{"id":7793,"date":"2021-10-11T17:23:31","date_gmt":"2021-10-11T15:23:31","guid":{"rendered":"https:\/\/tekmart.co.za\/t-blog\/?p=7793"},"modified":"2021-10-11T17:23:56","modified_gmt":"2021-10-11T15:23:56","slug":"what-is-nonrepudiation-an-expert-explanation-and-its-drawbacks","status":"publish","type":"post","link":"https:\/\/tekmart.co.za\/t-blog\/what-is-nonrepudiation-an-expert-explanation-and-its-drawbacks\/","title":{"rendered":"What is nonrepudiation?-an expert&#8217;s explanation and its drawbacks."},"content":{"rendered":"<span class=\"span-reading-time rt-reading-time\" style=\"display: block;\"><span class=\"rt-label rt-prefix\">Reading Time-approximately:<\/span> <span class=\"rt-time\"> 3<\/span> <span class=\"rt-label rt-postfix\">minutes<\/span><\/span>\n<h2 class=\"wp-block-heading\"><strong>Nonrepudiation ensures that no party can deny that it sent or received a message via\u00a0encryption\u00a0and\/or\u00a0digital signatures\u00a0or approved some information. It also cannot deny the authenticity of its signature on a document.<\/strong><\/h2>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/cdn.ttgtmedia.com\/rms\/onlineimages\/awati_rahul.jpg\" alt=\"Rahul Awati\"\/><\/figure>\n\n\n\n<p>By <a href=\"https:\/\/www.techtarget.com\/contributor\/Rahul-Awati\">Rahul Awati<\/a><\/p>\n\n\n\n<p>Although it originated as a legal concept, nonrepudiation is also widely used in computing,\u00a0information security\u00a0and communications.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>Information assurance and nonrepudiation<\/strong><\/h3>\n\n\n\n<p>Nonrepudiation is one of the five pillars of information assurance (IA), which is the practice of managing information-related risks and protecting information systems, like computers, servers and enterprise networks. The other four pillars are the following:<\/p>\n\n\n\n<ol class=\"wp-block-list\"><li>integrity<\/li><li>availability<\/li><li>authentication<\/li><li>confidentiality<\/li><\/ol>\n\n\n\n<p>Nonrepudiation provides proof of the origin, authenticity and integrity of data. It provides assurance to the sender that its message was delivered, as well as proof of the sender&#8217;s identity to the recipient. This way, neither party can deny that a message was sent, received and processed.<\/p>\n\n\n\n<p>Nonrepudiation is like authentication, particularly with respect to implementation. For instance, a\u00a0public key\u00a0signature can be a nonrepudiation device if only one party can produce signatures.<\/p>\n\n\n\n<p>In general, nonrepudiation combines both authentication and integrity.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img fetchpriority=\"high\" decoding=\"async\" width=\"1024\" height=\"430\" src=\"https:\/\/tekmart.co.za\/t-blog\/wp-content\/uploads\/2021\/10\/The-pillars-of-information-assurance-1024x430.png\" alt=\"The pillars of information assurance\" class=\"wp-image-7794\" srcset=\"https:\/\/tekmart.co.za\/t-blog\/wp-content\/uploads\/2021\/10\/The-pillars-of-information-assurance-1024x430.png 1024w, https:\/\/tekmart.co.za\/t-blog\/wp-content\/uploads\/2021\/10\/The-pillars-of-information-assurance-300x126.png 300w, https:\/\/tekmart.co.za\/t-blog\/wp-content\/uploads\/2021\/10\/The-pillars-of-information-assurance-768x323.png 768w, https:\/\/tekmart.co.za\/t-blog\/wp-content\/uploads\/2021\/10\/The-pillars-of-information-assurance-800x336.png 800w, https:\/\/tekmart.co.za\/t-blog\/wp-content\/uploads\/2021\/10\/The-pillars-of-information-assurance.png 1200w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><figcaption><strong>Nonrepudiation is one of the pillars of information assurance.<\/strong><\/figcaption><\/figure>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>Nonrepudiation, message authentication code and digital signatures<\/strong><\/h3>\n\n\n\n<p>Nonrepudiation is achieved through\u00a0cryptography, like digital signatures, and includes other services for authentication, auditing and logging.