SSCP Systems Security Certified PractitionerCryptographyHard

A forensic investigator is examining encrypted files found on a suspect's computer. The files appear to be encrypted using a symmetric key, and the investigator knows that the suspect used a passphrase to protect this key. To gain access to the files, the investigator needs to determine the symmetric key. Which cryptographic technique is MOST relevant to breaking the passphrase protection and recovering the key?

  1. ARainbow table attack on the encrypted files
  2. BKey Derivation Function (KDF) brute-force attack
  3. CSide-channel attack on the encryption algorithm
  4. DCollision attack on the symmetric cipher
Show answer & explanation

Correct answer: B. Key Derivation Function (KDF) brute-force attack

If a passphrase protects the symmetric key, it's highly probable that a Key Derivation Function (KDF) was used to derive the key from the passphrase. A brute-force attack on the KDF attempts to guess the passphrase and re-derive the key until the correct one is found, allowing decryption.

Why the other options are wrong

  • A. Rainbow table attacks are used against password hashes, typically when a salt is not used or is known, not directly on encrypted files to recover an encryption key.
  • C. Side-channel attacks exploit physical emissions (power consumption, timing) during cryptographic operations, which is unlikely to be applicable to recovering a key from a static encrypted file.
  • D. Collision attacks target hash functions, not symmetric ciphers, and are used to find two different inputs that produce the same output, not to recover a key.

Key Derivation Function (KDF) Attack

An attack against a Key Derivation Function, typically a brute-force or dictionary attack, aimed at recovering the original low-entropy secret (like a password or passphrase) used to derive a high-entropy cryptographic key.

  • Exploits the fact that the derived key is directly dependent on the input passphrase.
  • KDFs like PBKDF2, bcrypt, and scrypt are designed to be computationally expensive to slow down such attacks.
  • The strength of the KDF against brute-force depends on its iteration count and memory hardness.

Memory trick: Key Attacks: Guess the password, not the cipher!

More Cryptography questions