CompTIA SecurityX (CAS-005)Security EngineeringMedium

A critical infrastructure organization is integrating a new Industrial Control System (ICS) into its operational technology (OT) network. To ensure the highest level of security and prevent unauthorized access or modification, all communications between the ICS components and the supervisory control systems must be integrity-protected and cryptographically authenticated. Given the real-time constraints and resource limitations of some ICS devices, which advanced cryptographic primitive would be MOST suitable for ensuring data integrity and authenticity without full encryption?

  1. AHash-based Message Authentication Code (HMAC)
  2. BRSA Digital Signature Algorithm
  3. CElliptic Curve Digital Signature Algorithm (ECDSA)
  4. DAdvanced Encryption Standard (AES)
Show answer & explanation

Correct answer: A. Hash-based Message Authentication Code (HMAC)

The requirement is for data integrity and authenticity without full encryption, especially considering real-time constraints and resource limitations. HMAC (Hash-based Message Authentication Code) provides both data integrity (detects accidental or intentional modification) and authenticity (verifies the sender's identity using a shared secret key) efficiently. AES is for encryption, and ECDSA/RSA are digital signature algorithms that provide non-repudiation in addition to integrity and authenticity but are computationally more expensive than HMAC and might be overkill for resource-constrained ICS devices if non-repudiation is not a strict requirement.

Why the other options are wrong

  • B. RSA Digital Signature Algorithm provides integrity, authenticity, and non-repudiation, but like ECDSA, it's computationally heavier than HMAC and might exceed resource constraints.
  • C. ECDSA provides digital signatures for integrity, authenticity, and non-repudiation, but it's generally more computationally intensive than HMAC and might be an overkill if non-repudiation isn't strictly required.
  • D. AES is a symmetric encryption algorithm designed for confidentiality, not primarily for integrity and authenticity without encryption.

HMAC

HMAC (Hash-based Message Authentication Code) is a specific type of Message Authentication Code (MAC) involving a cryptographic hash function and a secret cryptographic key. It is used to simultaneously verify both the data integrity and the authenticity of a message.

  • Provides both data integrity and authenticity.
  • Uses a shared secret key.
  • More efficient than digital signatures for integrity/authenticity.
  • Does NOT provide confidentiality (encryption).

Memory trick: HMAC Keeps ICS Messages Honest and Authentic

More Security Engineering questions