SSCP Systems Security Certified PractitionerCryptographyEasy

A system administrator is configuring a new web server to use HTTPS. During the setup, they are prompted to select a cipher suite that ensures a unique session key is generated for every new connection, even if the server's long-term private key is compromised in the future. Which property does this requirement describe?

  1. AKey Separation
  2. BPerfect Forward Secrecy (PFS)
  3. CKey Derivation
  4. DKey Escrow
Show answer & explanation

Correct answer: B. Perfect Forward Secrecy (PFS)

Perfect Forward Secrecy (PFS) ensures that a compromise of a server's long-term private key will not compromise past session keys. Each session key is independently generated and discarded after the session ends.

Why the other options are wrong

  • A. Key separation refers to using different keys for different cryptographic purposes, which is not the primary focus here.
  • C. Key derivation is the process of generating new keys from a master key or password, not specifically about protecting past sessions from future key compromise.
  • D. Key escrow involves storing keys with a third party, which does not address the protection of past sessions if the server's key is compromised.

Perfect Forward Secrecy (PFS)

A property of key agreement protocols that ensures that if one of the long-term keys is compromised, it does not compromise any past session keys derived from it.

  • Each session uses a unique, ephemeral session key.
  • Session keys are not derived directly from a master secret that could be compromised later.
  • Often implemented using Diffie-Hellman key exchange or elliptic curve Diffie-Hellman (ECDHE).

Memory trick: PFS protects 'past' secrets from 'future' key compromises.

More Cryptography questions