CompTIA SecurityX (CAS-005)Security EngineeringMedium
A security architect is developing a strategy for long-term data archival that must maintain confidentiality and integrity for several decades. Given the rapid advancements in quantum computing, the architect is concerned about the future vulnerability of current cryptographic algorithms. Which area of cryptography should the architect prioritize for research and potential adoption to address this specific concern?
- ASymmetric Key Cryptography
- BHomomorphic Encryption
- CPost-Quantum Cryptography (PQC)
- DElliptic Curve Cryptography (ECC)
Show answer & explanationAnswer & explanation
Correct answer: C. Post-Quantum Cryptography (PQC)
Post-Quantum Cryptography (PQC) is specifically focused on developing and standardizing cryptographic algorithms that are resistant to attacks by large-scale quantum computers, making it the most relevant area for protecting long-term archives against future quantum threats.
Why the other options are wrong
- A. Symmetric key cryptography (e.g., AES) is generally considered less vulnerable to quantum attacks than asymmetric cryptography (like RSA or ECC), but the key sizes might need to be doubled, and it doesn't solve the public-key problem.
- B. Homomorphic encryption allows computation on encrypted data but does not primarily address quantum resistance.
- D. ECC is a current public-key cryptographic algorithm that is vulnerable to Shor's algorithm on a quantum computer.
Post-Quantum Cryptography (PQC)
Cryptographic algorithms that are believed to be secure against an attack by a quantum computer, as well as by classical computers, typically focusing on public-key algorithms.
- Aims to replace current vulnerable public-key crypto (RSA, ECC)
- Resistant to Shor's algorithm and Grover's algorithm
- Under active research and standardization (e.g., NIST PQC)
Memory trick: PQC Protects Against Quantum's Powerful Computation.