CompTIA SecurityX (CAS-005)Security ArchitectureMedium

A security architect is designing a secure software supply chain for an organization developing critical infrastructure software. It is paramount to ensure that all software components, including third-party libraries and internal modules, originate from trusted sources and have not been tampered with during transit or storage. Which cryptographic mechanism is BEST suited to verify the authenticity and integrity of these software components?

  1. AHashing algorithms.
  2. BHomomorphic encryption.
  3. CSymmetric encryption.
  4. DDigital signatures.
Show answer & explanation

Correct answer: D. Digital signatures.

Digital signatures use asymmetric cryptography to provide both authenticity (verifying the sender's identity) and integrity (ensuring the data has not been altered) of software components. This is crucial for a secure supply chain to confirm that the software came from a trusted developer and hasn't been tampered with.

Why the other options are wrong

  • A. Hashing algorithms provide integrity (detecting changes) but do not provide authenticity (who created the hash or the original data).
  • B. Homomorphic encryption allows computation on encrypted data but does not directly address authenticity or integrity verification for software components in transit.
  • C. Symmetric encryption provides confidentiality but not authenticity or integrity verification for the sender or content.

Digital Signatures

A digital signature is a mathematical scheme for verifying the authenticity and integrity of digital messages or documents. It uses asymmetric cryptography, where a sender signs data with their private key, and recipients verify it with the sender's public key.

  • Provides authenticity (sender verification) and integrity (tamper detection).
  • Uses public-key cryptography (private key to sign, public key to verify).
  • Non-repudiation: the sender cannot deny having signed the message.
  • Essential for secure software distribution and supply chains.

Memory trick: Sign it, then ship it: prove the source, protect the package.

More Security Architecture questions