CompTIA SecurityX (CAS-005)Security EngineeringMedium
A security architect is designing a new payment gateway system that requires extremely high assurance of transaction integrity and non-repudiation. Each transaction must be cryptographically proven to have originated from a specific sender and not been altered in transit. Which cryptographic primitive is essential for meeting these requirements?
- AKey Exchange
- BDigital Signature
- CHashing
- DSymmetric Encryption
Show answer & explanationAnswer & explanation
Correct answer: B. Digital Signature
A digital signature provides both integrity (proof that data has not been altered) and non-repudiation (proof of origin). It uses asymmetric cryptography, where the sender signs the transaction with their private key, and anyone can verify it with their public key, fulfilling the requirements for high assurance in payment systems.
Why the other options are wrong
- A. Key exchange protocols are used to establish shared secret keys, not to provide integrity or non-repudiation for data.
- C. Hashing provides integrity (detects alteration) but does not prove the origin (non-repudiation) of the data.
- D. Symmetric encryption provides confidentiality but not integrity or non-repudiation on its own.
Digital Signature
A cryptographic mechanism that uses asymmetric key cryptography to provide data integrity, authentication of the sender, and non-repudiation.
- Uses sender's private key to sign
- Verifiable with sender's public key
- Provides integrity, authentication, and non-repudiation
Memory trick: A Digital Signature proves it's really from 'U' and 'I' (You and I)!