3.6 Cryptographic Solutions & PKI

CISSP Domain 3 ยท Security Architecture and Engineering

3.6 Cryptographic Solutions & PKI

Cryptography protects information by applying mathematical techniques to confidentiality, integrity, authentication and related security requirements.

For CISSP, the important skill is not simply recognising algorithm names. You need to understand which cryptographic mechanism solves which problem, how keys are managed and how trust is established through systems such as Public Key Infrastructure.

๐Ÿ”’

Encrypt

Protect information against unauthorised disclosure.

CONFIDENTIALITY
#๏ธโƒฃ

Hash

Produce a fingerprint that can help detect modification.

INTEGRITY
โœ๏ธ

Sign

Bind cryptographic evidence to the holder of a private key.

AUTHENTICATION & INTEGRITY

The Big Idea

Different cryptographic mechanisms solve different security problems.

๐Ÿ‘๏ธ Keep data secret โ†’ Encryption
โœ… Detect modification โ†’ Hashing / MAC / Signature
๐Ÿ‘ค Authenticate signer โ†’ Digital Signature
๐Ÿค Establish shared secret โ†’ Key Agreement / Key Establishment
๐Ÿ“œ Trust public key โ†’ Digital Certificate / PKI
๐Ÿ—๏ธ Protect keys over time โ†’ Key Management
Do not start with the algorithm

Start with the security requirement.

Ask: Do I need confidentiality, integrity, authentication, key establishment or some combination of them?

Essential Comparison

Encryption vs Hashing vs Digital Signatures

MechanismMain purposeUses a key?Reversible?
EncryptionConfidentialityYesYes, with the appropriate key
HashingIntegrity / fingerprintingNormally noDesigned to be one-way
HMAC / MACIntegrity and message authenticationShared secretNot an encryption mechanism
Digital SignatureIntegrity, authentication and evidence supporting non-repudiationPrivate / public key pairNot used to recover the original message

Crypto Shortcut

ENCRYPT Hide it
HASH Fingerprint it
HMAC Fingerprint it with a shared secret
SIGN Prove who signed it and detect modification

Encrypt = Confidentiality ยท Hash = Integrity ยท Sign = Identity + Integrity

๐Ÿ”‘ Symmetric Cryptography One shared secret key

Symmetric cryptography uses a shared secret key.

The communicating parties must both possess appropriate secret key material.

Plaintext + Shared Secret Key
Encryption โ†’ Ciphertext
Ciphertext + Shared Secret Key
Decryption โ†’ Plaintext

Strengths

Fast Efficient Good for Large Data Suitable for Bulk Encryption

Challenges

Key Distribution Key Storage Key Rotation Large Number of Relationships
Example

A 50 GB backup needs to be encrypted.

Symmetric encryption is well suited to the bulk encryption of the backup because it is efficient for large amounts of information.

Common Example - AES

The Advanced Encryption Standard - AES - is a widely used symmetric block cipher.

AES supports key sizes including:

AES-128 AES-192 AES-256

Symmetric

SAME SECRET Shared by communicating parties
FAST Excellent for bulk encryption
PROBLEM How do we distribute the secret securely?

Symmetric = Fast but Secret-Key Distribution Matters

๐Ÿงฑ Block & Stream Encryption Different ways of processing information
Block Cipher

Processes information in fixed-size blocks.

AES is the classic CISSP example.

Stream Cipher

Generates a keystream that is combined with the data stream.

Appropriate nonce and key handling are critical.

A block cipher needs an appropriate mode of operation

Simply knowing that an algorithm uses AES does not tell you everything about how the encryption has been implemented.

Mode selection, initialization values, authentication and key management also matter.

Authenticated Encryption

Modern cryptographic designs commonly use authenticated encryption so confidentiality and integrity protection are provided together.

Conceptual example

Instead of merely asking:

"Can an attacker read this?"

authenticated encryption also asks:

"Can an attacker alter this without detection?"

๐Ÿ—๏ธ Asymmetric Cryptography Public key + private key

Asymmetric cryptography uses a mathematically related key pair.

Public Key

Designed to be distributed to others.

Private Key

Must remain under the control of the key owner.

Confidentiality Use

Sender uses Recipient's PUBLIC key
Encrypted Data โ†’ Recipient
Recipient uses Recipient's PRIVATE key

Asymmetric Confidentiality

ENCRYPT with recipient's PUBLIC key
DECRYPT with recipient's PRIVATE key

Public locks it ยท Private unlocks it

Typical Uses

Digital Signatures Key Establishment Certificates Authentication Secure Protocols
Asymmetric cryptography is computationally heavier

For that reason, modern systems often combine asymmetric and symmetric cryptography rather than using public-key cryptography to encrypt every byte of a large data stream.

