Professional Cloud ArchitectDesign for security and complianceMedium
A global media company uses Google Cloud Storage to host vast amounts of video content, images, and documents. They need to ensure the integrity and authenticity of this media content, verifying that it has not been tampered with since its original upload. They also need to allow third-party partners to verify the origin and integrity of specific files without direct access to the storage bucket. Which cryptographic technique should be implemented?
- ASymmetric encryption with AES-256
- BTokenization
- CHashing and digital signatures
- DAsymmetric encryption with RSA
Show answer & explanationAnswer & explanation
Correct answer: C. Hashing and digital signatures
Hashing provides data integrity by generating a unique fixed-size string (hash) for the content, which changes if the content is altered. Digital signatures, created using asymmetric cryptography, then verify the authenticity of the hash and thus the origin of the content. This combination allows third parties to verify integrity and authenticity without direct data access.
Why the other options are wrong
- A. Symmetric encryption ensures confidentiality, not integrity or authenticity, and cannot be verified by third parties without sharing the key.
- B. Tokenization replaces sensitive data with non-sensitive substitutes (tokens), primarily for data protection, not for verifying content integrity and authenticity.
- D. Asymmetric encryption provides confidentiality and can be used for digital signatures, but without hashing, verifying the integrity of large files is inefficient. It's only part of the solution.
Hashing and Digital Signatures
Hashing creates a unique fingerprint of data for integrity, and digital signatures use asymmetric cryptography to verify the origin and authenticity of that hash.
- Hashing ensures data integrity (detects tampering).
- Digital signatures provide authenticity and non-repudiation.
- Allows verification without revealing sensitive content.
Memory trick: Hash it to check it, sign it to prove it's from you.