SSCP Systems Security Certified PractitionerSystems and Application SecurityMedium
A financial institution is implementing a new online banking platform. To ensure the integrity and authenticity of user transactions, they need a mechanism to verify that a transaction message has not been altered in transit and that it originated from a legitimate sender. Which cryptographic technique is best suited for this requirement?
- ASymmetric-key encryption
- BDigital signature
- CAsymmetric-key encryption
- DHashing
Show answer & explanationAnswer & explanation
Correct answer: B. Digital signature
A digital signature provides both integrity and non-repudiation by using a sender's private key to sign a hash of the message. This allows recipients to verify the sender's identity and confirm that the message has not been tampered with.
Why the other options are wrong
- A. Symmetric-key encryption provides confidentiality but not integrity or authenticity in this context.
- C. Asymmetric-key encryption provides confidentiality and key exchange but does not inherently provide message integrity or sender authentication without digital signatures.
- D. Hashing provides integrity but does not prove the sender's identity or prevent repudiation.
Digital Signature
A mathematical scheme for demonstrating the authenticity of digital messages or documents. A valid digital signature gives a recipient reason to believe that the message was created by a known sender (authenticity), and that it was not altered in transit (integrity).
- Provides authenticity, integrity, and non-repudiation.
- Uses asymmetric cryptography (sender's private key for signing, sender's public key for verification).
- Often involves hashing the message first, then encrypting the hash.
Memory trick: Sign your digital words to prove they're yours and untouched.