0 / 4
Dual Signature
The customer sends the order information to the shop and the payment information to the bank. The shop must not see the card number, and the bank has no need to see what was bought. Yet both must be able to confirm that this payment and this order are a pair. A dual signature binds the hashes of the two into one and signs only once, meeting all of these needs at once.
Example: a customer buys a $1,500 laptop at an online shop and pays by card.
1 / 4
Customer: hash each original
The customer puts the payment information and the order information into the hash function separately. Out come the payment hash 7d2e and the order hash a41c.
2 / 4
Customer: join the two hashes
The customer places the order hash a41c after the payment hash 7d2e. The two values are not added; they are joined in order. The verifier must join them in the same order to get the same value.
3 / 4
Customer: hash the joined value again
The joined value goes into the hash function again, giving the combined hash c93f. If even one character of the order or payment information changes, this value changes completely.
4 / 4
Customer: sign once with the private key
The customer signs the combined hash c93f with their private key, producing the dual signature 5f1b80. This is the only signature. Only the customer has the private key, so no one else can make the same signature.
1 / 5
Shop: what it received
From the customer, the shop receives the order information, the payment hash 7d2e and the dual signature 5f1b80. The payment information comes along sealed in an envelope only the bank can open. The shop cannot open it and passes it on to the bank as it is.
2 / 5
Shop: hash the order
The shop puts the order information it received into the hash function and makes the order hash a41c itself.
3 / 5
Shop: join and hash again
The shop places its own a41c after the received payment hash 7d2e. Hashing the joined value again gives c93f. Without knowing the card number, it gets the same value as the customer.
4 / 5
Shop: decrypt the dual signature
Decrypting the received dual signature with the customer's public key gives c93f, the combined hash the customer signed.
5 / 5
Shop: compare the two values
The c93f it computed and the c93f from the signature are the same. This confirms three things. The customer really signed. The order was not changed. This order is paired with the payment whose hash is 7d2e.
1 / 5
Bank: what it received
The bank opens the envelope the shop passed on and takes out the payment information, the order hash a41c and the dual signature 5f1b80. It never receives the order information, so it does not know what the customer bought.
2 / 5
Bank: hash the payment
The bank puts the payment information into the hash function and makes the payment hash 7d2e itself.
3 / 5
Bank: join and hash again
The bank places the received order hash a41c after its own 7d2e. Hashing the joined value again gives c93f. Without knowing the order, it gets the same value as the customer.
4 / 5
Bank: decrypt the dual signature
Decrypting the received dual signature with the customer's public key gives c93f, the combined hash the customer signed.
5 / 5
Bank: compare the two values
The c93f it computed and the c93f from the signature are the same. This confirms three things. The customer really signed. The payment was not changed. This payment is paired with the order whose hash is a41c. So the bank approves the payment.
1 / 5
Bank: what it has to check
The bank holds the payment information and the customer's dual signature 5f1b80. On top of that, the shop has shown a tablet order form. The two orders cost the same, so the amount alone cannot tell them apart.
2 / 5
Bank: hash each original
The payment information gives 7d2e. The order form the shop showed gives e508, which differs from the real order (a41c).
3 / 5
Bank: join and hash again
Joining e508 after 7d2e and hashing again gives 1f6d.
4 / 5
Bank: decrypt the dual signature
Decrypting the dual signature with the customer's public key gives c93f. That is the combined hash the customer used when signing.
5 / 5
Bank: compare the two values
The recomputed 1f6d and the c93f from the signature are different. This means the customer did not sign this order form. The shop does not have the customer's private key, so it cannot make a new signature that fits this order form either.