CompTIA SecurityX (CAS-005)Security ArchitectureMedium
A security architect is designing a secure software supply chain for a critical aerospace system. The architect needs to ensure that software artifacts (e.g., binaries, libraries) originating from trusted developers are not tampered with during transit or storage before deployment. This requires a mechanism to verify the authenticity and integrity of each artifact. Which cryptographic control is best suited for this purpose?
- ADigital Signatures
- BHomomorphic Encryption
- CSymmetric Encryption
- DHashing
Show answer & explanationAnswer & explanation
Correct answer: A. Digital Signatures
Digital signatures provide both authenticity (verifying the sender's identity) and integrity (ensuring the data hasn't been altered) for software artifacts. A trusted developer signs the artifact with their private key, and anyone can verify it using their public key, which is crucial for a secure supply chain.
Why the other options are wrong
- B. Homomorphic encryption allows computation on encrypted data but doesn't primarily address authentication or integrity of the artifact itself.
- C. Symmetric encryption provides confidentiality but not authentication or integrity (unless combined with MACs).
- D. Hashing provides data integrity (detects changes) but does not provide authenticity (who created it) on its own.
Digital Signatures
A digital signature is a mathematical scheme for demonstrating the authenticity and integrity of digital messages or documents. It uses asymmetric cryptography, where a sender signs data with their private key, and a receiver verifies it using the sender's public key.
- Provides authenticity (originator verification) and integrity (tamper detection).
- Uses asymmetric cryptography (private key for signing, public key for verification).
- Non-repudiation: the sender cannot deny having signed the data.
- Crucial for secure software distribution and document verification.
Memory trick: Digital Signatures Deliver Documented Integrity.