EC-Council Certified Ethical Hacker (CEH) v12CryptographyHard
A security architect is designing a system for a highly sensitive government agency that transmits classified data over an untrusted network. They require a cryptographic solution that not only provides confidentiality but also guarantees data integrity and authenticity through a single, efficient cryptographic primitive. Which of the following best fits this requirement?
- ARSA encryption with an MD5 hash for integrity.
- BChaCha20-Poly1305 authenticated encryption.
- CDiffie-Hellman key exchange followed by RC4 stream cipher.
- DAES-256 in CBC mode with a separate HMAC-SHA256.
Show answer & explanationAnswer & explanation
Correct answer: B. ChaCha20-Poly1305 authenticated encryption.
Authenticated encryption (AEAD) modes like ChaCha20-Poly1305 (or AES-GCM) are specifically designed to provide confidentiality, integrity, and authenticity in a single, efficient pass. ChaCha20 is a stream cipher for confidentiality, and Poly1305 is a MAC for authenticity and integrity. This combined approach is highly recommended for modern secure communications.
Why the other options are wrong
- A. RSA is typically for key exchange or small data; MD5 is cryptographically broken and should not be used for integrity.
- C. Diffie-Hellman is for key exchange, and RC4 is a deprecated, insecure stream cipher with known vulnerabilities.
- D. While AES-CBC + HMAC provides the desired properties, it involves two separate cryptographic primitives and potentially two passes, making it less 'single, efficient' than AEAD.
Authenticated Encryption (AEAD)
Authenticated Encryption with Associated Data (AEAD) is a type of encryption that simultaneously provides confidentiality, integrity, and authenticity for cryptographic data. Examples include AES-GCM and ChaCha20-Poly1305.
- Combines encryption and message authentication.
- Provides confidentiality, integrity, authenticity.
- Protects against tampering and unauthorized disclosure.
- Often more efficient than separate encryption and MAC.
Memory trick: AEAD bundles all three: confidential, authentic, integral.