Glossary · Records and compliance

Non-repudiation

Evidence that stops a party from credibly denying it sent or received something, usually a digital signature plus trusted time and key records.

Non-repudiation is a security service that produces evidence a party cannot credibly deny, such as proof that it sent a particular message or that it received one.

Two directions. RFC 4949, the internet security glossary, separates non-repudiation with proof of origin, where the sender cannot deny sending, from non-repudiation with proof of receipt, where the recipient cannot deny receiving. It also stresses that the service does not stop anyone from denying anything. It creates evidence that can be stored and later shown to a third party to settle a dispute.

Technical and legal. RFC 4949 draws a second line. Technical non-repudiation is the assurance that a signature verified with a public key was made with the matching private key. Legal non-repudiation is how well anyone can establish who possessed or controlled that private key. A valid signature from a stolen key proves little about the key’s owner.

Building blocks.

Evidence needed Mechanism
Who produced it A digital signature, such as a JWS or an HTTP Message Signature (RFC 9421), with a key bound to an identity
When Trusted timestamps; the DID specification ties non-repudiation of DID updates to verifiable timestamps
That the key was valid then Certificate and key status records; X.509’s key usage bit for this purpose, originally nonRepudiation, is named contentCommitment in recent X.509 editions (RFC 5280)
That the record was not altered later A tamper-evident log

For agents. After an agent-to-agent exchange, the questions are usually which agent asked for what, on whose authority, and what the other side agreed to. Signing each request, each response and the authorization behind it, and keeping those signatures in a tamper-evident log, produces evidence for all three. A2A defines signatures for Agent Cards only. It defines none for messages or task results, so non-repudiation of an exchange has to come from extensions, HTTP-level signatures or separate records.

Neighbouring terms. A tamper-evident log preserves the evidence. A signed Agent Card is the one signed artifact A2A itself defines.

Sources

  1. RFC 4949: Internet Security Glossary, Version 2 (non-repudiation service) (accessed )
  2. RFC 5280: Internet X.509 PKI Certificate and CRL Profile, section 4.2.1.3: Key Usage (accessed )
  3. RFC 9421: HTTP Message Signatures (accessed )
  4. W3C Decentralized Identifiers (DIDs) v1.0, section 9.4: Non-Repudiation (accessed )
  5. A2A Protocol Specification, section 8.4: Agent Card Signing (accessed )