数字签名 Alice Bob sign verify SA =SA(M') PA =2 accept M (M',σ) M' communication channel Figure 31.6 Digital signatures in a public-key system.Alice signs the message M'by appending her digital signature o=SA(M)to it.She transmits the message/signature pair (M,o)to Bob, who verifies it by checking the equation M'=PA().If the equation holds,he accepts (M',o)as a message that Alice has signed.数字签名