SSCP Systems Security Certified PractitionerCryptographyMedium

A developer is implementing a secure communication channel and needs to choose a cipher suite for TLS. They prioritize forward secrecy, meaning that compromise of a long-term private key will not compromise past session keys. Which of the following key exchange mechanisms should be selected to achieve this?

  1. AEphemeral Diffie-Hellman (DHE)
  2. BPre-shared Key (PSK)
  3. CStatic Diffie-Hellman (DH)
  4. DRSA key exchange
Show answer & explanation

Correct answer: A. Ephemeral Diffie-Hellman (DHE)

Ephemeral Diffie-Hellman (DHE) or Elliptic Curve Diffie-Hellman Ephemeral (ECDHE) generate new, temporary key pairs for each session. This ensures that even if the server's long-term private key is compromised, past session keys remain secure, providing forward secrecy.

Why the other options are wrong

  • B. Pre-shared Key (PSK) typically uses a single, long-term shared secret, which also does not provide forward secrecy.
  • C. Static Diffie-Hellman (DH) uses fixed, long-term keys, which does not provide forward secrecy as compromise of these keys would compromise all sessions.
  • D. RSA key exchange encrypts a symmetric session key with the server's long-term public key. If the server's private key is compromised, all past sessions encrypted with keys transported by that RSA key can be decrypted.

Forward Secrecy (Perfect Forward Secrecy - PFS)

A property of a key agreement protocol that ensures that a compromise of long-term secret keys does not compromise past session keys.

  • Achieved by generating ephemeral (temporary) session keys.
  • Commonly implemented with Ephemeral Diffie-Hellman (DHE or ECDHE).
  • Crucial for protecting the confidentiality of past communications.

Memory trick: Ephemeral keys are like disposable locks: once used, they're gone, so past secrets stay safe.

More Cryptography questions