Symmetric vs Asymmetric

SymmetricAsymmetric
KeysShared secretPublic/private pair
PerformanceFastRelatively slower
Bulk encryptionExcellentUsually not the primary approach
Digital signaturesNoYes
Key distributionDifficult if no secure mechanism existsPublic keys may be distributed publicly, but their authenticity must be established
ExamplesAESRSA and elliptic-curve techniques
๐Ÿค Hybrid Cryptography Combine asymmetric trust with symmetric performance

Modern secure communications commonly use both asymmetric and symmetric cryptography.

Asymmetric Cryptography โ†’ Authenticate / Establish Session Secret
Session Secret โ†’ Symmetric Session Keys
Symmetric Encryption โ†’ Protect Bulk Communication
HTTPS / TLS concept

Your browser does not normally use public-key cryptography to encrypt every byte of a large website session.

Instead, public-key mechanisms help establish trust and session secrets, after which efficient symmetric cryptography protects the bulk communication.

Hybrid Cryptography

ASYMMETRIC Trust and key establishment
SYMMETRIC Fast bulk protection

Asymmetric starts it ยท Symmetric carries it

๐Ÿ“ Elliptic Curve Cryptography - ECC Public-key cryptography using elliptic-curve mathematics

Elliptic Curve Cryptography is a family of asymmetric cryptographic techniques based on the mathematical properties of elliptic curves.

ECC can provide strong public-key cryptographic security using comparatively smaller key sizes than some older public-key approaches.

Common Uses

Digital Signatures Key Agreement TLS Mobile Devices Embedded Systems
ECDSA

Elliptic Curve Digital Signature Algorithm.

Used for digital signatures.

ECDH

Elliptic Curve Diffie-Hellman.

Used to establish shared secrets.

ECDH โ‰  ECDSA

ECDH is associated with key agreement.

ECDSA is associated with digital signatures.

#๏ธโƒฃ Cryptographic Hashing Create a one-way fingerprint of information

A cryptographic hash function accepts data of varying size and produces a fixed-size output commonly called a hash or digest.

Message โ†’ Hash Function
Hash Function โ†’ Message Digest

Important Properties

One-Way

It should be computationally infeasible to reconstruct the original input from the digest.

Deterministic

The same input produces the same digest.

Avalanche Effect

A small input change should significantly change the output.

Collision Resistance

It should be difficult to find different inputs producing the same digest.

Common Uses

Integrity Checking Digital Signatures Password Protection File Fingerprints HMAC
Hashing is not encryption

There is no normal decryption operation that turns the digest back into the original message.

Integrity example

Original file:

Hash = ABC123

Downloaded file:

Hash = ABC123

Matching hashes provide evidence that the content has not changed.

An unkeyed hash does not prove who created the message

An attacker who changes a file may also calculate a new hash.

Authentication requires an additional trustworthy mechanism.

๐Ÿง‚ Salts & Password Hashing Passwords should not normally be stored as plaintext

Password-verification systems commonly store derived password values rather than plaintext passwords.

A unique random salt is added when deriving the stored password representation.

Password + Unique Salt
Password Derivation โ†’ Stored Value

Why Salt?

Imagine two users choose:

Password123!

Without unique salts, identical passwords can result in identical stored hashes.

With different salts, the resulting values differ.

Salt is not normally secret

Its purpose is primarily to make precomputed attacks less effective and prevent identical passwords from automatically producing the same stored representation.

Password Salt

SAME PASSWORD +
DIFFERENT SALT =
DIFFERENT STORED VALUE Better resistance to precomputation
๐Ÿ” MAC & HMAC Integrity plus authentication using a shared secret

A Message Authentication Code - MAC - uses secret key material to provide integrity and message authentication.

HMAC is a widely used construction based on a cryptographic hash function and a secret key.

Message + Shared Secret
HMAC โ†’ Authentication Code

Provides

Integrity Message Authentication
HMAC does not provide non-repudiation

Both communicating parties possess the shared secret.

Either party could therefore potentially create a valid HMAC.

Hash vs HMAC

HASH No secret key
HMAC Hash construction + shared secret
โœ๏ธ Digital Signatures Private key signs ยท Public key verifies

Digital signatures use asymmetric cryptography to provide evidence relating a message to the holder of a private signing key.

Signing

Message โ†’ Hash
Digest + Sender's PRIVATE Key
Signature Algorithm โ†’ Digital Signature

Verification

Receiver uses Sender's PUBLIC Key
Signature โ†’ Verify
Message โ†’ Hash Again
Verification โ†’ Confirm Signature

Provides

Integrity Authentication Evidence Supporting Non-Repudiation
Digital signature โ‰  confidentiality

Signing a document does not automatically hide its contents.

