ISC2 CISSP (Certified Information Systems Security Professional)Security Architecture and EngineeringHard
A cryptocurrency exchange platform is implementing a new system to manage user wallets and transaction keys. Due to the high value and sensitivity of these assets, the platform requires a solution that generates, stores, and manages cryptographic keys in a hardened, tamper-resistant hardware device. Which security architecture element is best suited for this purpose?
- ASoftware-based Key Management System (KMS)
- BIntrusion Prevention System (IPS)
- CVirtual Machine Monitor (VMM)
- DHardware Security Module (HSM)
Show answer & explanationAnswer & explanation
Correct answer: D. Hardware Security Module (HSM)
A Hardware Security Module (HSM) is a physical computing device that safeguards and manages digital keys, performs encryption and decryption functions, and provides a hardware root of trust. Its tamper-resistant design makes it ideal for securing high-value cryptographic keys like those used in cryptocurrency exchanges.
Why the other options are wrong
- A. Software-based KMS lacks the tamper-resistance and hardware-backed security of an HSM.
- B. An IPS detects and prevents network intrusions, unrelated to secure key management.
- C. A VMM (hypervisor) manages virtual machines but doesn't provide hardened key management.
Hardware Security Module (HSM)
A physical computing device that safeguards and manages digital keys, performs encryption and decryption functions, and provides a hardware root of trust.
- Offers a high level of security due to its tamper-resistant and tamper-evident design.
- Used for protecting cryptographic keys, digital signatures, and certificate authorities.
- Complies with industry standards like FIPS 140-2 for cryptographic modules.
Memory trick: HSM: The 'H'ardened 'S'ecurity 'M'achine for your most 'M'portant keys.