CompTIA SecurityX (CAS-005)Security EngineeringMedium
A security architect is designing a new microservices platform that will host highly sensitive customer data. To minimize the blast radius in case of a compromise, each microservice instance must have its own unique encryption key for its persistent data, and these keys must be protected by a master key. Which cryptographic technique BEST describes this approach?
- AEnvelope Encryption
- BAsymmetric Key Encryption
- CSymmetric Key Encryption
- DHomomorphic Encryption
Show answer & explanationAnswer & explanation
Correct answer: A. Envelope Encryption
Envelope encryption uses a data encryption key (DEK) to encrypt the actual data, and then encrypts the DEK itself with a master key (key encryption key or KEK). This approach allows for unique DEKs per data set/microservice while centralizing the protection of those DEKs with a more securely managed KEK, aligning with the described scenario.
Why the other options are wrong
- B. Asymmetric key encryption uses a public/private key pair for encryption and decryption, typically for secure communication or digital signatures, not for hierarchical data encryption keys.
- C. Symmetric key encryption uses a single key for both encryption and decryption, but doesn't inherently describe the hierarchical key protection model.
- D. Homomorphic encryption allows computations on encrypted data without decrypting it, which is not the primary goal described.
Envelope Encryption
A cryptographic method where data is encrypted with a data encryption key (DEK), and the DEK itself is then encrypted with a key encryption key (KEK).
- Separates data encryption from key encryption.
- Allows for frequent rotation of DEKs without re-encrypting all data.
- KEKs are typically managed by a secure service (e.g., KMS, HSM).
Memory trick: Envelope encryption is like putting your secret message in a small, sealed envelope, and then putting that envelope into a locked safe.