CompTIA SecurityX (CAS-005)Security EngineeringMedium

A security architect is designing a key management system for a global enterprise that processes highly sensitive data. The system must ensure that cryptographic keys are generated, stored, and used in a way that provides the highest level of tamper resistance and protection against disclosure, even from privileged administrators. Which specialized hardware component would be MOST appropriate for safeguarding the master encryption keys?

  1. AHardware Security Module (HSM)
  2. BSecure Enclave Processor
  3. CField-Programmable Gate Array (FPGA)
  4. DTrusted Platform Module (TPM)
Show answer & explanation

Correct answer: A. Hardware Security Module (HSM)

A Hardware Security Module (HSM) is specifically designed to provide a secure, tamper-resistant environment for cryptographic key generation, storage, and cryptographic operations. HSMs are certified to high-security standards (e.g., FIPS 140-2 Level 3 or 4) and are intended to protect keys even from administrators, offering physical and logical tamper detection and response mechanisms. This directly addresses the requirement for the highest level of tamper resistance and protection against disclosure for master encryption keys in a global enterprise.

Why the other options are wrong

  • B. A Secure Enclave Processor (like Apple's Secure Enclave) is a dedicated secure subsystem within a System-on-a-Chip (SoC) that protects sensitive data (e.g., biometric info, encryption keys) on a local device, but it's not typically used for managing master enterprise-wide encryption keys in a centralized system.
  • C. An FPGA is a reconfigurable integrated circuit that can be programmed for specialized tasks. While it can implement cryptographic functions, it's not inherently a secure key storage or management solution like an HSM and lacks its built-in security features and certifications.
  • D. A TPM provides secure boot, secure storage for platform measurements, and limited cryptographic functions, but it is typically bound to a specific host and offers a lower level of tamper resistance and key management capabilities compared to an HSM.

Hardware Security Module (HSM)

An HSM is a physical computing device that safeguards and manages digital keys for strong authentication and provides cryptoprocessing. These modules traditionally come in the form of a plug-in card or an external network-attached device.

  • Provides tamper-resistant storage for cryptographic keys.
  • Performs cryptographic operations securely within the module.
  • Certified to high security standards (e.g., FIPS 140-2).
  • Protects keys from privileged administrators and physical attacks.

Memory trick: HSM Holds Keys with Highest Security

More Security Engineering questions