SSCP Systems Security Certified PractitionerCryptographyMedium
A developer is implementing a secure communication channel and needs to choose a cipher suite for TLS. They prioritize forward secrecy, meaning that compromise of a long-term private key will not compromise past session keys. Which of the following key exchange mechanisms should be selected to achieve this?
- AEphemeral Diffie-Hellman (DHE)
- BPre-shared Key (PSK)
- CStatic Diffie-Hellman (DH)
- DRSA key exchange
Show answer & explanationAnswer & explanation
Correct answer: A. Ephemeral Diffie-Hellman (DHE)
Ephemeral Diffie-Hellman (DHE) or Elliptic Curve Diffie-Hellman Ephemeral (ECDHE) generate new, temporary key pairs for each session. This ensures that even if the server's long-term private key is compromised, past session keys remain secure, providing forward secrecy.
Why the other options are wrong
- B. Pre-shared Key (PSK) typically uses a single, long-term shared secret, which also does not provide forward secrecy.
- C. Static Diffie-Hellman (DH) uses fixed, long-term keys, which does not provide forward secrecy as compromise of these keys would compromise all sessions.
- D. RSA key exchange encrypts a symmetric session key with the server's long-term public key. If the server's private key is compromised, all past sessions encrypted with keys transported by that RSA key can be decrypted.
Forward Secrecy (Perfect Forward Secrecy - PFS)
A property of a key agreement protocol that ensures that a compromise of long-term secret keys does not compromise past session keys.
- Achieved by generating ephemeral (temporary) session keys.
- Commonly implemented with Ephemeral Diffie-Hellman (DHE or ECDHE).
- Crucial for protecting the confidentiality of past communications.
Memory trick: Ephemeral keys are like disposable locks: once used, they're gone, so past secrets stay safe.