If confidentiality is also required, encryption must be applied appropriately.

Digital Signature

SIGN with PRIVATE key
VERIFY with PUBLIC key

Private Signs ยท Public Verifies

Critical CISSP Distinction

Public-Key Encryption vs Digital Signature

ConfidentialityDigital Signature
Primary goalKeep message secretIntegrity and signer authentication
Key used by senderRecipient's PUBLIC keySender's PRIVATE key
Key used by receiverRecipient's PRIVATE keySender's PUBLIC key

Whose Key?

CONFIDENTIALITY Encrypt for the RECIPIENT
SIGNATURE Sign as the SENDER

Secret for them = Their public key ยท Proof from me = My private key

๐Ÿค Key Establishment & Agreement Create shared secrets over untrusted networks

Secure communication often requires two parties that have never previously shared a secret to establish symmetric session key material.

Diffie-Hellman

Diffie-Hellman techniques allow parties to derive a shared secret over a public channel without directly transmitting the resulting shared secret itself.

DH

Classical Diffie-Hellman key agreement.

ECDH

Diffie-Hellman using elliptic-curve mathematics.

Unauthenticated key agreement can be vulnerable to MITM

Establishing a secret does not automatically prove who is on the other end.

Secure protocols therefore combine key establishment with authentication mechanisms.

Forward Secrecy

Ephemeral key-agreement mechanisms can provide forward secrecy.

The goal is that compromise of a long-term private key in the future does not automatically reveal previously established session keys.

Forward Secrecy

TODAY Unique ephemeral session secret
FUTURE Long-term key compromised
PAST SESSION Should remain protected
๐ŸŒ TLS as a Cryptographic System A practical example of several crypto mechanisms working together

Transport Layer Security - TLS - demonstrates why secure systems combine several cryptographic techniques.

๐Ÿ“œ Certificate โ†’ Authenticate server identity
๐Ÿ—๏ธ Public-Key Cryptography โ†’ Authentication / key establishment
๐Ÿค Key Agreement โ†’ Establish session secrets
๐Ÿ”‘ Symmetric Cryptography โ†’ Protect bulk session traffic
โœ… Integrity Protection โ†’ Detect unauthorised modification
TLS is a hybrid cryptographic protocol

No single cryptographic mechanism provides every required property.

Public Key Infrastructure

What Problem Does PKI Solve?

Asymmetric cryptography gives us public and private keys.

But one critical question remains:

How do I know that this public key really belongs to the person, organisation or system claiming to own it?

Public Key Infrastructure provides processes, technologies, policies and trust relationships used to manage public-key identities and digital certificates.

๐Ÿ‘ค Identity + Public Key
Certificate Authority โ†’ Digital Certificate
Certificate โ†’ Trusted Binding

PKI

KEY Who owns this public key?
CERTIFICATE Binds identity to public key
CA Vouches for that binding

PKI = Trust the Public Key

๐Ÿ›๏ธ PKI Components CA ยท RA ยท Certificates ยท Repositories ยท Status Services
Certificate Authority - CA

Issues and digitally signs certificates.

The CA is a central trust component.

Registration Authority - RA

May perform identity validation and registration activities on behalf of the CA.

Digital Certificate

Binds identity or subject information to a public key.

Repository

Makes relevant certificates and status information available.

CRL

Certificate Revocation List containing certificates that have been revoked by the issuing authority.

OCSP Responder

Provides online certificate-status information.

CA vs RA

RA Checks / registers identity
CA Issues / signs certificate

RA validates ยท CA certifies

๐Ÿ“œ Digital Certificates Bind a public key to a subject

X.509 certificates are widely used in PKI systems.

Certificate information commonly includes:

Subject

The entity associated with the certificate.

Issuer

The CA that issued the certificate.

Public Key

Public-key information associated with the subject.

Serial Number

Unique identifier assigned by the issuing CA.

Validity Period

When the certificate is considered valid.

Extensions

Additional constraints and uses associated with the certificate.

Signature Algorithm

Identifies the mechanism used by the issuing CA to sign.

CA Signature

Protects the certificate's integrity and establishes the issuer's assertion.

A certificate contains a public key - not the subject's private key

The corresponding private key must remain appropriately protected by its owner.

โ›“๏ธ Certificate Chain of Trust Leaf โ†’ Intermediate โ†’ Root

PKI trust is often hierarchical.

๐ŸŒ Website Certificate signed by Intermediate CA
Intermediate CA signed by Root CA
Root CA โ†’ Trusted Locally as Trust Anchor
Root CA

A root certificate is typically self-signed.

