1
00:00:00,000 --> 00:00:00,930
In this lesson,

2
00:00:00,930 --> 00:00:03,270
we're going to cover non-repudiation.

3
00:00:03,270 --> 00:00:05,850
Now, non-repudiation in cybersecurity is focused

4
00:00:05,850 --> 00:00:07,350
on providing undeniable proof

5
00:00:07,350 --> 00:00:09,630
in the world of digital transactions.

6
00:00:09,630 --> 00:00:11,460
Non-repudiation is a security measure

7
00:00:11,460 --> 00:00:12,540
that ensures individuals

8
00:00:12,540 --> 00:00:14,700
or entities involved in a communication

9
00:00:14,700 --> 00:00:17,400
or transaction cannot deny their participation

10
00:00:17,400 --> 00:00:19,830
or the authenticity of their actions.

11
00:00:19,830 --> 00:00:21,420
I like to think about this as the difference

12
00:00:21,420 --> 00:00:23,430
between sending a standard letter in the mail

13
00:00:23,430 --> 00:00:24,263
and sending one

14
00:00:24,263 --> 00:00:26,460
that requires a signed receipt upon delivery.

15
00:00:26,460 --> 00:00:28,650
The receiver's signature on the receipt tells us

16
00:00:28,650 --> 00:00:30,000
that the recipient can't deny

17
00:00:30,000 --> 00:00:31,920
that they have received that letter.

18
00:00:31,920 --> 00:00:34,770
In fact, non-repudiation has been used for centuries,

19
00:00:34,770 --> 00:00:37,830
even before computers were even developed or thought of.

20
00:00:37,830 --> 00:00:39,900
If we look back a few hundred years or more,

21
00:00:39,900 --> 00:00:42,150
kings and noblemen used to use signet rings

22
00:00:42,150 --> 00:00:45,390
to imprint their unique seal onto a wax on a document

23
00:00:45,390 --> 00:00:46,830
to make sure it was sealed.

24
00:00:46,830 --> 00:00:49,350
This seal acted as a form of non-repudiation.

25
00:00:49,350 --> 00:00:51,660
If a decree or letter bore that king's seal,

26
00:00:51,660 --> 00:00:54,060
it was undeniable evidence that it was authentic

27
00:00:54,060 --> 00:00:56,130
and it came from the king himself.

28
00:00:56,130 --> 00:00:57,930
Now, anyone receiving this sealed document

29
00:00:57,930 --> 00:01:00,510
could be confident of who sent it because only the king

30
00:01:00,510 --> 00:01:03,510
or that noble person had that specific signet ring.

31
00:01:03,510 --> 00:01:05,190
So they couldn't claim that the contents

32
00:01:05,190 --> 00:01:08,070
of the document were not written by that person.

33
00:01:08,070 --> 00:01:10,140
Hopefully, this medieval example does help you

34
00:01:10,140 --> 00:01:12,450
to underscore the importance and timeless nature

35
00:01:12,450 --> 00:01:14,430
of ensuring authenticity and accountability

36
00:01:14,430 --> 00:01:16,470
in all of our communications and transactions

37
00:01:16,470 --> 00:01:19,650
because that is what non-repudiation is all about.

38
00:01:19,650 --> 00:01:21,600
Now, let's move back into the digital world

39
00:01:21,600 --> 00:01:23,190
and we don't use signet rings here

40
00:01:23,190 --> 00:01:25,410
but instead we use something that's more modern.

41
00:01:25,410 --> 00:01:27,420
This is a digital signature.

42
00:01:27,420 --> 00:01:29,970
Now, a digital signature, much like the king's signet ring,

43
00:01:29,970 --> 00:01:31,080
is considered to be unique

44
00:01:31,080 --> 00:01:33,900
to each user who's operating within the digital domain.

45
00:01:33,900 --> 00:01:35,280
A digital signature is created

46
00:01:35,280 --> 00:01:37,890
by first hashing a particular message or communication

47
00:01:37,890 --> 00:01:39,480
that you want to digitally sign

48
00:01:39,480 --> 00:01:41,640
and then it encrypts that hash digest

49
00:01:41,640 --> 00:01:45,000
with the user's private key using asymmetric encryption.

