#sknebelGoogle has been floating signatures based on HTTPS keys, I think for AMP caches ("if the origin server signs the page, we can show the cached copy exactly as if it came from the server"). And there's the signature stuff often used with ActivityPub, but I think that's tied to JSON-LD