SSCP Systems Security Certified PractitionerCryptographyMedium
A security architect is designing a system for storing highly sensitive government documents. The requirement explicitly states that the encryption method must be resistant to all known forms of cryptanalysis, including attacks from quantum computers, for the foreseeable future. Which cryptographic concept is most relevant to this requirement?
- AHomomorphic Encryption
- BKey Escrow
- CPost-Quantum Cryptography (PQC)
- DQuantum Key Distribution (QKD)
Show answer & explanationAnswer & explanation
Correct answer: C. Post-Quantum Cryptography (PQC)
Post-Quantum Cryptography (PQC) refers to cryptographic algorithms that are believed to be secure against attacks by quantum computers, as well as classical computers. It's the field focused on developing encryption methods resilient to future quantum threats.
Why the other options are wrong
- A. Homomorphic encryption allows computations on encrypted data without decrypting it, distinct from quantum resistance.
- B. Key escrow involves storing keys with a third party, which is not about quantum resistance.
- D. Quantum Key Distribution (QKD) is a method for securely exchanging keys using quantum mechanics, not for encrypting data itself in a quantum-resistant manner.
Post-Quantum Cryptography (PQC)
Cryptographic algorithms that are secure against an attack by a quantum computer. This field is concerned with developing new cryptographic systems that can withstand quantum attacks while still being implementable on classical computers.
- Aims to replace current public-key algorithms vulnerable to quantum computers.
- Examples include lattice-based, code-based, hash-based, and multivariate polynomial cryptography.
- Does not require quantum hardware to implement.
Memory trick: PQC protects against the future quantum threat.