ISC2 CISSP (Certified Information Systems Security Professional)Security Architecture and EngineeringHard
A developer is creating a mobile application that processes payment information. The application needs to securely store cryptographic keys on the device to perform encryption and decryption operations. Which security capability of mobile systems is specifically designed to provide a hardware-backed, isolated environment for storing such sensitive data?
- ASecure Enclave/Element
- BApplication Sandbox
- CVPN Client
- DFull Disk Encryption (FDE)
Show answer & explanationAnswer & explanation
Correct answer: A. Secure Enclave/Element
A Secure Enclave (Apple) or Secure Element (Android, general) is a dedicated, isolated hardware subsystem within a mobile device designed to store cryptographic keys and perform sensitive operations in an environment protected from the main operating system and applications. This provides a higher level of assurance for key protection than software-only solutions.
Why the other options are wrong
- B. Application sandboxing isolates applications from each other but doesn't provide hardware-level protection for cryptographic keys.
- C. A VPN client secures network communication but is unrelated to hardware-backed key storage on the device itself.
- D. Full Disk Encryption protects data at rest but doesn't offer specific hardware isolation for cryptographic keys used by applications.
Secure Enclave/Element
A dedicated, isolated hardware subsystem within a mobile device or SoC (System on a Chip) for processing sensitive data and cryptographic keys.
- Provides a hardware root of trust, isolated from the main processor and OS.
- Used for biometric authentication, payment processing, and cryptographic key management.
- Protects sensitive operations even if the main OS is compromised.
Memory trick: For mobile keys, the Enclave is the unbreachable vault.