CompTIA SecurityX (CAS-005)Security ArchitectureHard

A security architect is designing a system that processes highly sensitive personal health information (PHI). The system must be able to perform analytics and machine learning on this data without ever decrypting it, even during processing. This is necessary to comply with stringent privacy regulations. Which advanced cryptographic technique would enable this capability?

  1. ASymmetric Encryption
  2. BAsymmetric Encryption
  3. CHomomorphic Encryption
  4. DHashing
Show answer & explanation

Correct answer: C. Homomorphic Encryption

Homomorphic encryption allows computations to be performed on encrypted data without decrypting it first. The results of these computations remain encrypted and, when decrypted, are the same as if the operations had been performed on the unencrypted data. This directly addresses the requirement to process sensitive data without decryption.

Why the other options are wrong

  • A. Symmetric encryption requires data to be decrypted before processing, which violates the 'without ever decrypting it' requirement.
  • B. Asymmetric encryption is used for secure key exchange and digital signatures, not for computing on encrypted data.
  • D. Hashing creates a one-way function for data integrity verification, not for encryption or processing of sensitive data.

Homomorphic Encryption (HE)

An advanced cryptographic method that allows computations on encrypted data, producing an encrypted result which, when decrypted, matches the result of operations performed on the unencrypted data.

  • Enables privacy-preserving computations on sensitive data.
  • Comes in partially, somewhat, and fully homomorphic forms.
  • Computationally intensive, but actively researched for practical applications.

Memory trick: Homo-morph-ic: Same shape, different state, compute while encrypted.

More Security Architecture questions