SSCP Systems Security Certified PractitionerCryptographyMedium
A security architect is designing a system for secure communication between microservices within a cloud environment. The architect wants to ensure that even if a long-term private key is compromised, past communication sessions cannot be decrypted. Which cryptographic property is essential for achieving this goal?
- APerfect Forward Secrecy (PFS)
- BHigh key entropy
- CStrong collision resistance
- DNon-repudiation
Show answer & explanationAnswer & explanation
Correct answer: A. Perfect Forward Secrecy (PFS)
Perfect Forward Secrecy (PFS) ensures that if a long-term private key used to establish a session key is compromised, it does not compromise the confidentiality of past session keys. This is achieved by generating ephemeral (short-lived) session keys unique to each session.
Why the other options are wrong
- B. High key entropy ensures the key is difficult to guess but doesn't prevent compromise of past sessions if the long-term key is leaked.
- C. Strong collision resistance is a property of hash functions, unrelated to the confidentiality of past communication sessions.
- D. Non-repudiation ensures that a party cannot deny having performed an action, which is distinct from protecting past session confidentiality.
Perfect Forward Secrecy (PFS)
A property of a key-agreement protocol that ensures that a session key derived from a set of long-term keys will not be compromised even if one of the long-term keys is compromised in the future.
- Protects past session confidentiality.
- Uses ephemeral (short-lived) session keys.
- Typically achieved with Diffie-Hellman or elliptic curve Diffie-Hellman.
Memory trick: PFS Protects Past Secrets.