It is trusted because the root has been deliberately installed or distributed as a trust anchor - not merely because it signed itself.

Why Intermediate CAs?

Root CA private keys are extremely sensitive.

Rather than using a root key for routine certificate issuance, organisations commonly use subordinate or intermediate CAs.

Root CA โ†’ High-value trust anchor
Intermediate CA โ†’ Operational certificate issuance
End Entity โ†’ Server / User / Device Certificate

Certificate Chain

LEAF End entity
INTERMEDIATE Signs leaf
ROOT Trust anchor

Leaf โ†’ Intermediate โ†’ Trusted Root

โœ… Certificate Validation A signed certificate is not automatically trustworthy

When validating a certificate, a relying system may need to consider several conditions.

1๏ธโƒฃ Signature โ†’ Was it signed by an appropriate issuer?
2๏ธโƒฃ Trust Chain โ†’ Does the chain terminate at a trusted anchor?
3๏ธโƒฃ Validity โ†’ Is the certificate currently within its valid dates?
4๏ธโƒฃ Identity โ†’ Does it represent the entity being accessed?
5๏ธโƒฃ Usage โ†’ Is the certificate appropriate for this purpose?
6๏ธโƒฃ Status โ†’ Has it been revoked or otherwise invalidated?
TLS example

A website presents a cryptographically valid certificate.

However, the certificate belongs to:

different-example.com

while the user is visiting:

bank-example.com.

A valid signature alone does not make that certificate appropriate for the connection.

๐Ÿšซ Certificate Revocation What happens when a certificate must stop being trusted?

A certificate may still be within its published validity period but become unsafe or inappropriate to trust.

Reasons for Revocation

Private Key Compromise CA Compromise Incorrect Issuance Change of Affiliation Certificate No Longer Required

CRL - Certificate Revocation List

A CA can publish a signed list identifying certificates that have been revoked.

CA โ†’ Publish CRL
Client โ†’ Check List

OCSP - Online Certificate Status Protocol

OCSP provides a mechanism to request certificate-status information online rather than relying solely on downloading a complete revocation list.

Client โ†’ OCSP Request
OCSP Responder โ†’ Status Response
CRLOCSP
ApproachDownload revocation informationQuery certificate status
InformationList of revoked certificatesStatus response for certificate
Potential issueLists can become large or stale between publicationsRequires status-service availability and can introduce privacy considerations

CRL vs OCSP

CRL Get the LIST
OCSP Ask the STATUS

Certificate Lifecycle

1๏ธโƒฃ Request โ†’ Certificate requested
2๏ธโƒฃ Validate โ†’ Identity / authority checked
3๏ธโƒฃ Issue โ†’ CA signs certificate
4๏ธโƒฃ Deploy โ†’ Certificate and key used
5๏ธโƒฃ Monitor โ†’ Expiry and compromise tracked
6๏ธโƒฃ Renew / Replace โ†’ New certificate issued where required
7๏ธโƒฃ Revoke / Expire โ†’ Certificate stops being accepted
Certificate management is an operational security process

Organisations need visibility of certificates, owners, expiration dates, associated private keys and dependencies.

An unexpected expired certificate can become an availability incident.

๐Ÿ—๏ธ Cryptographic Key Lifecycle Generating a strong key is only the beginning

Cryptographic security depends heavily on how keys are managed throughout their lifetime.

1๏ธโƒฃ Generate โ†’ Create appropriate key material securely
2๏ธโƒฃ Establish / Distribute โ†’ Deliver or establish keys securely
3๏ธโƒฃ Store โ†’ Protect key material
4๏ธโƒฃ Use โ†’ Restrict keys to authorised cryptographic purposes
5๏ธโƒฃ Rotate / Replace โ†’ Introduce new key material
6๏ธโƒฃ Revoke / Deactivate โ†’ Stop inappropriate future use
7๏ธโƒฃ Archive / Recover โ†’ Retain when legitimate requirements exist
8๏ธโƒฃ Destroy โ†’ Securely remove key material when no longer needed
Key compromise can defeat strong cryptography

An attacker may not need to break the algorithm if they can simply steal the key.

Key Lifecycle

CREATE Securely
PROTECT While used
ROTATE When required
REVOKE When untrusted
DESTROY When no longer required
โณ Cryptoperiod Keys should not necessarily be used forever

A cryptoperiod is the period during which a cryptographic key is authorised for a particular use.

Appropriate cryptoperiods depend on factors such as:

Key Type Algorithm Data Sensitivity Threat Amount of Data Protected Operational Requirements Compromise Consequences
Why rotate keys?

