SSCP Systems Security Certified PractitionerCryptographyMedium
A system architect is designing a secure data storage solution for highly sensitive government data. They require a cryptographic algorithm that has been rigorously tested, published, and widely adopted by both government and industry for its strong security properties. Which algorithm would be the most appropriate choice for encrypting the data at rest?
- ABlowfish
- BRC4
- CAdvanced Encryption Standard (AES)
- DTriple DES (3DES)
Show answer & explanationAnswer & explanation
Correct answer: C. Advanced Encryption Standard (AES)
AES (Advanced Encryption Standard) is the current standard for symmetric-key encryption, adopted by the U.S. government and widely used globally. It has undergone extensive public scrutiny and is considered highly secure and efficient, making it the most appropriate choice for sensitive data at rest.
Why the other options are wrong
- A. Blowfish is a strong algorithm but less widely standardized and adopted than AES, and has a smaller block size.
- B. RC4 is a stream cipher known to have significant cryptographic weaknesses and should not be used for new applications.
- D. 3DES is still considered secure but is much slower than AES and has a smaller block size, making it less efficient and nearing end-of-life.
Advanced Encryption Standard (AES)
A symmetric block cipher chosen by NIST to replace DES. It supports key sizes of 128, 192, and 256 bits, with a fixed block size of 128 bits. It is widely adopted and considered highly secure.
- Symmetric block cipher, 128-bit block size.
- Key sizes: 128, 192, 256 bits.
- NIST standard, widely adopted globally.
Memory trick: For government-level security, think of the 'Advanced' standard.