Here is an explanation of the process under 'The current scheme for package signature checks' at the following url
https://www.debian.org/doc/manuals/securing-debian-manual/de....