Limiting how long one key is used can reduce the amount of information or number of systems affected if that key is compromised.

Shorter is not automatically operationally better

Key rotation needs to balance security requirements with reliable distribution, availability and operational complexity.

๐Ÿงฐ Key Recovery & Escrow What happens if legitimate access to an encryption key is lost?

Some encryption systems require a controlled recovery capability.

Example

An employee encrypts important corporate information and then leaves the organisation.

If the only decryption key disappears with the employee, the information may become permanently unavailable.

Key Escrow

Key escrow stores recoverable cryptographic key material with an authorised third party or controlled organisational mechanism.

Key Recovery

Key recovery allows authorised access to protected key material when a legitimate recovery condition occurs.

Encryption key recovery โ‰  signing key recovery

Recovering encryption keys may be necessary to preserve access to organisational data.

Duplicating or escrowing private signing keys can undermine confidence that only the claimed signer controlled the key.

Think about the security objective

Encryption keys may need recovery because data availability matters.

Signature keys depend strongly on sole control and authenticity.

๐Ÿ‘ฅ Split Knowledge & Dual Control Reduce reliance on one privileged individual
Split Knowledge

Sensitive information is divided so one individual does not possess the entire secret.

Dual Control

Two or more authorised individuals must participate in a sensitive operation.

Key ceremony example

Several security officers each possess part of the information or authorisation required to activate a highly sensitive cryptographic key.

No single individual can perform the operation alone.

Split vs Dual

SPLIT KNOWLEDGE No one knows everything
DUAL CONTROL No one acts alone
๐Ÿฆ Hardware Security Modules - HSM Protect valuable cryptographic keys and operations

HSMs are specialised security devices designed to protect cryptographic keys and perform cryptographic operations within a controlled hardware environment.

Key Generation Key Storage Digital Signing Encryption Decryption CA Key Protection
Certificate Authority example

A root CA's private signing key represents an extremely high-value organisational secret.

Keeping the signing operation inside protected cryptographic hardware can significantly reduce the exposure of that private key.

Protect the key where it is used

The safest private key is often one that does not need to be exported into ordinary application memory or stored as a normal file.

Cryptographic Lifecycle

Algorithm Selection

Selecting a cryptographic algorithm is a risk-management and architecture decision.

Security Strength

Is the algorithm and parameter set sufficiently strong?

Purpose

Encryption, signature, hashing or key establishment?

Data Lifetime

How long must the information remain protected?

Performance

What processing and latency constraints exist?

Platform

Which devices and implementations must support it?

Standards

Which organisational or regulatory requirements apply?

Interoperability

Which external systems must communicate?

Future Migration

Can the algorithm be replaced when requirements change?

Algorithms age

Cryptographic algorithms and parameter sizes that were once considered appropriate may eventually become unsuitable because of advances in cryptanalysis, computing capability or standards.

๐Ÿ”„ Cryptographic Agility Design systems so cryptography can change

Cryptographic agility - often shortened to crypto agility - is the ability to replace or adapt cryptographic algorithms and mechanisms without requiring a complete redesign of the surrounding system.

Poor architecture

One encryption algorithm is hard-coded into:

  • thousands of applications;
  • firmware;
  • databases;
  • network protocols;
  • third-party integrations.

Replacing it becomes a multi-year engineering project.

Crypto-agile architecture

Cryptographic functions and policies are designed so algorithms, certificates and parameters can be changed in a controlled way.

Crypto Agility Requires Visibility

๐Ÿ” Discover โ†’ Where is cryptography used?
๐Ÿ“‹ Inventory โ†’ Which algorithms, keys and certificates exist?
โš ๏ธ Assess โ†’ Which uses are becoming risky?
๐Ÿ”„ Replace โ†’ Migrate safely
โœ… Validate โ†’ Confirm migration succeeded

Crypto Agility

KNOW What crypto you use
CHANGE It when required
WITHOUT Breaking everything
Current Cryptographic Transition

Quantum Computing & Cryptography

Large-scale cryptographically relevant quantum computers would threaten important classes of traditional public-key cryptography.

This creates a long-term architectural requirement to identify cryptographic dependencies and prepare systems for migration.

"Harvest now, decrypt later"

An attacker may collect encrypted information today and retain it in the hope that future technology allows them to decrypt it.

This is particularly relevant when information must remain confidential for many years.

โš›๏ธ Post-Quantum Cryptography - PQC Cryptographic algorithms designed to resist quantum attacks

Post-quantum cryptography uses mathematical algorithms intended to remain secure against attacks from both classical and sufficiently capable quantum computers.

Importantly:

Post-quantum cryptography runs on ordinary classical computing systems. It does not require a quantum computer.

