ISC2 CISSP (Certified Information Systems Security Professional)Security Architecture and EngineeringMedium
A team is designing a new microservices architecture. They need a mechanism to ensure that each service can cryptographically verify the origin and integrity of messages received from other services within the architecture. Which cryptographic primitive is best suited for this purpose, assuming confidentiality is handled separately?
- AKey Derivation Functions (KDFs)
- BDigital Signatures
- CHashing with a Salt
- DSymmetric Key Encryption
Show answer & explanationAnswer & explanation
Correct answer: B. Digital Signatures
Digital signatures are specifically designed to provide assurance of origin (authentication) and integrity of a message. The sender signs the message with their private key, and the receiver verifies the signature using the sender's public key, ensuring the message came from the claimed sender and hasn't been tampered with.
Why the other options are wrong
- A. KDFs are used to derive cryptographic keys from a master key or password, not for message origin/integrity verification.
- C. Hashing with a salt is used for password storage or integrity checks, but it doesn't provide sender authentication or non-repudiation.
- D. Symmetric key encryption provides confidentiality, but not non-repudiation or verifiable origin without additional mechanisms.
Digital Signatures
A mathematical scheme for demonstrating the authenticity of digital messages or documents.
- Provides integrity (message not altered).
- Provides authenticity (verifies sender's identity).
- Provides non-repudiation (sender cannot deny sending).
- Uses asymmetric cryptography (sender's private key for signing, public key for verification).
Memory trick: Signatures Confirm Sender's Sincerity.