Certified Cloud Security Professional (CCSP)Cloud Concepts, Architecture and DesignHard
A security architect is evaluating a cloud provider's offerings for storing highly sensitive customer data. The architect is concerned about the potential for unauthorized access by cloud provider employees. Which security concept directly addresses this concern by ensuring that no single entity, including the cloud provider, has complete access to the data?
- AHomomorphic Encryption
- BData Loss Prevention (DLP)
- CSeparation of Duties (SoD)
- DMulti-party Computation (MPC)
Show answer & explanationAnswer & explanation
Correct answer: D. Multi-party Computation (MPC)
Multi-party Computation (MPC) allows multiple parties to jointly compute a function over their private inputs without revealing those inputs to each other. This directly prevents any single entity, including the cloud provider, from having complete access to the sensitive data while still enabling computations.
Why the other options are wrong
- A. Homomorphic Encryption allows computations on encrypted data but is typically applied by the data owner, not necessarily involving multiple parties to prevent provider access.
- B. DLP prevents data exfiltration, but doesn't inherently restrict provider access to data at rest.
- C. Separation of Duties distributes tasks to prevent fraud or error by a single individual, but doesn't inherently prevent a cloud provider from accessing data it hosts.
Multi-party Computation (MPC)
A cryptographic technique that allows multiple parties to jointly compute a function over their private inputs while keeping those inputs secret from each other.
- Ensures data privacy even when processed by untrusted entities.
- Prevents any single party from gaining full knowledge of the data.
- Useful for collaborative analysis of sensitive data without revealing individual contributions.
Memory trick: MPC is like a secret ballot election: everyone contributes their vote, but no one sees individual choices.