NIST's Initial PQC Standards

StandardAlgorithmPurpose
FIPS 203ML-KEMKey encapsulation / shared-secret establishment
FIPS 204ML-DSADigital signatures
FIPS 205SLH-DSAHash-based digital signatures
The migration challenge is architectural

Organisations first need to know where vulnerable public-key algorithms are used before they can replace them.

This is another reason crypto agility is increasingly important.

PQC

ML-KEM Establish keys
ML-DSA Sign
SLH-DSA Sign using hash-based construction
๐Ÿ’ก Quantum Key Distribution - QKD Use quantum properties to establish secret key material

Quantum Key Distribution uses quantum-mechanical properties to help establish secret key material between parties.

One important idea is that attempting to observe the quantum communication can disturb it in a detectable way.

Alice โ†’ Quantum Channel
Quantum Channel โ†’ Bob
Measurements โ†’ Generate Shared Secret Key Material
QKD โ‰  Post-Quantum Cryptography

PQC uses new mathematical cryptographic algorithms running on conventional computing systems.

QKD uses quantum communication technology to establish secret keys.

QKD โ‰  complete replacement for PKI

Establishing key material does not by itself solve every problem of identity, authentication, certificate management or application security.

PQC vs QKD

PQC Quantum-resistant mathematics
QKD Quantum communication for key distribution
Architecture Perspective

Cryptography is a System, Not an Algorithm

A secure cryptographic architecture requires more than selecting a strong cipher.

๐Ÿงฎ Algorithm โ†’ Is the cryptographic method appropriate?
๐ŸŽฒ Generation โ†’ Are keys and randomness generated securely?
๐Ÿ—๏ธ Storage โ†’ Are private and secret keys protected?
๐Ÿšš Distribution โ†’ How are keys established or transported?
๐Ÿ“… Lifecycle โ†’ When are keys rotated or revoked?
๐Ÿ“œ Trust โ†’ How are public keys authenticated?
๐Ÿ”„ Agility โ†’ Can the cryptography be replaced later?
Strong algorithm + weak key management = weak cryptographic system.
Practical Scenario

Connecting to an Online Bank

A customer visits an online banking website using HTTPS.

Several cryptographic mechanisms work together.

1๏ธโƒฃ Website โ†’ Presents digital certificate
2๏ธโƒฃ Browser โ†’ Validates certificate chain and identity
3๏ธโƒฃ Key Agreement โ†’ Establish session secrets
4๏ธโƒฃ Symmetric Keys โ†’ Protect session efficiently
5๏ธโƒฃ Integrity Protection โ†’ Detect modification
This is why CISSP separates the cryptographic functions

Certificates do not perform the whole job.

Symmetric encryption does not establish identity.

Hashing alone does not establish trust.

Secure protocols combine several mechanisms.

Second Scenario

Sending a Confidential Signed Message

Alice wants to send Bob a message that:

  • only Bob can read;
  • Bob can verify that Alice signed it;
  • Bob can detect whether the message changed.

Signature

Alice signs using:

Alice's PRIVATE key.

Bob verifies using:

Alice's PUBLIC key.

Confidentiality

The message or session key can be protected for:

Bob using Bob's PUBLIC key or another appropriate key-establishment mechanism.

Bob accesses the protected information using:

Bob's PRIVATE key or resulting session secret.

Alice โ†’ Bob

PROVE ALICE Alice's PRIVATE key
VERIFY ALICE Alice's PUBLIC key
KEEP SECRET FOR BOB Bob's PUBLIC key / established session secret
BOB OPENS Bob's PRIVATE key / session secret
๐ŸŽ“ CISSP Scenarios Identify the correct cryptographic mechanism
Scenario 1

An organisation needs to encrypt several terabytes of backup data efficiently.

Which approach is MOST appropriate?

Symmetric encryption.

Scenario 2

Alice wants Bob to receive information that only Bob can decrypt using asymmetric cryptography.

Which public key should Alice use?

Bob's public key.

Scenario 3

Alice digitally signs a document.

Which key should Alice use?

Alice's private key.

Scenario 4

Bob receives Alice's digitally signed document.

Which key should Bob use to verify the signature?

Alice's public key.

Scenario 5

A file's digest changes after one character in the file is modified.

Which cryptographic concept is demonstrated?

Cryptographic hashing and the avalanche effect.

Scenario 6

Two systems share a secret and need to verify that API messages have not been modified and came from a party possessing that secret.

Which mechanism is appropriate?

MAC / HMAC.

Scenario 7

Two users have chosen the same password, but their stored password values should not automatically be identical.

Which mechanism helps?

