SSCP Systems Security Certified PractitionerCryptographyEasy
A system administrator is configuring a new web server to use HTTPS. During the setup, they are prompted to select a cipher suite that ensures a unique session key is generated for every new connection, even if the server's long-term private key is compromised in the future. Which property does this requirement describe?
- AKey Separation
- BPerfect Forward Secrecy (PFS)
- CKey Derivation
- DKey Escrow
Show answer & explanationAnswer & explanation
Correct answer: B. Perfect Forward Secrecy (PFS)
Perfect Forward Secrecy (PFS) ensures that a compromise of a server's long-term private key will not compromise past session keys. Each session key is independently generated and discarded after the session ends.
Why the other options are wrong
- A. Key separation refers to using different keys for different cryptographic purposes, which is not the primary focus here.
- C. Key derivation is the process of generating new keys from a master key or password, not specifically about protecting past sessions from future key compromise.
- D. Key escrow involves storing keys with a third party, which does not address the protection of past sessions if the server's key is compromised.
Perfect Forward Secrecy (PFS)
A property of key agreement protocols that ensures that if one of the long-term keys is compromised, it does not compromise any past session keys derived from it.
- Each session uses a unique, ephemeral session key.
- Session keys are not derived directly from a master secret that could be compromised later.
- Often implemented using Diffie-Hellman key exchange or elliptic curve Diffie-Hellman (ECDHE).
Memory trick: PFS protects 'past' secrets from 'future' key compromises.