CompTIA SecurityX (CAS-005)Security ArchitectureMedium

A security architect is designing a secure software supply chain for a critical aerospace system. The architect needs to ensure that software artifacts (e.g., binaries, libraries) originating from trusted developers are not tampered with during transit or storage before deployment. This requires a mechanism to verify the authenticity and integrity of each artifact. Which cryptographic control is best suited for this purpose?

  1. ADigital Signatures
  2. BHomomorphic Encryption
  3. CSymmetric Encryption
  4. DHashing
Show answer & explanation

Correct answer: A. Digital Signatures

Digital signatures provide both authenticity (verifying the sender's identity) and integrity (ensuring the data hasn't been altered) for software artifacts. A trusted developer signs the artifact with their private key, and anyone can verify it using their public key, which is crucial for a secure supply chain.

Why the other options are wrong

  • B. Homomorphic encryption allows computation on encrypted data but doesn't primarily address authentication or integrity of the artifact itself.
  • C. Symmetric encryption provides confidentiality but not authentication or integrity (unless combined with MACs).
  • D. Hashing provides data integrity (detects changes) but does not provide authenticity (who created it) on its own.

Digital Signatures

A digital signature is a mathematical scheme for demonstrating the authenticity and integrity of digital messages or documents. It uses asymmetric cryptography, where a sender signs data with their private key, and a receiver verifies it using the sender's public key.

  • Provides authenticity (originator verification) and integrity (tamper detection).
  • Uses asymmetric cryptography (private key for signing, public key for verification).
  • Non-repudiation: the sender cannot deny having signed the data.
  • Crucial for secure software distribution and document verification.

Memory trick: Digital Signatures Deliver Documented Integrity.

More Security Architecture questions