CompTIA SecurityX (CAS-005)Security EngineeringMedium

A security architect is designing a new payment gateway system that requires extremely high assurance of transaction integrity and non-repudiation. Each transaction must be cryptographically bound to the sender in a way that is verifiable by any third party and cannot be later denied by the sender. Which cryptographic primitive is BEST suited to meet these specific requirements?

  1. AHashing (SHA-256)
  2. BDigital Signature
  3. CMessage Authentication Code (MAC)
  4. DSymmetric Encryption (AES)
Show answer & explanation

Correct answer: B. Digital Signature

A digital signature provides both integrity and non-repudiation. It uses the sender's private key to sign a hash of the transaction, and any third party can verify it using the sender's public key. This cryptographic binding ensures the sender cannot deny having sent the transaction, meeting the 'non-repudiation' and 'verifiable by any third party' requirements.

Why the other options are wrong

  • A. Hashing provides integrity but does not prove the sender's identity or prevent repudiation.
  • C. A Message Authentication Code (MAC) provides integrity and authenticity, but it requires a shared secret key, so it cannot provide non-repudiation to a third party.
  • D. Symmetric encryption provides confidentiality but not integrity or non-repudiation in a verifiable way by a third party.

Digital Signature

A mathematical scheme for demonstrating the authenticity of digital messages or documents. It provides integrity, authenticity, and non-repudiation by using asymmetric cryptography.

  • Uses sender's private key for signing.
  • Verifiable with sender's public key.
  • Provides integrity, authenticity, and non-repudiation.

Memory trick: A DIGITAL SIGNATURE is like a personal, undeniable stamp.

More Security Engineering questions