SSCP Systems Security Certified PractitionerCryptographyEasy
A system administrator is configuring a secure tunnel using IPsec. During the Internet Key Exchange (IKE) phase, the administrator needs to ensure that the two endpoints can agree on a shared secret key over an insecure channel without actually transmitting the key itself. Which cryptographic algorithm facilitates this process?
- AAES
- BSHA-256
- CRSA
- DDiffie-Hellman
Show answer & explanationAnswer & explanation
Correct answer: D. Diffie-Hellman
The Diffie-Hellman key exchange algorithm allows two parties to establish a shared secret key over an insecure communication channel without revealing the key to eavesdroppers. This is a fundamental component of protocols like IKE for IPsec.
Why the other options are wrong
- A. AES is a symmetric encryption algorithm used for data confidentiality, not for key exchange itself.
- B. SHA-256 is a hashing algorithm used for data integrity, not for key exchange.
- C. RSA is primarily used for digital signatures and asymmetric encryption, not for establishing a shared secret over an insecure channel without prior key distribution.
Diffie-Hellman Key Exchange
A cryptographic protocol that allows two parties to establish a shared secret key over an insecure communication channel without the key being transmitted directly.
- Enables secure key establishment over public channels.
- Does not transmit the actual shared secret.
- Vulnerable to man-in-the-middle attacks without authentication.
Memory trick: DH for Shared Secrets.