CompTIA SecurityX (CAS-005)Security ArchitectureMedium
A financial institution is designing a new payment processing system that must comply with strict regulatory requirements for data confidentiality and non-repudiation. The system needs to ensure that all financial transactions are provably authentic and that the sender cannot later deny having sent a specific transaction. Which cryptographic primitive is essential for achieving non-repudiation in this context?
- ASymmetric Encryption.
- BDigital Signatures.
- CHashing.
- DAsymmetric Encryption.
Show answer & explanationAnswer & explanation
Correct answer: B. Digital Signatures.
Digital signatures use the sender's private key to sign a transaction, providing strong evidence of authenticity and integrity. Because only the sender possesses their private key, they cannot credibly deny having originated the signed transaction, thus achieving non-repudiation.
Why the other options are wrong
- A. Symmetric encryption provides confidentiality but not non-repudiation, as both sender and receiver share the same key.
- C. Hashing provides integrity (detects tampering) but does not prove the sender's identity or prevent repudiation.
- D. Asymmetric encryption provides confidentiality (using the recipient's public key) but does not inherently provide non-repudiation for the sender without the use of their private key for signing.
Digital Signatures
A digital signature is a cryptographic mechanism used to verify the authenticity, integrity, and non-repudiation of a digital message or document.
- Uses asymmetric cryptography (sender's private key for signing, public key for verification).
- Provides authenticity (sender identity).
- Provides integrity (detects tampering).
- Provides non-repudiation (sender cannot deny).
- Often based on hashing the message first, then encrypting the hash.
Memory trick: A digital signature is like your unique, undeniable fingerprint on a document.