Professional Cloud ArchitectDesign for security and complianceHard

A global pharmaceutical company is building a research data platform on Google Cloud. The platform will store highly sensitive clinical trial data, which must be protected against unauthorized access and modification, ensuring data integrity and non-repudiation. They need to verify the authenticity and integrity of data and logs, especially for audit purposes. Which cryptographic technique, supported by Google Cloud services, is crucial for achieving data integrity and non-repudiation for audit logs and critical data files?

  1. ASymmetric encryption
  2. BHashing with digital signatures
  3. CTokenization
  4. DObfuscation
Show answer & explanation

Correct answer: B. Hashing with digital signatures

Hashing generates a unique fixed-size string for data, ensuring integrity (any change alters the hash). Digital signatures, using asymmetric cryptography, then sign this hash, providing authenticity and non-repudiation, which is crucial for audit logs.

Why the other options are wrong

  • A. Symmetric encryption protects confidentiality but does not inherently guarantee integrity or non-repudiation.
  • C. Tokenization replaces sensitive data with non-sensitive substitutes, primarily for privacy and reducing scope of PCI DSS, not for integrity/non-repudiation.
  • D. Obfuscation makes data harder to understand but doesn't provide cryptographic guarantees of integrity or non-repudiation.

Hashing and Digital Signatures

Hashing creates a unique fingerprint of data for integrity, while digital signatures use asymmetric cryptography to cryptographically bind an identity to data, providing authenticity and non-repudiation.

  • Hashing detects any unauthorized data modification.
  • Digital signatures prove the sender's identity and that the message hasn't been tampered with.
  • Used for audit logs, software distribution, and secure communication.

Memory trick: CIA: Confidentiality, Integrity, Availability. Non-Repudiation too!

More Design for security and compliance questions