Security Dimension 3 Non-Repudiation per X.805 Clause 6.3: Non-repudiation provides means for preventing an individual or entity from denying having performed a particular action related to data by making available proof of various network-related actions (e.g. proof of obligation + intent + or commitment + proof of data origin + proof of ownership + proof of resource use). It ensures the availability of evidence that can be presented to a third party and used to prove that some kind of event or action has taken place. (1) Non-Repudiation Categories per X.805 + X.813: (a) Non-Repudiation of Origin (NRO) - prevents the sender from denying having sent a message; (b) Non-Repudiation of Delivery (NRD) - prevents the recipient from denying having received a message; (c) Non-Repudiation of Submission (NRS) - proves submission to delivery agent; (d) Non-Repudiation of Transport (NRT) - proves message transit; (e) Non-Repudiation of Approval (NRA) - proves approval action; (f) Non-Repudiation of Sender (NRSr); (g) Non-Repudiation of Receipt by Recipient (NRRr). (2) Implementation Mechanisms: (a) Digital Signatures (RSA + ECDSA + EdDSA + Post-Quantum signatures like CRYSTALS-Dilithium + Falcon + SPHINCS+); (b) Trusted Time-Stamping (TSA + RFC 3161 + ETSI EN 319 422 + GMT timing); (c) Hash chains + Blockchain immutable ledgers; (d) Public Key Infrastructure (PKI) + X.509 Certificate Chain + Long-Term Validation (LTV); (e) Notary services + Trust Service Providers + Qualified Trust Service Providers (QTSP) per eIDAS; (f) Audit Logs + Tamper-evident logging + WORM Write-Once-Read-Many + immutable storage; (g) Trusted Hardware (HSM Hardware Security Modules + TPM + Secure Enclaves SGX + ARM TrustZone); (h) Key Escrow + Key Recovery for legal access; (i) Forensic preservation chain-of-custody. (3) Non-Repudiation per Security Layer: (a) Infrastructure - device action logging + signing of configuration commits + change tickets; (b) Services - service-level transaction signing + IMS Call Detail Records (CDR) + SIP Identity (RFC 8224) + STIR/SHAKEN caller ID; (c) Applications - email signing (S/MIME + PGP + DKIM) + document signing (PAdES + XAdES + CAdES + JAdES) + e-signing platforms (Adobe Sign + DocuSign + HelloSign). (4) Non-Repudiation per Security Plane: (a) Management - configuration change audit trails + signed configuration changes + privileged action logging; (b) Control - signed routing updates + signed signalling messages; (c) End-User - signed e-commerce transactions + signed legal documents + signed financial. (5) Threats Mitigated per X.805 Table 1: (a) Destruction (Y); (b) Corruption (Y); (c) Removal (Y); (d) Disclosure (Y); (e) Interruption (Y) - all 5 threats (because the audit evidence cannot be denied). (6) Legal + Regulatory Frameworks: (a) ESIGN Act 2000 (US 15 USC 7001) + UETA Uniform Electronic Transactions Act + state-level adoption; (b) eIDAS Regulation (EU 910/2014) + amendment eIDAS 2.0 + EUDI Wallet + Qualified Electronic Signature (QES) + Advanced Electronic Signature (AdES); (c) Singapore Electronic Transactions Act + UNCITRAL Model Law on Electronic Signatures; (d) India IT Act 2000 + Digital Signature Certificate (DSC) under CCA; (e) UK Electronic Communications Act 2000; (f) ISO/IEC 14533 Long-Term Signature Profile + ISO 32000 PDF + PAdES; (g) Federal Rules of Evidence Rule 902(14) Self-Authenticating; (h) HIPAA + SOX + PCI DSS audit trail requirements. (7) Standards: (a) ITU-T X.813 Non-repudiation framework; (b) ISO/IEC 13888 Non-repudiation; (c) ISO/IEC 14533 Long-Term Signature; (d) ETSI EN 319 4xx series Digital Signatures; (e) RFC 5652 CMS + RFC 5280 X.509; (f) FIPS 186-5 Digital Signature Standard; (g) FIPS 203-205 Post-Quantum Signatures; (h) NIST SP 800-89 Recommendation for Obtaining Assurances for Digital Signature Applications. (8) Modern Evolution: (a) Blockchain + Distributed Ledger immutable ledgers for proof; (b) Self-Sovereign Identity (SSI) verifiable credentials; (c) Zero-Knowledge Proofs (ZKP) for selective disclosure; (d) Post-Quantum Cryptography migration of signature algorithms (NIST PQC Round 4 standards); (e) Long-Term Validation (LTV) for signatures with archive-grade preservation; (f) Cloud HSM (AWS CloudHSM + Azure Dedicated HSM + Google Cloud HSM). Coordinates with X.805 Layer 1/2/3 + Plane 1/2/3 + Threats All-5 + Security Dimension 6 Data Integrity (signatures rely on integrity) + ITU-T X.813 + ISO/IEC 13888 + ETSI EN 319 4xx + eIDAS + ESIGN + IETF RFC 5652 + 5280 + 3161 + 8224 + STIR/SHAKEN + FIPS 186-5 + NIST PQC. ITU-T X.805 Security Dimension 3 Non-Repudiation applies.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.