<\/p>\n\n\n\n<p>In online transactions, digital signatures ensure that a party cannot later deny sending information or deny the authenticity of its signature. A digital signature is created using the\u00a0private key\u00a0of an\u00a0asymmetric key pair, which is public key cryptography, and verified with a corresponding public key.<\/p>\n\n\n\n<p>Only the private key holder can access this key and create this signature, proving that a document was\u00a0electronically signed\u00a0by that holder. This ensures that a person cannot later deny that they furnished the signature, providing nonrepudiation.<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\"><p>In cryptography, a message authentication code (MAC), also known as a\u00a0<em>tag<\/em>, is used to authenticate a message or confirm that the message came from the stated sender and was not changed along the way. Unlike digital signatures, MAC values are generated and verified using the same secret key, which the sender and recipient must agree on before initiating communications.<\/p><\/blockquote>\n\n\n\n<p>A MAC can protect against message forgery by anyone who doesn&#8217;t know the shared secret key, providing both integrity and authentication. However, MAC algorithms, like\u00a0cipher-based MAC and\u00a0hash-based MAC, cannot provide nonrepudiation.<\/p>\n\n\n\n<p>In addition to digital signatures, nonrepudiation is also used in digital contracts and email. Email nonrepudiation involves methods such as email tracking.<\/p>\n\n\n\n<figure class=\"wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio\"><div class=\"wp-block-embed__wrapper\">\n<iframe title=\"What are Digital Signatures and How Do They Work?\" width=\"500\" height=\"281\" src=\"https:\/\/www.youtube.com\/embed\/uw4aTvRDHB4?feature=oembed\" frameborder=\"0\" allow=\"accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share\" referrerpolicy=\"strict-origin-when-cross-origin\" allowfullscreen><\/iframe>\n<\/div><\/figure>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>Drawbacks of nonrepudiation with digital signatures<\/strong><\/h3>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\"><p>Since no\u00a0security\u00a0technology is foolproof, some experts warn that a digital signature alone may not always guarantee nonrepudiation. Some suggest using multiple approaches to ensure nonrepudiation. One such practice is to capture\u00a0biometric\u00a0information and other data about the sender or signer that collectively would be difficult to repudiate.<\/p><\/blockquote>\n\n\n\n<p>It&#8217;s also important to know that the current definitions of nonrepudiation in the digital space consider only the validity of the signature itself. They do not allow for the possibility that the signer was manipulated, forced or tricked into signing. It&#8217;s also feasible that a\u00a0virus,\u00a0worm\u00a0or other type of\u00a0malware\u00a0can compromise a sender&#8217;s private key, possibly stealing or forging its digital signature and jeopardizing nonrepudiation.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img decoding=\"async\" width=\"941\" height=\"1024\" src=\"https:\/\/tekmart.co.za\/t-blog\/wp-content\/uploads\/2021\/10\/Types-of-biometric-aunthentication-941x1024.png\" alt=\"Types of biometric aunthentication\" class=\"wp-image-7795\" srcset=\"https:\/\/tekmart.co.za\/t-blog\/wp-content\/uploads\/2021\/10\/Types-of-biometric-aunthentication-941x1024.png 941w, https:\/\/tekmart.co.za\/t-blog\/wp-content\/uploads\/2021\/10\/Types-of-biometric-aunthentication-276x300.png 276w, https:\/\/tekmart.co.za\/t-blog\/wp-content\/uploads\/2021\/10\/Types-of-biometric-aunthentication-768x835.png 768w, https:\/\/tekmart.co.za\/t-blog\/wp-content\/uploads\/2021\/10\/Types-of-biometric-aunthentication-800x870.png 800w, https:\/\/tekmart.co.za\/t-blog\/wp-content\/uploads\/2021\/10\/Types-of-biometric-aunthentication.png 1070w\" sizes=\"(max-width: 941px) 100vw, 941px\" \/><figcaption><strong>Specific information about a sender or signer through biometrics strengthens the nonrepudiation process.