DSA · Digital Signature Algorithm

A signature is just a number — one only your key could produce.

The Digital Signature Algorithm turns a document into a pair of integers that nobody can forge and nobody can quietly alter. This is what happens in the second after you click Sign, why one reused random number can undo all of it, and which algorithm actually signs your contracts today.

FIPS 186NIST standard since 1994
(r, s)The entire signature
2048-bitMinimum in practice
What it proves

Three things a scanned signature can never give you.

An image of a name proves nothing about who put it there or whether the page changed afterwards. A digital signature is a mathematical claim, and it either checks out or it doesn't.

01

Authenticity

Only the holder of one specific private key could have produced this pair of numbers. Verification uses the matching public key, which proves the link without ever revealing the private one.

Why it matters: identity rests on possession of a key, not on a picture of a name.
02

Integrity

The signature is computed over a hash of the document, not the document itself. Change a comma, change a date, change one invisible character — the hash changes completely and verification fails.

Why it matters: tampering is detected, not merely discouraged.
03

Non-repudiation

Because only one key could have produced the signature, it is hard for the signer to credibly deny it — provided the key was genuinely under their control. That last condition is where real disputes are usually fought.

Worth knowing: the maths supports the argument; how much legal weight it carries still depends on the jurisdiction.
The mechanism

Three phases, and only one of them is secret

DSA rests on the discrete logarithm problem: it is cheap to compute gx mod p, and currently infeasible to work backwards from the result to x. Everything below follows from that asymmetry.

Phase 01 Once, per signer

Key generation

Agree the public domain parameters, then draw a private key at random and derive the public one from it.

x ← random, 0 < x < q y = gx mod p

x never leaves the signer. y is published in the certificate.

Phase 02 Every signature

Signing

Hash the message, draw a fresh secret k for this signature alone, and produce two integers.

r = (gk mod p) mod q s = k−1 (H(m) + x·r) mod q

The signature is the pair (r, s). Nothing else is sent.

Phase 03 Anyone, any time

Verification

Recompute a value from the public key and the document’s hash. If it lands on r, the signature holds.

w = s−1 mod q u1 = H(m)·w,   u2 = r·w v = (gu1 yu2 mod p) mod q v = r  →  valid

No secret is needed to verify. That is the entire point.

The six numbers

Four you can publish. Two you never can.

Every letter in those equations has a job. Only two of them are secret, and the second one is secret for a single signature and then thrown away.

Published · 4

Carried inside the certificate. Anyone verifying a signature already holds every one of these, and knowing them gets you no closer to signing.

  • Prime modulus

    The large prime everything is computed modulo. Its size sets the difficulty of the underlying discrete logarithm problem.

    2048–3072 bits
  • Prime divisor

    A prime that divides p − 1. It fixes the size of the signature, which is why a DSA signature stays small while p grows.

    224–256 bits
  • Generator

    A number whose powers cycle through a subgroup of order q. Shared openly, often across a whole organisation.

    derived from p, q
  • Public key

    The only published value derived from the private key — and the one every verifier needs. Anyone can check with it; nobody can sign with it.

    y = gx mod p
Next to its neighbours

Four signature algorithms, one job

People say “DSA” loosely, and usually mean one of these four. They solve the same problem from different hard maths, and only three are still approved for new signatures.

Comparison of RSA, DSA, ECDSA and EdDSA signature algorithms
Algorithm Hard problem Typical key Where you meet it FIPS 186-5 status
RSAPKCS#1 Integer factorisation 3072-bit PDF signatures, TLS certificates, most Class 3 signing certificates Approved
DSAFIPS 186-4 Discrete log, finite field 3072-bit Legacy PGP keys, older SSH hosts, historical government systems Verify only
ECDSAP-256 and friends Discrete log, elliptic curve 256-bit TLS, e-passports, most modern certificate chains Approved
EdDSAEd25519, Ed448 Twisted Edwards curve 256-bit SSH keys, code signing, newer protocol work Approved

Key sizes are not comparable across rows: a 256-bit elliptic-curve key is roughly the strength of a 3072-bit finite-field key. Smaller is not weaker here — it is different maths.

