SSCP Systems Security Certified PractitionerCryptographyHard
A system architect is designing a secure communication protocol between a client application and a server. The architect wants to ensure that the protocol provides both confidentiality and data integrity, as well as authentication of the sender. Which type of cryptographic primitive combines these three security services efficiently?
- AAuthenticated Encryption with Associated Data (AEAD)
- BAsymmetric encryption for all data
- CDigital signatures without encryption
- DSeparate encryption and hashing functions
Show answer & explanationAnswer & explanation
Correct answer: A. Authenticated Encryption with Associated Data (AEAD)
Authenticated Encryption with Associated Data (AEAD) modes of operation are specifically designed to provide confidentiality (encryption), integrity (authenticity), and often implicit authenticity of the sender (via shared key for MAC). They combine encryption and MAC into a single, secure primitive, preventing common 'encrypt-then-MAC' or 'MAC-then-encrypt' pitfalls.
Why the other options are wrong
- B. Asymmetric encryption is computationally expensive and unsuitable for encrypting large amounts of data, making it inefficient for general communication.
- C. Digital signatures provide integrity and non-repudiation/authentication but do not provide confidentiality (encryption) for the data itself.
- D. While possible, combining separate encryption and hashing functions (e.g., encrypt-then-MAC) can be error-prone and less efficient than a dedicated AEAD mode.
Authenticated Encryption with Associated Data (AEAD)
A type of encryption that simultaneously provides confidentiality, integrity, and authenticity for encrypted data, and integrity/authenticity for associated unencrypted data.
- Combines encryption and message authentication.
- Prevents common cryptographic implementation errors.
- Examples include GCM, CCM, EAX modes.
Memory trick: AEAD All-in-One Security.