SSCP Systems Security Certified PractitionerCryptographyMedium
A security engineer is evaluating different cryptographic algorithms for securing data in transit across a high-speed network. The primary concern is maintaining confidentiality and integrity with minimal latency. Which of the following cryptographic primitives, when correctly implemented, offers both confidentiality and integrity in a single operation?
- ARSA
- BAES-GCM
- CAES-CBC
- DSHA-256
Show answer & explanationAnswer & explanation
Correct answer: B. AES-GCM
AES-GCM (Galois/Counter Mode) is an authenticated encryption mode. It provides both confidentiality (encryption) and authenticity/integrity (via a Message Authentication Code or MAC) in a single, efficient operation, making it ideal for high-speed network communication.
Why the other options are wrong
- A. RSA is an asymmetric algorithm primarily used for key exchange and digital signatures, not for bulk data confidentiality and integrity in a single operation.
- C. AES-CBC provides confidentiality but not integrity directly. It would require a separate MAC for integrity.
- D. SHA-256 is a hashing algorithm providing integrity (and non-repudiation with signatures) but no confidentiality.
Authenticated Encryption (AEAD)
A type of encryption that simultaneously provides confidentiality, integrity, and authenticity for data. If any part of the ciphertext or associated authenticated data is modified, decryption and verification will fail.
- Combines encryption with a Message Authentication Code (MAC).
- Protects against tampering, decryption, and replay attacks.
- Examples include AES-GCM and ChaCha20-Poly1305.
Memory trick: Crypto Primitives: Confidentiality, Integrity, Authentication, Non-repudiation!