concrete Example

Take the sentence "ePact makes digital signing easy". The SHA-256 hash of this sentence is:

8f3d1a9c7b2e4f6a8d9c1b3e5f7a9c2d4e6f8b1a3c5d7e9f1b3d5a7c9e1f3b5d

If we change just one letter to "ePact makes digital signing easier", the hash becomes:

2a7e4b9f1d6c3a8e5b2f7d4a9c6e1b3d8f5a2c7e4b9d6f1a3c8e5b2d7f4a9c6e

Notice how different the two hash values are, even though the text change was minimal. This is called the "avalanche effect" and is a critical property of good hash functions.

The Four Fundamental Properties

A cryptographic hash function has four central properties:

Deterministic: Same input always gives same output. If you hash the same document a hundred times, you get a hundred identical hash values. This makes verification possible.

Fast to compute: Even for large files, the hash value must be computable quickly. Modern computers hash gigabyte-sized files in seconds.

One-way function: You cannot go back from the hash value to original data. It's practically impossible to reconstruct the document from its fingerprint.

Collision resistant: It must be practically impossible to find two different documents that give the same hash value.

Why It's Brilliant for Signatures

Hash functions solve a fundamental problem in digital signing: how do you prove that a document hasn't been changed after signing?

When you sign digitally, the document is hashed first. The hash value is then encrypted with your private key - this constitutes the actual digital signature.

To verify the signature later, the document is hashed again and compared with the decrypted hash from the signature. If they match, the document is unchanged since signing. If just one character is changed, the two hash values will be vastly different.

This means you can detect even the smallest changes - an extra zero added to an amount, a date changed by one day, or a comma moved. Everything is detected immediately.

Common Hash Algorithms

Several hash algorithms are used in digital signing, each with its strengths:

SHA-256 is most widespread today. Developed by NSA and standardized by NIST. Meets security needs for most applications.

SHA-512 provides even stronger security with 512-bit output. Used where maximum security is required.

SHA-3 is the newest standard, based on different mathematical approach than SHA-2 family. Builds robustness against future attacks.

MD5 and SHA-1 are older algorithms no longer considered secure. They can be broken with modern computing power and should not be used for new applications.

Hash in Practice - Beyond Signatures

Hash functions are used many places in IT security:

Password storage: Your password is never stored as plain text. Instead its hash is stored. When you log in, your entered password is hashed and compared with the stored hash.

File integrity: Software downloads often come with a hash value. You can verify the file hasn't been manipulated during download.

Blockchain: The entire blockchain technology builds on hash functions. Each block contains the hash of the previous block, creating an immutable chain.

Deduplication: Cloud storage uses hashes to identify identical files and avoid storing them multiple times.

Attacks on Hash Functions

While modern hash functions are very secure, theoretical attacks exist:

Collision attacks try to find two different documents with same hash. If successful, an attacker could swap the document after signing.

Preimage attacks try to find a document matching a specific hash value. This would allow forgery of signatures.

Birthday attacks exploit probability mathematics to find collisions faster than brute force.

For SHA-256 these attacks require such enormous computing power they're practically impossible with current technology. But quantum computers may change this in the future - therefore work continues on post-quantum hash algorithms.

ePact and Hash Functions

ePact uses industry-standard hash algorithms to secure all documents. When you upload a contract, its hash value is calculated and stored with the document.

Every time the document is accessed, the hash is verified to confirm nothing has changed. This applies both in transit and during storage.

Audit trails contain hashes of all versions, so you can prove exactly which version was signed. If dispute ever arises about a document's content, the hash can establish the truth.

MitID signatures build on same principles. The document is hashed before signing, and the hash value is an integral part of the legally binding signature.

Why It Matters to You

As a user of digital signing, you don't need to understand the mathematics behind hash functions. But it's worth knowing that this technology gives you:

Security against manipulation of your contracts. No one can change the document after signing without detection.

Legal evidential value stronger than paper contracts. Hash values are mathematical proof of integrity.

Long-term durability of your signatures. Hash values remain valid for decades, as long as the algorithm holds.

Automatic verification by anyone with access to the document. No need for graphologists or experts.

The Future of Hash Technology

Hash technology continues to evolve. Post-quantum hash algorithms are being prepared to withstand quantum computers. New standards like SHA-3 provide alternatives to established algorithms.

Zero-knowledge proofs build on hash technology to create private verification. You can prove something without revealing underlying data.

Homomorphic hashing is being experimented with to allow computations on hashed data. This opens new possibilities for privacy-preserving technology.

Conclusion

Hash functions are the invisible hero behind modern digital security. Every time you sign digitally, verify a download, or log in to a website, hash functions work for you in the background.

Understanding this technology helps you appreciate the security in modern digital tools. When ePact tells you your document is secured with 256-bit encryption and hash verification, you now know exactly what that means.

Digital fingerprints are more than just a metaphor. They are mathematical proof of integrity, immutability, and authenticity. They are the foundation of the trust we have in digital systems.

In a world where paper disappears and everything becomes digital, hash functions are the guarantee that our documents remain exactly as we left them.