SSCP Systems Security Certified PractitionerCryptographyHard
A security engineer is implementing a cryptographic solution for protecting sensitive data at rest on a server. The requirement states that even if the server's memory is dumped, the encryption keys for the data should not be easily recoverable from the dump. Which of the following techniques would best address this requirement?
- AStoring keys in a configuration file encrypted with a master password.
- BEncrypting the keys with a second symmetric key stored in a database.
- CUsing a strong password-based key derivation function (PBKDF).
- DUsing a Hardware Security Module (HSM) to protect and manage keys.
Show answer & explanationAnswer & explanation
Correct answer: D. Using a Hardware Security Module (HSM) to protect and manage keys.
A Hardware Security Module (HSM) is specifically designed to securely store, manage, and perform cryptographic operations using keys, without ever exposing the keys themselves outside the tamper-resistant boundary of the device. This makes them highly resistant to memory dump attacks.
Why the other options are wrong
- A. Keys in a configuration file, even encrypted, can still be recovered if the master password or the decryption mechanism is found in memory.
- B. Storing keys in a database merely shifts the problem; the database's encryption key would still be vulnerable to memory dumps.
- C. PBKDFs are used to derive strong cryptographic keys from passwords but don't protect the derived key from being exposed once it's in active memory for use.
Hardware Security Module (HSM)
A physical computing device that safeguards and manages cryptographic keys and provides cryptoprocessing functions within a tamper-resistant environment.
- Provides secure storage for cryptographic keys.
- Performs crypto operations without exposing keys.
- Offers tamper detection and resistance.
Memory trick: HSM Hides the Key.