Unique password salts.

Scenario 8

A browser needs to determine whether a website public key really belongs to the claimed website.

Which infrastructure helps establish this trust?

PKI and digital certificates.

Scenario 9

A CA delegates identity verification to another organisational component before certificate issuance.

Which component performs that function?

Registration Authority - RA.

Scenario 10

A website certificate was issued legitimately but its private key has since been compromised.

What should happen?

The certificate should be revoked and replaced.

Scenario 11

A client downloads a periodically published list of invalid certificates from a CA.

Which mechanism is this?

CRL.

Scenario 12

A client asks an online service for the current status of a specific certificate.

Which protocol is MOST relevant?

OCSP.

Scenario 13

A company protects all encryption keys using powerful algorithms, but keeps them in plaintext configuration files.

Primary weakness?

Key management.

Scenario 14

Two administrators must both participate before a root CA signing key can be activated.

Which concept is demonstrated?

Dual control.

Scenario 15

No administrator possesses the entire sensitive key component.

Which concept is demonstrated?

Split knowledge.

Scenario 16

A future compromise of a TLS server's long-term private key should not expose session keys from previously recorded connections.

Which property is required?

Forward secrecy.

Scenario 17

An organisation cannot easily replace an obsolete algorithm because it has been hard-coded into hundreds of systems.

Which capability was missing?

Cryptographic agility.

Scenario 18

An organisation wants a quantum-resistant mechanism for establishing shared secret key material using ordinary computers.

Which current concept is MOST relevant?

Post-quantum Key Encapsulation Mechanism such as ML-KEM.

Scenario 19

Two locations use quantum properties of transmitted photons to help establish secret key material.

Which technology is this?

Quantum Key Distribution - QKD.

Scenario 20

A very large database is encrypted using public-key cryptography for every record even though a symmetric session key could provide the required confidentiality more efficiently.

Which architecture is generally preferable?

Hybrid cryptography - asymmetric mechanisms for trust or key establishment and symmetric encryption for bulk data.

CISSP Exam Perspective

Recognise the Clue Words

Bulk Encryption

Fast, shared secret, large data.

Symmetric

Public / Private Pair

Signatures and key establishment.

Asymmetric

Fixed-Length Fingerprint

Detect modification.

Hash

Shared Secret + Integrity

Authenticate message between parties sharing key.

HMAC

Private Signs

Public verifies.

Digital Signature

Confidential for Bob

Use Bob's public key.

Public-Key Confidentiality

Who Owns This Public Key?

Identity-to-key binding.

Certificate / PKI

Checks Identity

Before certificate issuance.

RA

Signs Certificate

Trust authority.

CA

List of Revoked Certificates

Download status list.

CRL

Online Certificate Status

Query certificate.

OCSP

Protect Valuable Keys

Dedicated cryptographic hardware.

HSM

No One Knows Whole Secret

Divide sensitive information.

Split Knowledge

No One Acts Alone

Multiple participants required.

Dual Control

Past Sessions Stay Safe

Future long-term key compromise.

Forward Secrecy

Replace Algorithms Easily

Prepare for cryptographic transition.

Crypto Agility

Quantum-Resistant Algorithms

Conventional computers.

PQC

Quantum Communication

Establish secret keys using quantum properties.

QKD
โš ๏ธ Common CISSP Mistakes The key direction questions are especially important
Hashing โ‰  Encryption

Encryption is reversible with appropriate key material.

Hashing is designed as a one-way transformation.

Digital Signature โ‰  Confidentiality

A signature protects integrity and supports authentication.

It does not hide the message.

For confidentiality, think RECIPIENT

Encrypt using the recipient's public key.

For signature, think SENDER

Sign using the sender's private key.

HMAC โ‰  Digital Signature

HMAC uses a shared secret.

A digital signature uses asymmetric key material.

HMAC โ‰  Non-Repudiation

Both parties may possess the shared secret and therefore may both be capable of creating a valid authentication code.

Salt โ‰  Secret Encryption Key

Password salts are normally stored alongside the password-derived value.

Certificate โ‰  Private Key

Certificates distribute public-key information.

Private keys should remain protected.

Self-Signed Root โ‰  Automatically Trustworthy

A root CA is trusted because it is deliberately configured as a trust anchor.

Expiry โ‰  Revocation

Expiration occurs when the certificate reaches the end of its validity period.

Revocation invalidates a certificate before normal expiration.

CRL โ‰  OCSP

CRL provides a revocation list.

OCSP provides online certificate-status responses.

Strong Algorithm โ‰  Strong System

Weak keys, poor randomness, bad implementation or exposed key material can defeat otherwise strong cryptography.

