TechKnowSurge
VideoSecurityFree

Requirements: Non-Repudiation

Non-repudiation ensures that the sender of a message cannot later deny having sent it, providing a verifiable link between a message and its origin. Though closely related to authenticity, the two concepts serve different sides of the same communication.

Complete this video to capture a CTF flag worth 1 point.

About this video

Non-repudiation is a foundational security concept that ensures a sender cannot later deny having transmitted a message. Once a message is sent, non-repudiation provides verifiable evidence tying that message to its source, making denial ineffective. This is especially critical in environments where the authenticity of communications has legal, operational, or security implications. Although non-repudiation and authenticity are closely related, they address the same communication event from opposite sides. Authenticity is receiver-focused, giving the recipient verifiable proof that a message originated from a claimed source. Non-repudiation is sender-focused, preventing the originating party from disputing that they sent the message in the first place. Understanding this distinction is essential for implementing security controls that protect both parties in any digital exchange.

What you'll learn

What's covered

Non-Repudiation

Key terms

Non-repudiation
The assurance that a party cannot deny having sent or received a message or performed an action.
Authentication
The process of verifying the identity of a user, device, or system.
Digital Signature
A cryptographic mechanism used to verify the authenticity and integrity of a digital message or document.
Authenticity
The assurance that information or a communication originates from the claimed source and has not been fabricated or impersonated. Digital signatures and certificates are common mechanisms for establishing authenticity.

Topics

Non Repudiation Authenticity Cryptography Message Integrity Digital Signatures Security Requirements

Transcript

A very similar concept to authenticity is non-repudiation. Non-repudiation means that if I send something, I can't deny that it came from me. It's a way that somebody can't deny that they sent something. So in this case, Susan's sending a message to David, and Susan now can't deny that this message did come from her.

Consider an example. Say both Susan and David need to be in an important meeting at 12:00. Their boss says, "Be in this meeting." But Susan wants David to miss this meeting, so she sends a message to David and says, "Well, it's been changed to 2:00." Now David shows up at two o'clock and realizes he's in trouble, because he didn't show up to the 12 o'clock meeting. He blames Susan, but Susan denies that she sent the email. What David can do, if there's some sort of non-repudiation, is say, "No, this was sent by Susan. Look at this information." So non-repudiation is this idea that Susan can't deny she sent this message.

Authenticity versus non-repudiation

Authenticity and non-repudiation are really close to the same thing, so let's look at the differences so we understand this. Susan sends a message to David. Authenticity is on David's side: authenticity means that David can see that it came from Susan, that the message is authentic. Non-repudiation is on Susan's side: Susan can't deny that she sent the message. So non-repudiation is that Susan can't say, "No, I didn't send it," and authenticity is that David can say, "Oh yeah, this came from Susan."

About TechKnowSurge

TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.

Explore free tools and programs →