CompTIA SecurityX (CAS-005)Security ArchitectureMedium

A company is developing a secure communication platform. The architecture requires that messages between users are encrypted end-to-end, and the system must be able to verify the identity of both the sender and receiver without a central authority acting as an intermediary for key exchange. Which cryptographic primitive is MOST suitable for establishing secure, authenticated communication channels in this scenario?

  1. AAsymmetric Key Cryptography
  2. BSymmetric Key Cryptography
  3. CHashing Algorithms
  4. DMessage Authentication Codes (MACs)
Show answer & explanation

Correct answer: A. Asymmetric Key Cryptography

Asymmetric key cryptography (also known as public-key cryptography) is essential for end-to-end encrypted communication without a central key exchange authority. It allows parties to securely exchange public keys and then use them for key establishment (e.g., Diffie-Hellman) or digital signatures (for authentication), which are crucial for verifying sender/receiver identity and establishing a secure channel.

Why the other options are wrong

  • B. Symmetric key cryptography requires a shared secret key, which poses a significant challenge for secure key exchange without a central authority or prior arrangement.
  • C. Hashing algorithms provide integrity checks but do not offer encryption or a mechanism for secure key exchange or identity verification.
  • D. MACs provide data integrity and authenticity but rely on a shared secret key, similar to symmetric encryption, and thus don't solve the decentralized key exchange problem.

Asymmetric Key Cryptography (Public-Key)

Asymmetric key cryptography uses a pair of mathematically linked keys: a public key (shared widely) and a private key (kept secret). It enables secure communication, digital signatures, and key exchange without a pre-shared secret.

  • Uses distinct public and private keys.
  • Public key encrypts data, private key decrypts.
  • Private key signs data, public key verifies signature.
  • Facilitates secure key exchange (e.g., Diffie-Hellman) and digital identities.
  • Foundation for TLS/SSL, PGP, and many secure communication protocols.

Memory trick: Two keys are better than one for secrets and signatures.

More Security Architecture questions