Certified Cloud Security Professional (CCSP)Cloud Data SecurityHard
A cloud architect is designing a solution for a highly sensitive research dataset that needs to be processed by a third-party analytics service. The research data contains personally identifiable information (PII) that cannot be exposed to the third party, even during processing. The architect needs a method that allows computations to be performed directly on the encrypted data without decrypting it first. Which cryptographic solution should the architect recommend?
- AHomomorphic Encryption
- BAsymmetric Encryption
- CSymmetric Encryption
- DHashing
Show answer & explanationAnswer & explanation
Correct answer: A. Homomorphic Encryption
Homomorphic encryption is a unique cryptographic technique that allows computations to be performed on encrypted data without prior decryption. This means the third-party analytics service can process the sensitive data without ever seeing it in plain text, addressing the strict privacy requirement.
Why the other options are wrong
- B. Asymmetric encryption is used for secure key exchange or digital signatures, not for performing computations on encrypted data.
- C. Symmetric encryption requires decryption before processing, exposing the PII to the third party.
- D. Hashing provides data integrity and is one-way, meaning it cannot be decrypted for processing, and computations cannot be performed on hashed data to derive meaningful results.
Homomorphic Encryption
A form of encryption that allows computations to be performed on ciphertext, generating an encrypted result which, when decrypted, matches the result of operations performed on the plaintext. This enables privacy-preserving computation.
- Computations on encrypted data.
- Result is also encrypted.
- Decrypted result matches plaintext operation.
Memory trick: Homo-Magic: Compute on Encrypted, Secret Stays Secure.