SSCP Systems Security Certified PractitionerCryptographyEasy

A system administrator is configuring a secure tunnel using IPsec. During the Internet Key Exchange (IKE) phase, the administrator needs to ensure that the two endpoints can agree on a shared secret key over an insecure channel without actually transmitting the key itself. Which cryptographic algorithm facilitates this process?

  1. AAES
  2. BSHA-256
  3. CRSA
  4. DDiffie-Hellman
Show answer & explanation

Correct answer: D. Diffie-Hellman

The Diffie-Hellman key exchange algorithm allows two parties to establish a shared secret key over an insecure communication channel without revealing the key to eavesdroppers. This is a fundamental component of protocols like IKE for IPsec.

Why the other options are wrong

  • A. AES is a symmetric encryption algorithm used for data confidentiality, not for key exchange itself.
  • B. SHA-256 is a hashing algorithm used for data integrity, not for key exchange.
  • C. RSA is primarily used for digital signatures and asymmetric encryption, not for establishing a shared secret over an insecure channel without prior key distribution.

Diffie-Hellman Key Exchange

A cryptographic protocol that allows two parties to establish a shared secret key over an insecure communication channel without the key being transmitted directly.

  • Enables secure key establishment over public channels.
  • Does not transmit the actual shared secret.
  • Vulnerable to man-in-the-middle attacks without authentication.

Memory trick: DH for Shared Secrets.

More Cryptography questions