ISC2 CISSP (Certified Information Systems Security Professional)Security Architecture and EngineeringMedium

A manufacturing plant is integrating new Internet of Things (IoT) sensors into its operational technology (OT) network to monitor equipment performance. These sensors have limited processing power and memory. Which type of cryptographic key is generally preferred for securing communication between these resource-constrained devices and a central server, and why?

  1. AElliptic Curve Cryptography (ECC) keys, due to their legacy support and widespread hardware acceleration.
  2. BAsymmetric keys, due to their smaller key sizes and faster operations.
  3. CSymmetric keys, due to their computational efficiency and smaller key sizes for equivalent security strength.
  4. DHashing algorithms, as they provide confidentiality and integrity with minimal overhead.
Show answer & explanation

Correct answer: C. Symmetric keys, due to their computational efficiency and smaller key sizes for equivalent security strength.

Symmetric key cryptography is significantly more computationally efficient than asymmetric cryptography, requiring less processing power and memory for encryption and decryption. For resource-constrained IoT devices, this efficiency is critical, and symmetric keys offer strong security with smaller key sizes compared to asymmetric keys for the same security level.

Why the other options are wrong

  • A. While ECC is more efficient than RSA for asymmetric crypto, symmetric crypto is still generally more efficient overall, and legacy support isn't the primary driver here.
  • B. Asymmetric keys are computationally intensive and have larger key sizes for equivalent security, making them unsuitable for constrained devices.
  • D. Hashing provides integrity, but not confidentiality, which is often required for IoT communication, and it's not a 'key' type for encryption.

Symmetric Cryptography

A type of encryption where the same secret key is used for both encryption and decryption.

  • Faster and more efficient than asymmetric cryptography.
  • Requires secure key exchange out-of-band.
  • Commonly used for bulk data encryption.

Memory trick: Symmetric is Swift for Small Systems.

More Security Architecture and Engineering questions