SSCP Systems Security Certified PractitionerCryptographyHard

A financial institution is implementing a system for secure online transactions. They require a cryptographic solution that ensures the integrity of the transaction data, confirms the sender's identity, and prevents the sender from later denying they sent the transaction. Which of the following cryptographic techniques BEST fulfills all three of these requirements?

  1. AHashing with a Message Authentication Code (MAC)
  2. BTransport Layer Security (TLS) with mutual authentication
  3. CDigital signatures using asymmetric cryptography
  4. DSymmetric encryption with a shared secret key
Show answer & explanation

Correct answer: C. Digital signatures using asymmetric cryptography

Digital signatures, generated using the sender's private key and verified with their public key, provide integrity (data hasn't changed), authentication (sender's identity), and non-repudiation (sender cannot deny the signature).

Why the other options are wrong

  • A. Hashing with a MAC provides integrity and authenticity (if the key is shared secretly), but not non-repudiation, as both sender and receiver know the key.
  • B. TLS with mutual authentication provides confidentiality, integrity, and mutual authentication for the communication channel, but the individual transaction data itself might still require a separate mechanism for non-repudiation.
  • D. Symmetric encryption provides confidentiality but not integrity, authentication, or non-repudiation on its own.

Digital Signature

A cryptographic mechanism that uses asymmetric cryptography to bind an identity to a piece of information, ensuring authenticity, integrity, and non-repudiation.

  • Created by hashing data and encrypting the hash with the sender's private key.
  • Verified by decrypting the hash with the sender's public key and comparing it to a newly computed hash of the data.
  • Crucial for legal and financial transactions.

Memory trick: CIA+NN: Confidentiality, Integrity, Availability, Non-repudiation, Authentication!

More Cryptography questions