Non-repudiation
Non-repudiation is the degree to which an action or event can be proven to have taken place, such that the party responsible for it cannot credibly deny it afterwards. It is a quality attribute and, per ISO/IEC 25010, a sub-characteristic of security.
In practice, non-repudiation is achieved through mechanisms that bind an action to its originator in a way a third party can verify, such as a digital signature or an audit log entry cryptographically linked to a principal's identity.
It’s distinct from authenticity, which establishes that data or a message genuinely comes from a claimed source. Authenticity is about identifying who acted, while non-repudiation is about making that identification stand up as proof later, even if the party disputes it.
References
- ISO/IEC (2023). ISO/IEC 25010:2023 — Systems and software Quality Requirements and Evaluation (SQuaRE) — Quality model.