EC-Council Certified Ethical Hacker (CEH) v12CryptographyMedium

A developer is designing a system for digital currency transactions. They need to ensure that transactions are verifiable as originating from the sender and that the sender cannot later deny having sent the transaction. Which cryptographic primitive is essential for achieving both authenticity and non-repudiation in this context?

  1. ASymmetric encryption
  2. BDigital signatures
  3. CHashing
  4. DKey exchange protocols
Show answer & explanation

Correct answer: B. Digital signatures

Digital signatures provide both authenticity (verifying the sender's identity) and non-repudiation (preventing the sender from denying the transaction). The sender signs the transaction with their private key, and anyone can verify it using the sender's public key, ensuring that only the sender could have created that specific signature.

Why the other options are wrong

  • A. Symmetric encryption provides confidentiality, not authenticity or non-repudiation.
  • C. Hashing provides integrity, but not authenticity of the sender or non-repudiation.
  • D. Key exchange protocols establish shared keys, but do not inherently provide non-repudiation for transactions.

Digital Signatures

A digital signature is a mathematical scheme for demonstrating the authenticity of digital messages or documents. It provides integrity, authenticity, and non-repudiation by using a sender's private key to sign a hash of the data.

  • Uses asymmetric cryptography.
  • Provides authenticity, integrity, non-repudiation.
  • Sender uses private key to sign.
  • Receiver uses sender's public key to verify.

Memory trick: Keys encrypt, hashes check, signatures prove.

More Cryptography questions