<\/strong><\/figcaption><\/figure>\n\n\n\n<p>To avoid such issues and to ensure that a digital signature is valid &#8212; and, therefore, the appropriate choice for nonrepudiation &#8212; it must be established through a secure and fully trusted document handling and signature mechanism.<\/p>\n\n\n\n<p>Another concern is the possibility that a digital signature remains the same, even if it&#8217;s been faked by someone who has the private key. The U.S. Department of Defense addressed this problem with the common access card (CAC), a type of\u00a0smart card\u00a0for active duty defense personnel.<\/p>\n\n\n\n<p>The CAC proves the holder&#8217;s identity and enables physical access to controlled spaces and defense computer systems. It satisfies the requirements for digital signatures, as well as three IA pillars: nonrepudiation, integrity and authentication.<\/p>\n\n\n\n<figure class=\"wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio\"><div class=\"wp-block-embed__wrapper\">\n<iframe title=\"What is Multifactor Authentication (MFA)?\" width=\"500\" height=\"281\" src=\"https:\/\/www.youtube.com\/embed\/_3rlQVXGKZc?feature=oembed\" frameborder=\"0\" allow=\"accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share\" referrerpolicy=\"strict-origin-when-cross-origin\" allowfullscreen><\/iframe>\n<\/div><\/figure>\n","protected":false},"excerpt":{"rendered":"<p><span class=\"span-reading-time rt-reading-time\" style=\"display: block;\"><span class=\"rt-label rt-prefix\">Reading Time-approximately:<\/span> <span class=\"rt-time\"> 3<\/span> <span class=\"rt-label rt-postfix\">minutes<\/span><\/span>Nonrepudiation ensures that no party can deny that it sent or received a message via\u00a0encryption\u00a0and\/or\u00a0digital signatures\u00a0or approved some information. It also cannot deny the authenticity of its signature on a document. By Rahul Awati Although it originated as a legal concept, nonrepudiation is also widely used in computing,\u00a0information security\u00a0and communications. Information assurance and nonrepudiation Nonrepudiation is one of the five<\/p>\n<p><a class=\"more-link\" href=\"https:\/\/tekmart.co.za\/t-blog\/what-is-nonrepudiation-an-expert-explanation-and-its-drawbacks\/\">Read More<\/a><\/p>\n","protected":false},"author":113,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[307,4,127,30,54,125,3,184,28,33,147,238],"tags":[],"class_list":["post-7793","post","type-post","status-publish","format-standard","hentry","category-cybersecurity-risk-assessment-and-management","category-datacenter-news","category-enterprise-identity-and-access-management","category-expert-advise-and-opinion","category-hackers-and-cybercrime-prevention","category-identity-and-access-management","category-industry-news-and-expert-advise","category-msps-and-cybersecurity","category-partner-content","category-partner-resources","category-security","category-timeless-articles"],"_links":{"self":[{"href":"https:\/\/tekmart.co.za\/t-blog\/wp-json\/wp\/v2\/posts\/7793","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/tekmart.co.za\/t-blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/tekmart.co.za\/t-blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/tekmart.co.za\/t-blog\/wp-json\/wp\/v2\/users\/113"}],"replies":[{"embeddable":true,"href":"https:\/\/tekmart.co.za\/t-blog\/wp-json\/wp\/v2\/comments?post=7793"}],"version-history":[{"count":2,"href":"https:\/\/tekmart.co.za\/t-blog\/wp-json\/wp\/v2\/posts\/7793\/revisions"}],"predecessor-version":[{"id":7797,"href":"https:\/\/tekmart.co.za\/t-blog\/wp-json\/wp\/v2\/posts\/7793\/revisions\/7797"}],"wp:attachment":[{"href":"https:\/\/tekmart.co.za\/t-blog\/wp-json\/wp\/v2\/media?parent=7793"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/tekmart.co.za\/t-blog\/wp-json\/wp\/v2\/categories?post=7793"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/tekmart.co.za\/t-blog\/wp-json\/wp\/v2\/tags?post=7793"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}