SSCP Systems Security Certified PractitionerSystems and Application SecurityMedium

A software vendor needs to distribute signed software updates to its customers. The customers must be able to verify the authenticity and integrity of the updates before installation. Which cryptographic concept is essential for achieving both authenticity and integrity in this scenario?

  1. AHashing without a key
  2. BSymmetric encryption
  3. CPublic Key Infrastructure (PKI) for confidentiality
  4. DDigital signatures
Show answer & explanation

Correct answer: D. Digital signatures

Digital signatures provide both authenticity (proving the sender's identity) and integrity (ensuring the data has not been tampered with). The vendor signs the update with their private key, and customers verify it with the vendor's public key.

Why the other options are wrong

  • A. Hashing alone provides integrity but not authenticity, as anyone can compute a hash.
  • B. Symmetric encryption provides confidentiality but not authenticity or integrity on its own.
  • C. PKI is used for managing digital certificates and public keys, but its primary function for confidentiality (encryption) doesn't directly address authenticity and integrity of signed updates; digital signatures do.

Digital Signature

A mathematical scheme for demonstrating the authenticity of digital messages or documents. A valid digital signature gives a recipient reason to believe that the message was created by a known sender (authenticity) and that it was not altered in transit (integrity).

  • Uses asymmetric cryptography (private key for signing, public key for verification).
  • Provides authenticity and integrity, but not confidentiality.
  • Often combined with hashing for efficiency.

Memory trick: Crypto primitives are the basic tools to secure digital interactions.

More Systems and Application Security questions