CompTIA SecurityX (CAS-005)Security EngineeringMedium
A security architect is designing a new payment gateway system that requires extremely high assurance for transaction integrity and non-repudiation. Each transaction must be cryptographically proven to have originated from a specific participant and not been altered in transit. The solution must also scale to millions of transactions per day. Which cryptographic primitive is BEST suited to achieve both integrity and non-repudiation in this high-volume context?
- ADigital Signature
- BHashing
- CMessage Authentication Code (MAC)
- DSymmetric Encryption
Show answer & explanationAnswer & explanation
Correct answer: A. Digital Signature
A digital signature, using asymmetric cryptography, provides both integrity (by detecting alteration) and non-repudiation (by proving the sender's identity). This is crucial for high-assurance transactions where the sender cannot later deny having sent the message.
Why the other options are wrong
- B. Hashing provides integrity (detects alteration) but does not provide non-repudiation as anyone can compute the hash.
- C. A MAC provides integrity and authenticity (shared secret proof of origin) but does not provide non-repudiation because the shared secret means any party with the key could have generated it.
- D. Symmetric encryption provides confidentiality but does not inherently offer integrity or non-repudiation.
Digital Signature
A mathematical scheme for verifying the authenticity of digital messages or documents, providing both data integrity and non-repudiation, using asymmetric cryptography.
- Uses asymmetric (public-key) cryptography
- Provides data integrity (detects tampering)
- Ensures non-repudiation (proves sender's origin)
Memory trick: Digital Signatures Prove Origin and Integrity.