50
00:01:45,000 --> 00:01:46,950
This allows the digital signature to ensure

51
00:01:46,950 --> 00:01:48,990
that a piece of information, whether it's an email

52
00:01:48,990 --> 00:01:51,960
or a transaction, originated from a stated source

53
00:01:51,960 --> 00:01:54,300
and hasn't been altered during its transit.

54
00:01:54,300 --> 00:01:55,980
If someone attempts to refute their involvement

55
00:01:55,980 --> 00:01:58,345
in the digitally signed transaction, the signature serves

56
00:01:58,345 --> 00:02:01,410
as undeniable proof that they actually sent that

57
00:02:01,410 --> 00:02:04,110
and the integrity of that transaction hasn't been changed

58
00:02:04,110 --> 00:02:05,910
since they used their private key to create

59
00:02:05,910 --> 00:02:08,280
that digital signature, and that digital signature

60
00:02:08,280 --> 00:02:10,889
is made up of an encrypted hash digest.

61
00:02:10,889 --> 00:02:14,250
Now, non-repudiation is important for three main reasons.

62
00:02:14,250 --> 00:02:15,750
We use it to confirm the authenticity

63
00:02:15,750 --> 00:02:17,100
of digital transactions.

64
00:02:17,100 --> 00:02:18,420
We use it to ensure the integrity

65
00:02:18,420 --> 00:02:20,520
of critical communications, and we use it

66
00:02:20,520 --> 00:02:23,310
to provide accountability in digital processes.

67
00:02:23,310 --> 00:02:25,500
First, we have confirming the authenticity

68
00:02:25,500 --> 00:02:27,150
of digital transactions.

69
00:02:27,150 --> 00:02:28,200
In the digital world,

70
00:02:28,200 --> 00:02:30,810
impersonation and identity theft is so much easier

71
00:02:30,810 --> 00:02:32,670
to perform than it was in person.

72
00:02:32,670 --> 00:02:35,280
So it really is important that a system has the capability

73
00:02:35,280 --> 00:02:38,520
to guarantee a transaction or communication's authenticity

74
00:02:38,520 --> 00:02:40,260
is there to ensure that your users

75
00:02:40,260 --> 00:02:42,900
can't state they didn't perform a certain action.

76
00:02:42,900 --> 00:02:44,970
So if I sent a digitally signed email

77
00:02:44,970 --> 00:02:48,180
to my stockbroker asking him to sell 100% of my shares,

78
00:02:48,180 --> 00:02:50,190
he can be assured that it was really me who sent it

79
00:02:50,190 --> 00:02:52,080
because I digitally signed it.

80
00:02:52,080 --> 00:02:53,340
But if he receives an email

81
00:02:53,340 --> 00:02:55,050
from me that is not digitally signed,

82
00:02:55,050 --> 00:02:57,300
there is no assurance that I actually sent it.

83
00:02:57,300 --> 00:02:59,160
After all, you could go out right now

84
00:02:59,160 --> 00:03:00,750
and sign up for a free email account

85
00:03:00,750 --> 00:03:05,280
like jasondion@yahoo.com or jasondion@gmail.com

86
00:03:05,280 --> 00:03:07,620
and pretend to be somebody else pretty easily.

87
00:03:07,620 --> 00:03:09,570
But you really can't fake their digital signature

88
00:03:09,570 --> 00:03:11,580
because only they have their private key

89
00:03:11,580 --> 00:03:14,640
that's going to be used inside of that digital signature.

90
00:03:14,640 --> 00:03:16,920
Second, we have ensuring integrity.

91
00:03:16,920 --> 00:03:19,020
With non-repudiation measures in place,

92
00:03:19,020 --> 00:03:20,490
all the parties involved can trust

93
00:03:20,490 --> 00:03:22,350
that the messages haven't been tampered with

94
00:03:22,350 --> 00:03:24,300
because any alteration would break the chain

95
00:03:24,300 --> 00:03:25,740
of undeniable proof.

