SSCP Systems Security Certified PractitionerCryptographyHard

A security consultant is explaining the concept of perfect forward secrecy (PFS) to a client. Which statement accurately describes how PFS enhances the security of encrypted communications?

  1. AIt ensures that a compromised session key cannot be used to decrypt future communications.
  2. BIt guarantees that past recorded communications remain confidential even if the long-term private key is later compromised.
  3. CIt ensures that all communications are encrypted with a unique, one-time pad.
  4. DIt prevents an attacker from forging digital signatures even if the private key is compromised.
Show answer & explanation

Correct answer: B. It guarantees that past recorded communications remain confidential even if the long-term private key is later compromised.

Perfect forward secrecy (PFS) ensures that if a long-term private key (e.g., a server's TLS private key) is compromised, it cannot be used to decrypt past recorded communications that were protected with ephemeral session keys. This is achieved by generating temporary, unique session keys for each communication session.

Why the other options are wrong

  • A. PFS protects *past* communications from future key compromise, not future communications from a *past* session key compromise.
  • C. While PFS uses ephemeral keys, it does not imply the use of a one-time pad, which is a specific type of encryption with different properties and practical limitations.
  • D. PFS is about confidentiality of communications, not the integrity or non-repudiation provided by digital signatures.

Perfect Forward Secrecy (PFS)

A property of key agreement protocols that ensures that a compromise of long-term private keys does not compromise past session keys.

  • Achieved through ephemeral Diffie-Hellman (DHE/ECDHE).
  • Protects confidentiality of historical data.
  • Important for TLS/SSL and other secure communication protocols.

Memory trick: PFS is like a time-lock safe; even if you get the master key later, old contents are still secure.

More Cryptography questions