Certified Cloud Security Professional (CCSP)Cloud Data SecurityMedium
A cloud customer is implementing a new data storage solution in a multi-tenant cloud environment. Due to strict regulatory requirements, they need to ensure that their sensitive data is cryptographically separated from other tenants' data and that the encryption keys are never exposed to the cloud provider. Which cryptographic solution best meets these requirements?
- AServer-side encryption with customer-provided keys (SSE-C)
- BClient-side encryption with customer-managed keys (CSEK)
- CTransparent Data Encryption (TDE)
- DServer-side encryption with platform-managed keys (SSE-PMK)
Show answer & explanationAnswer & explanation
Correct answer: B. Client-side encryption with customer-managed keys (CSEK)
Client-side encryption with customer-managed keys (CSEK) ensures that data is encrypted before it leaves the customer's control and that the encryption keys remain exclusively with the customer, addressing both cryptographic separation and key exposure concerns.
Why the other options are wrong
- A. SSE-C involves the customer providing keys to the cloud provider, which exposes the keys, violating a key requirement.
- C. TDE encrypts data at rest within a database but is typically managed by the cloud provider or database administrator, and keys can still be exposed to the provider.
- D. SSE-PMK means the cloud provider manages both encryption and keys, failing to meet the 'keys never exposed' requirement.
Client-Side Encryption with Customer-Managed Keys (CSEK)
A data encryption method where data is encrypted by the customer's system before being uploaded to the cloud, and the encryption keys are generated and retained exclusively by the customer.
- Data encrypted pre-upload.
- Customer retains full control of encryption keys.
- Cloud provider never sees unencrypted data or keys.
- Provides highest level of data confidentiality and key isolation.
Memory trick: Keys in hand, data secure, out of provider's view.