The part most explainers skip

The algorithm this page is named after is no longer approved for new signatures.

NIST published FIPS 186-5 in February 2023. It keeps DSA for verifying signatures that already exist, and removes it for generating new ones, citing security analysis of real implementations and the industry’s move to elliptic curves. FIPS 186-4 was withdrawn a year later, in February 2024.

So when a vendor says their product “uses DSA”, it is worth asking which one they mean. In practice, the signature on a contract today is produced by RSA or ECDSA — and which one is decided by the certificate and the authority that issued it, not by the platform sending the document.

Feb 2023FIPS 186-5 published
Feb 2024FIPS 186-4 withdrawn
Verify onlyWhat DSA is still for
FIPS 204

ML-DSA

Module-Lattice Digital Signature Algorithm, standardised in August 2024 from CRYSTALS-Dilithium. The name is a coincidence worth noticing: the successor to DSA is also called DSA, and shares none of its maths.

Designed to survive a quantum computer running Shor’s algorithm, which would break RSA, DSA and ECDSA alike.
FIPS 205

SLH-DSA

Stateless Hash-Based Digital Signature Algorithm, from SPHINCS+. Slower and much larger, but its security rests only on the hash function — a deliberately conservative fallback if lattice assumptions ever weaken.

Nothing here is urgent for a contract signed and disputed within a decade. It matters for documents meant to hold for thirty years.
One mistake, total failure

Reuse k twice and you have given away your private key.

Every signature needs a fresh, unpredictable k. Sign two different messages with the same key and the same k, and the two equations can be solved for x with ordinary algebra — no brute force, no supercomputer, no waiting.

This is not theoretical. Sony’s PlayStation 3 code-signing key was recovered in 2010 because the implementation used a constant instead of a random value. The key was extracted, and anything could then be signed as Sony.

The fix is standardised: RFC 6979 derives k deterministically from the private key and the message hash, so it is unpredictable to everyone else and never repeats for different messages. FIPS 186-5 specifies deterministic ECDSA for the same reason.

Which is why “we implemented the cryptography ourselves” is rarely the reassurance it is meant to be.
Questions

The ones people actually ask

Short answers on what DSA actually is, where it still applies, and what replaced it.

No. A digital signature is the general idea — proving a document came from a particular key and hasn’t changed since. DSA is one specific algorithm for producing one, published by NIST in 1994. RSA, ECDSA and EdDSA are others. People often use “DSA” as shorthand for the whole category, which is where most of the confusion starts.
The mathematics has not been broken. But FIPS 186-5 removed DSA from approved signature generation in February 2023, keeping it only for verifying older signatures, and FIPS 186-4 was withdrawn in February 2024. For anything new, ECDSA, EdDSA or RSA are the current choices. Existing DSA signatures remain verifiable.
FIPS 186-4 defines pairs for the modulus p and the divisor q: 2048/224, 2048/256 and 3072/256. The original 1024/160 pairing is long obsolete. Treat 2048 bits as the floor for anything that still matters, and 3072 where the document has a long life ahead of it.
Because k appears in the signing equation alongside the private key. Two signatures made with the same k give an attacker two equations in two unknowns, which solves directly for the private key. Weak randomness has cost real organisations their signing keys. RFC 6979 removes the risk by deriving k deterministically from the key and the message.
Not on its own. Cryptography establishes that a document is unchanged and came from a particular key. Whether that counts as a valid signature is a question of law, and the answer differs by country and by document type — some instruments require a qualified certificate, some require registration or stamp duty, and some cannot be signed electronically at all. The legality guide sets out what applies where.
A sufficiently large quantum computer running Shor’s algorithm would break DSA, ECDSA and RSA together, since all three rest on problems it solves efficiently. No such machine exists today. NIST standardised replacements in August 2024 — ML-DSA (FIPS 204) and SLH-DSA (FIPS 205) — and the migration matters most for documents expected to hold their weight for decades.

You shouldn’t have to pick an algorithm

Docsliy applies the signature tier the jurisdiction requires, through a certificate authority licensed to issue it, and keeps the evidence that goes with it. You send the contract.