96
00:03:25,740 --> 00:03:28,350
Since non-repudiation relies on digital signatures

97
00:03:28,350 --> 00:03:30,570
and digital signatures have hash values in them,

98
00:03:30,570 --> 00:03:32,700
these digital signatures are used to ensure

99
00:03:32,700 --> 00:03:35,910
not just non-repudiation, but also integrity.

100
00:03:35,910 --> 00:03:39,030
And third, and finally, we have providing accountability.

101
00:03:39,030 --> 00:03:40,800
When every action has a digital stamp

102
00:03:40,800 --> 00:03:43,230
of authenticity attached to it, we can create a sense

103
00:03:43,230 --> 00:03:46,020
of responsibility and accountability among our users

104
00:03:46,020 --> 00:03:48,150
because they know that their actions can be traced back

105
00:03:48,150 --> 00:03:49,920
to them without denial.

106
00:03:49,920 --> 00:03:52,320
For example, some auto insurance companies now

107
00:03:52,320 --> 00:03:54,870
have the option for people to use an app on their smartphone

108
00:03:54,870 --> 00:03:57,090
that will feed their real-time driving data back

109
00:03:57,090 --> 00:03:58,620
to the insurance company.

110
00:03:58,620 --> 00:04:00,480
If you agree to use that tracking app,

111
00:04:00,480 --> 00:04:02,730
it will tell the insurance company how fast you drive,

112
00:04:02,730 --> 00:04:05,220
how quickly you change lanes, how long you wait to brake

113
00:04:05,220 --> 00:04:07,410
for a stop sign and things like that.

114
00:04:07,410 --> 00:04:09,540
In return for allowing them to collect this data,

115
00:04:09,540 --> 00:04:12,240
you can get a potential discount on your auto insurance

116
00:04:12,240 --> 00:04:14,880
if you drive within their safe driving profiles.

117
00:04:14,880 --> 00:04:17,550
For many drivers, opting into this app will provide them

118
00:04:17,550 --> 00:04:20,310
with accountability and remind them to drive more safely.

119
00:04:20,310 --> 00:04:22,410
And because the app is installed in your smartphone,

120
00:04:22,410 --> 00:04:24,330
the company knows it's you who's driving

121
00:04:24,330 --> 00:04:25,920
and this provides non-repudiation

122
00:04:25,920 --> 00:04:27,900
since you can unlock the phone using your face

123
00:04:27,900 --> 00:04:31,170
or fingerprint to activate this app every time you log in

124
00:04:31,170 --> 00:04:32,760
and start a new drive.

125
00:04:32,760 --> 00:04:34,590
So remember, non-repudiation

126
00:04:34,590 --> 00:04:36,240
is about ensuring undeniable proof

127
00:04:36,240 --> 00:04:38,940
of your participation in a digital interaction.

128
00:04:38,940 --> 00:04:40,470
When you think about non-repudiation,

129
00:04:40,470 --> 00:04:41,730
I want you to think about the fact

130
00:04:41,730 --> 00:04:44,100
that someone cannot say they didn't do something

131
00:04:44,100 --> 00:04:46,590
because you have a method to prove that they did.

132
00:04:46,590 --> 00:04:48,600
The best tool for achieving non-repudiation

133
00:04:48,600 --> 00:04:50,160
really is digital signatures.

134
00:04:50,160 --> 00:04:52,140
So if you hear the word non-repudiation,

135
00:04:52,140 --> 00:04:53,880
immediately, I want you to start thinking

136
00:04:53,880 --> 00:04:55,200
about digital signatures

137
00:04:55,200 --> 00:04:57,450
to achieve a level of trustworthiness.

138
00:04:57,450 --> 00:04:59,820
In the digital landscape where trust is paramount,

139
00:04:59,820 --> 00:05:03,180
non-repudiation does stand out as a beacon of authenticity,

140
00:05:03,180 --> 00:05:04,650
accountability, and assurance

141
00:05:04,650 --> 00:05:07,173
for all of our digital transactions and messages.

