CompTIA SecurityX (CAS-005)Security EngineeringMedium

A security architect is developing a strategy for long-term data archival that must maintain confidentiality and integrity for several decades, even against future advances in cryptanalysis, including quantum computing. The archived data will be accessed infrequently but must remain secure. Which cryptographic approach should be prioritized for protecting this data?

  1. ASymmetric-key encryption with large key sizes
  2. BElliptic Curve Cryptography (ECC)
  3. CHomomorphic Encryption
  4. DPost-Quantum Cryptography (PQC)
Show answer & explanation

Correct answer: D. Post-Quantum Cryptography (PQC)

Post-Quantum Cryptography (PQC) refers to cryptographic algorithms that are designed to be secure against attacks by quantum computers, as well as classical computers. Given the requirement for 'several decades' of security and protection against 'quantum computing' advances, PQC is the most appropriate choice for long-term data archival.

Why the other options are wrong

  • A. Symmetric-key encryption with large key sizes can provide current security but is not inherently resistant to quantum attacks on key exchange or brute-force if quantum algorithms become efficient enough.
  • B. ECC is currently secure against classical attacks but is vulnerable to Shor's algorithm on quantum computers.
  • C. Homomorphic encryption allows computations on encrypted data but does not address the threat of quantum cryptanalysis for long-term archival confidentiality.

Post-Quantum Cryptography (PQC)

Post-Quantum Cryptography (PQC) refers to cryptographic algorithms that are designed to be secure against attacks by quantum computers, as well as classical computers.

  • Developed to replace current public-key algorithms vulnerable to Shor's algorithm.
  • Includes lattice-based, code-based, hash-based, and multivariate polynomial schemes.
  • Essential for long-term data confidentiality and integrity in a post-quantum world.

Memory trick: PQC: protects against quantum leaps in decryption.

More Security Engineering questions