SSCP Systems Security Certified PractitionerSystems and Application SecurityMedium

A financial institution is implementing a new online banking platform. To ensure the integrity and authenticity of user transactions, they need a mechanism to verify that a transaction message has not been altered in transit and that it originated from a legitimate sender. Which cryptographic technique is best suited for this requirement?

  1. ASymmetric-key encryption
  2. BDigital signature
  3. CAsymmetric-key encryption
  4. DHashing
Show answer & explanation

Correct answer: B. Digital signature

A digital signature provides both integrity and non-repudiation by using a sender's private key to sign a hash of the message. This allows recipients to verify the sender's identity and confirm that the message has not been tampered with.

Why the other options are wrong

  • A. Symmetric-key encryption provides confidentiality but not integrity or authenticity in this context.
  • C. Asymmetric-key encryption provides confidentiality and key exchange but does not inherently provide message integrity or sender authentication without digital signatures.
  • D. Hashing provides integrity but does not prove the sender's identity or prevent repudiation.

Digital Signature

A mathematical scheme for demonstrating the authenticity of digital messages or documents. A valid digital signature gives a recipient reason to believe that the message was created by a known sender (authenticity), and that it was not altered in transit (integrity).

  • Provides authenticity, integrity, and non-repudiation.
  • Uses asymmetric cryptography (sender's private key for signing, sender's public key for verification).
  • Often involves hashing the message first, then encrypting the hash.

Memory trick: Sign your digital words to prove they're yours and untouched.

More Systems and Application Security questions