CompTIA SecurityX (CAS-005)Security EngineeringHard
A cryptographer is designing a long-term data archival system that must remain secure against future advances in quantum computing. The data has a retention period of 50 years. Which cryptographic primitive should be prioritized for key exchange to ensure post-quantum security?
- AKyber
- BRSA Key Exchange
- CElliptic Curve Diffie-Hellman (ECDH)
- DDiffie-Hellman (DH)
Show answer & explanationAnswer & explanation
Correct answer: A. Kyber
Kyber is a lattice-based key encapsulation mechanism (KEM) that has been selected by NIST as a primary standard for post-quantum cryptography (PQC) for key exchange/encapsulation. It is designed to resist attacks from quantum computers, making it suitable for long-term security requirements.
Why the other options are wrong
- B. RSA is a public-key algorithm also vulnerable to Shor's algorithm, making it unsuitable for post-quantum security.
- C. ECDH is a widely used public-key algorithm, but it is vulnerable to Shor's algorithm on a sufficiently powerful quantum computer.
- D. Diffie-Hellman is a classic key exchange protocol vulnerable to quantum attacks, similar to RSA and ECDH.
Post-Quantum Cryptography (PQC)
Cryptographic algorithms designed to be secure against attacks by quantum computers as well as classical computers.
- Resistant to Shor's and Grover's algorithms.
- Examples include lattice-based, code-based, hash-based, and multivariate polynomial cryptography.
- NIST is standardizing PQC algorithms for future use.
Memory trick: Quantum era demands new keys, Kyber leads the way.