CompTIA SecurityX (CAS-005)Security EngineeringMedium

A security architect is designing a new microservices platform that will host highly sensitive customer data. To ensure data confidentiality and integrity, all data at rest must be encrypted. Furthermore, the encryption keys themselves must be protected and managed securely, with the ability to rotate them regularly without re-encrypting all data. Which advanced cryptographic technique would BEST address these requirements?

  1. AHomomorphic Encryption
  2. BHashing with Salting
  3. CEnvelope Encryption
  4. DQuantum Key Distribution (QKD)
Show answer & explanation

Correct answer: C. Envelope Encryption

Envelope encryption uses a data encryption key (DEK) to encrypt the actual data, and then this DEK is encrypted by a master key (Key Encryption Key or KEK). This allows for efficient key rotation by only re-encrypting the smaller DEK with a new KEK, rather than the entire dataset, while maintaining strong security for the DEKs.

Why the other options are wrong

  • A. Homomorphic Encryption allows computations on encrypted data without decrypting it, which is not primarily for key management or data at rest encryption with easy rotation.
  • B. Hashing with salting is used for password storage and integrity verification, not for encrypting data at rest or managing encryption keys.
  • D. Quantum Key Distribution (QKD) is a method for securely distributing cryptographic keys using quantum mechanics, not for encrypting data at rest or managing key rotation in this manner.

Envelope Encryption

A cryptographic technique where data is encrypted with a unique data encryption key (DEK), and the DEK itself is then encrypted with a separate key encryption key (KEK).

  • Data encrypted by DEK
  • DEK encrypted by KEK
  • Enables efficient key rotation (only KEK needs rotation)
  • Separates data encryption from key encryption

Memory trick: Envelope: Keys within keys for easy rotation and secure data.

More Security Engineering questions