Professional Cloud ArchitectDesign for security and complianceMedium
A global media company uses Google Cloud Storage to host vast amounts of video content, images, and other media files. They need to ensure the integrity of these files against tampering and detect any unauthorized modifications. They also need to provide a non-repudiable proof of the file's origin. Which cryptographic technique should be used to meet these requirements?
- AAsymmetric Encryption
- BTokenization
- CHashing and Digital Signatures
- DSymmetric Encryption
Show answer & explanationAnswer & explanation
Correct answer: C. Hashing and Digital Signatures
Hashing generates a unique fixed-size output (hash) for a file, allowing detection of tampering if the hash changes. Digital signatures, created using a private key and verified with a public key, provide non-repudiation and confirm the sender's identity. Symmetric and asymmetric encryption are for confidentiality, not primarily integrity or non-repudiation. Tokenization replaces sensitive data with non-sensitive tokens.
Why the other options are wrong
- A. Asymmetric encryption uses a public/private key pair, primarily for confidentiality (secure communication) or digital signatures, but encryption itself doesn't guarantee integrity or non-repudiation without hashing and signing.
- B. Tokenization replaces sensitive data with a non-sensitive equivalent (token) to reduce risk, but it does not provide integrity checking or non-repudiation for file content.
- D. Symmetric encryption uses a single key for both encryption and decryption, primarily providing confidentiality, not integrity or non-repudiation.
Hashing and Digital Signatures
Cryptographic techniques used together to ensure data integrity (hashing) and authenticate the sender while providing non-repudiation (digital signatures).
- Hashing detects tampering by creating a unique digest.
- Digital signatures use asymmetric cryptography for authenticity and non-repudiation.
- Often used for software updates, documents, and content integrity.
Memory trick: Hash for Integrity, Sign for Proven Origin, No Deny.