CompTIA SecurityX (CAS-005)Security EngineeringMedium
A security architect is designing a long-term data archival system that must remain secure against future advances in cryptanalysis, including the potential advent of quantum computers. The data being archived is highly sensitive and requires confidentiality for several decades. Which of the following cryptographic approaches should the architect prioritize for key exchange and encryption to meet this requirement?
- APost-Quantum Cryptography (PQC)
- BRSA with 4096-bit keys
- CAdvanced Encryption Standard (AES-256)
- DElliptic Curve Cryptography (ECC)
Show answer & explanationAnswer & explanation
Correct answer: A. Post-Quantum Cryptography (PQC)
Post-Quantum Cryptography (PQC) refers to cryptographic algorithms that are designed to be secure against attacks by quantum computers. Given the long-term confidentiality requirement and the threat of quantum computing, PQC is the only option specifically addressing this future-proofing need for key exchange and encryption.
Why the other options are wrong
- B. RSA, even with very large key sizes like 4096-bit, is also vulnerable to Shor's algorithm on a sufficiently powerful quantum computer.
- C. AES-256 is a symmetric encryption algorithm that is considered quantum-resistant for data encryption (not key exchange) if the key size is large enough (e.g., 256-bit), but the question asks about key exchange and encryption, and PQC encompasses both aspects for quantum resistance.
- D. ECC is a current public-key cryptography standard, but it is vulnerable to Shor's algorithm on a sufficiently powerful quantum computer.
Post-Quantum Cryptography (PQC)
Cryptographic algorithms designed to be secure against cryptanalytic attacks by both classical and quantum computers, addressing the threat of future quantum capabilities.
- Resistant to Shor's and Grover's quantum algorithms
- Focuses on public-key algorithms for key exchange and digital signatures
- NIST is standardizing several PQC algorithms
Memory trick: PQC: Protects Quantum Computing.