SSCP Systems Security Certified PractitionerCryptographyMedium
A system administrator is tasked with securing communication between two web servers over an untrusted network. They decide to use Transport Layer Security (TLS) with a cipher suite that includes an elliptic curve algorithm for key exchange and AES-256 for symmetric encryption. Which component of the TLS handshake process is primarily responsible for establishing a shared secret key for the symmetric encryption?
- AClientHello message
- BKey Exchange Algorithm
- CServer Certificate
- DApplication Data
Show answer & explanationAnswer & explanation
Correct answer: B. Key Exchange Algorithm
The Key Exchange Algorithm, such as Ephemeral Diffie-Hellman (DHE) or Elliptic Curve Diffie-Hellman Ephemeral (ECDHE), is specifically designed to allow the client and server to securely agree upon a shared symmetric key during the TLS handshake, even over an insecure channel.
Why the other options are wrong
- A. The ClientHello message initiates the handshake and specifies supported cipher suites, but doesn't establish the key itself.
- C. The Server Certificate is used for server authentication, not direct shared secret key establishment.
- D. Application Data is the encrypted data exchanged after the TLS handshake is complete, not part of key establishment.
TLS Key Exchange
A critical phase in the TLS handshake where the client and server securely establish a shared symmetric encryption key for subsequent data transmission.
- Uses asymmetric cryptography (e.g., RSA, Diffie-Hellman) to establish a symmetric key.
- Ensures that eavesdroppers cannot determine the symmetric key.
- Modern implementations prioritize Perfect Forward Secrecy (PFS) using ephemeral keys.
Memory trick: TLS Handshake: Hello, Cert, Key, Change!