CompTIA SecurityX (CAS-005)Security EngineeringMedium
A security architect is designing a new cloud-native application that will process highly sensitive personal identifiable information (PII). The application uses microservices, and each microservice needs to securely communicate with other microservices without relying on a centralized certificate authority or pre-shared keys for every connection. Which of the following advanced cryptographic techniques would BEST address this requirement?
- AHomomorphic Encryption
- BFormat-Preserving Encryption (FPE)
- CQuantum Key Distribution (QKD)
- DMutual Transport Layer Security (mTLS)
Show answer & explanationAnswer & explanation
Correct answer: D. Mutual Transport Layer Security (mTLS)
Mutual Transport Layer Security (mTLS) provides two-way authentication, ensuring that both the client and server verify each other's identities using certificates. This is ideal for secure microservice communication within a Zero Trust architecture, eliminating the need for centralized CAs or pre-shared keys for every individual service.
Why the other options are wrong
- A. Homomorphic encryption allows computations on encrypted data but does not primarily address secure communication between services.
- B. FPE encrypts data while retaining its original format, useful for database fields, but not for mutual authentication between services.
- C. QKD is a method for securely exchanging cryptographic keys using quantum mechanics, not directly for securing microservice communication authentication.
Mutual TLS (mTLS)
Mutual TLS is a method for two-way authentication where both the client and server present certificates to each other to verify their identities.
- Provides strong authentication for both ends of a connection.
- Commonly used in Zero Trust architectures and microservices.
- Relies on public key infrastructure (PKI) for certificate issuance.
Memory trick: Microservices mutually trust, like a secure handshake.