SSCP Systems Security Certified PractitionerCryptographyMedium

A developer is designing a system that requires users to digitally sign documents to ensure non-repudiation. The system must also guarantee the integrity of the document and authenticate the signer. Which component of a digital signature provides the integrity guarantee?

  1. AThe hash of the document
  2. BThe signer's private key
  3. CThe encryption algorithm used
  4. DThe signer's public key
Show answer & explanation

Correct answer: A. The hash of the document

A digital signature is created by hashing the document and then encrypting that hash with the signer's private key. If any part of the document is altered, its hash will change, causing the verification process (comparing the re-hashed document with the decrypted hash) to fail, thus guaranteeing integrity.

Why the other options are wrong

  • B. The private key is used to encrypt the hash, providing authenticity and non-repudiation, but the hash itself provides integrity.
  • C. The encryption algorithm is used to secure the hash, but the hash function itself provides the integrity property.
  • D. The public key is used to decrypt the hash during verification, confirming the signer's identity and that the private key was used.

Digital Signature Integrity

The property of a digital signature that ensures the signed data has not been altered since it was signed. This is achieved by including a cryptographic hash of the data within the signature.

  • Relies on cryptographic hashing.
  • Any change to the data invalidates the hash.
  • Verifies that the original content remains intact.

Memory trick: Hash Ensures Integrity, Keys Confirm Identity.

More Cryptography questions