Certified Cloud Security Professional (CCSP)Cloud Data SecurityMedium
A software-as-a-service (SaaS) provider offers an application that stores customer data in a multi-tenant cloud database. Each customer's data must be logically separated and encrypted with a unique set of keys. The provider wants to ensure that a compromise of one customer's encryption key does not affect the confidentiality of another customer's data. Which key management principle is the provider primarily aiming to enforce?
- AKey Archiving
- BKey Separation
- CKey Escrow
- DKey Rotation
Show answer & explanationAnswer & explanation
Correct answer: B. Key Separation
Key separation is the principle that different keys should be used for different purposes, or in this case, for different tenants or data sets, to limit the impact of a key compromise. This ensures that a breach of one key does not compromise all data.
Why the other options are wrong
- A. Key archiving involves securely storing old keys, typically for decrypting historical data, and doesn't address the current problem of isolation between tenants.
- C. Key escrow involves storing a copy of encryption keys with a third party, primarily for recovery or legal access, not for preventing cross-tenant compromise.
- D. Key rotation involves periodically changing keys but doesn't inherently prevent a single compromise from affecting multiple data sets if the same key was used.
Key Separation
A cryptographic key management principle stating that different keys should be used for different purposes (e.g., encryption, signing) or for different data sets/tenants. This limits the impact of a single key compromise.
- Unique keys for different purposes or data.
- Limits impact of a key compromise.
- Crucial for multi-tenant environments.
Memory trick: Separate Keys, Secure Silos.