SSCP Systems Security Certified PractitionerCryptographyMedium
A financial institution is implementing a system for secure online transactions. They require a mechanism to ensure that a customer cannot later deny having initiated a specific transaction, even if their private key is compromised after the transaction. Which cryptographic property, when properly implemented, primarily addresses this 'non-denial' aspect?
- AIntegrity
- BConfidentiality
- CNon-repudiation
- DAvailability
Show answer & explanationAnswer & explanation
Correct answer: C. Non-repudiation
Non-repudiation is the cryptographic property that provides irrefutable proof of an action, such that the originator cannot later deny having performed it. Digital signatures, applied correctly, are the primary mechanism to achieve non-repudiation for transactions.
Why the other options are wrong
- A. Integrity ensures data hasn't been altered but doesn't prevent denial of origin.
- B. Confidentiality ensures privacy but doesn't prevent denial of an action.
- D. Availability ensures systems are accessible but is unrelated to proving transaction origin.
Non-repudiation
A cryptographic service that provides undeniable proof of the origin or integrity of data, or the identity of the sender, preventing the sender from falsely denying having sent a message or initiated a transaction.
- Prevents denial of origin or action.
- Typically achieved using digital signatures.
- Crucial for legal and financial transactions.
Memory trick: Non-repudiation is like a digital receipt you can't throw away.