CompTIA SecurityX (CAS-005)Security EngineeringMedium

A security architect is designing a new cloud-native application that will process highly sensitive customer data. The application uses microservices, and each microservice requires its own unique encryption key for data at rest. To minimize the risk of key compromise and ensure high availability, the architect decides to encrypt each microservice's data key with a unique key encryption key (KEK), which is then encrypted by a master key stored in a Hardware Security Module (HSM). This layered approach to encryption is known as:

  1. AEnvelope Encryption
  2. BHomomorphic Encryption
  3. CQuantum Cryptography
  4. DSymmetric Block Chaining
Show answer & explanation

Correct answer: A. Envelope Encryption

Envelope encryption is a practice where a data key (used for encrypting the actual data) is itself encrypted by a key encryption key (KEK). This KEK can then be encrypted by another KEK, forming a hierarchy, often with the top-level key stored securely in an HSM.

Why the other options are wrong

  • B. Homomorphic encryption allows computations on encrypted data without decrypting it, which is not the scenario described.
  • C. Quantum cryptography deals with using quantum mechanical properties for cryptographic tasks, not a layered key management strategy.
  • D. Symmetric Block Chaining (e.g., CBC) is a mode of operation for block ciphers, not a key management strategy.

Envelope Encryption

A method of encrypting data where a data encryption key (DEK) is used to encrypt the data, and then the DEK itself is encrypted by a key encryption key (KEK).

  • Creates a hierarchy of keys
  • Often uses an HSM for the master KEK
  • Improves scalability and security of key management

Memory trick: Envelopes Wrap Keys, HSMs Hold the Master.

More Security Engineering questions