CompTIA SecurityX (CAS-005)Security EngineeringMedium
A financial institution is migrating its legacy mainframe applications to a modern cloud-native architecture. The security team needs to ensure that the new applications comply with stringent regulatory requirements for data integrity and non-repudiation. Which cryptographic primitive, when used for transaction signing, MOST effectively addresses these requirements?
- ADigital signatures (e.g., RSA or ECDSA)
- BKey derivation functions (e.g., PBKDF2)
- CHashing (e.g., SHA-256)
- DSymmetric encryption (e.g., AES)
Show answer & explanationAnswer & explanation
Correct answer: A. Digital signatures (e.g., RSA or ECDSA)
Digital signatures use asymmetric cryptography to provide both data integrity (by detecting any alteration) and non-repudiation (by proving the signer's identity and intent). This directly addresses the requirements for financial transactions.
Why the other options are wrong
- B. Key derivation functions are used to derive cryptographic keys from a master key or password, not for signing data to ensure integrity or non-repudiation.
- C. Hashing provides data integrity (detects changes) but does not provide non-repudiation, as anyone can compute the hash of a message.
- D. Symmetric encryption provides confidentiality but does not inherently provide data integrity or non-repudiation on its own.
Digital Signature
A mathematical scheme for verifying the authenticity and integrity of digital messages or documents, providing non-repudiation.
- Uses asymmetric cryptography (private key to sign, public key to verify).
- Ensures data integrity (detects tampering).
- Provides non-repudiation (proves sender's identity and intent).
Memory trick: Signatures prove who and what, for integrity and non-repudiation.