CompTIA SecurityX (CAS-005)Security EngineeringMedium

A security architect is designing a new microservices platform that will host highly sensitive customer data. To minimize the blast radius in case of a compromise, each microservice instance must have its own unique encryption key for its persistent data, and these keys must be protected by a master key. Which cryptographic technique BEST describes this approach?

  1. AEnvelope Encryption
  2. BAsymmetric Key Encryption
  3. CSymmetric Key Encryption
  4. DHomomorphic Encryption
Show answer & explanation

Correct answer: A. Envelope Encryption

Envelope encryption uses a data encryption key (DEK) to encrypt the actual data, and then encrypts the DEK itself with a master key (key encryption key or KEK). This approach allows for unique DEKs per data set/microservice while centralizing the protection of those DEKs with a more securely managed KEK, aligning with the described scenario.

Why the other options are wrong

  • B. Asymmetric key encryption uses a public/private key pair for encryption and decryption, typically for secure communication or digital signatures, not for hierarchical data encryption keys.
  • C. Symmetric key encryption uses a single key for both encryption and decryption, but doesn't inherently describe the hierarchical key protection model.
  • D. Homomorphic encryption allows computations on encrypted data without decrypting it, which is not the primary goal described.

Envelope Encryption

A cryptographic method where data is encrypted with a data encryption key (DEK), and the DEK itself is then encrypted with a key encryption key (KEK).

  • Separates data encryption from key encryption.
  • Allows for frequent rotation of DEKs without re-encrypting all data.
  • KEKs are typically managed by a secure service (e.g., KMS, HSM).

Memory trick: Envelope encryption is like putting your secret message in a small, sealed envelope, and then putting that envelope into a locked safe.

More Security Engineering questions