CompTIA SecurityX (CAS-005)Security EngineeringHard
A security architect is developing a strategy for long-term data archival that must maintain confidentiality and integrity for several decades, even against the threat of future quantum computers. The data includes highly sensitive intellectual property. Which advanced cryptographic approach should be prioritized to ensure the enduring security of this archived data?
- APost-Quantum Cryptography (PQC)
- BElliptic Curve Cryptography (ECC)
- CHomomorphic Encryption (HE)
- DSymmetric Encryption (e.g., AES-256 with long keys)
Show answer & explanationAnswer & explanation
Correct answer: A. Post-Quantum Cryptography (PQC)
Post-Quantum Cryptography (PQC) is specifically designed to be resistant to attacks by future quantum computers. For long-term data archival requiring confidentiality and integrity for several decades against this specific threat, PQC algorithms are the only appropriate choice.
Why the other options are wrong
- B. ECC, like RSA, is vulnerable to Shor's algorithm on a sufficiently powerful quantum computer, making it unsuitable for long-term security against quantum threats.
- C. Homomorphic Encryption allows computations on encrypted data but does not primarily address the quantum threat to key exchange or digital signatures, nor does it guarantee long-term confidentiality against quantum attacks better than PQC.
- D. Symmetric encryption (like AES-256) is generally considered more quantum-resistant than asymmetric algorithms, but Grover's algorithm could halve its effective key length. While a sufficiently large key size might offer some protection, PQC offers dedicated solutions for all cryptographic primitives.
Post-Quantum Cryptography (PQC)
Cryptographic algorithms that are believed to be secure against cryptanalytic attacks by both classical and quantum computers. PQC aims to replace current public-key cryptography standards vulnerable to quantum algorithms.
- Resistant to Shor's and Grover's algorithms.
- Focuses on public-key algorithms (key exchange, digital signatures).
- Standardization efforts are ongoing (e.g., NIST PQC competition).
Memory trick: PQC Protects Quantum-Proof Confidentiality.