Key Recovery โ‰  Always Appropriate

Recovery may be important for encryption keys.

Private signing keys require especially careful protection of sole control.

PQC โ‰  QKD

PQC is quantum-resistant mathematical cryptography.

QKD uses quantum communication to establish key material.

Quantum-resistant โ‰  quantum computer required

Post-quantum algorithms are intended to run on conventional computers.

Quick Reference

If you need to...Think...
Encrypt large quantities of data efficientlySymmetric Encryption
Use a public/private key pairAsymmetric Cryptography
Detect data modificationHash
Authenticate a message with a shared secretHMAC / MAC
Authenticate a signer cryptographicallyDigital Signature
Encrypt data for Bob using public-key cryptographyBob's Public Key
Verify Alice's signatureAlice's Public Key
Sign as AliceAlice's Private Key
Establish a shared secretDH / ECDH / KEM
Trust a public keyPKI / Certificate
Validate certificate applicantRA
Issue certificateCA
Check a revocation listCRL
Request online certificate statusOCSP
Protect high-value private keysHSM
Divide secret information between peopleSplit Knowledge
Require multiple people to perform an operationDual Control
Protect previous sessions after future key compromiseForward Secrecy
Replace algorithms without redesigning everythingCrypto Agility
Use quantum-resistant mathematical algorithmsPQC
Distribute key material using quantum communicationQKD

Cryptography Master Memory Aid

SYMMETRIC Same shared secret ยท Fast
ASYMMETRIC Public + Private ยท Trust and key establishment
HASH One-way fingerprint
HMAC Fingerprint + shared secret
SIGNATURE Private signs ยท Public verifies
PKI Trust the public key
KEY MANAGEMENT Protect the secret over its entire life
CRYPTO AGILITY Be able to change cryptography

Encrypt ยท Hash ยท Authenticate ยท Sign ยท Trust ยท Manage

The CISSP Key Direction Shortcut

CONFIDENTIALITY Encrypt with RECIPIENT'S PUBLIC key
CONFIDENTIALITY Recipient decrypts with RECIPIENT'S PRIVATE key
SIGNATURE Sender signs with SENDER'S PRIVATE key
VERIFICATION Verify using SENDER'S PUBLIC key

Secret for THEM โ†’ Their Public ยท Proof from ME โ†’ My Private

Key Takeaways

Cryptographic solutions should be selected according to the security property that needs to be achieved.

Symmetric cryptography uses shared secret key material and is highly efficient for bulk encryption.

Asymmetric cryptography uses public/private key pairs and enables capabilities such as digital signatures and secure key establishment.

Modern systems commonly use hybrid cryptography: asymmetric mechanisms establish trust or session secrets while symmetric cryptography protects bulk information efficiently.

To protect confidentiality for a recipient using public-key encryption, use the recipient's public key.

The recipient uses their private key to perform the corresponding private operation.

Cryptographic hashing produces a one-way fingerprint and is commonly used to support integrity checking.

HMAC combines shared secret material with a hash-based construction to provide integrity and message authentication.

Digital signatures use the signer's private key to sign and the signer's public key to verify.

Digital signatures support integrity, authentication and evidence used for non-repudiation, but do not automatically provide confidentiality.

Salts help protect password-verification systems against precomputed attacks and ensure identical passwords do not automatically produce identical stored representations.

Diffie-Hellman and ECDH are associated with key agreement, while ECDSA is associated with digital signatures.

Ephemeral key agreement can provide forward secrecy so compromise of a long-term key does not automatically expose previously established sessions.

PKI solves the trust problem surrounding public keys by binding identities to public keys using certificates and trusted authorities.

A Registration Authority may validate identity while a Certificate Authority issues and signs certificates.

Certificate trust can be established through a chain from an end-entity certificate through intermediate CAs to a trusted root.

Certificate validation should consider trust chain, signature, validity period, identity, intended usage and revocation status.

CRLs provide revocation lists while OCSP provides online certificate status information.

Strong algorithms do not compensate for weak key management.

Key management includes secure generation, establishment, storage, use, rotation, revocation, recovery where appropriate and eventual destruction.

Split knowledge means no one individual possesses the complete secret, while dual control requires multiple people to participate in a sensitive operation.

Cryptoperiods limit the authorised usage period of cryptographic key material.

HSMs can protect highly sensitive keys and perform cryptographic operations inside dedicated hardware.

Crypto agility allows organisations to migrate algorithms and cryptographic mechanisms when security requirements change.

Post-quantum cryptography uses mathematical algorithms intended to resist quantum attacks while running on conventional computing systems.

Quantum Key Distribution is a different concept that uses quantum communication to establish secret key material.

Cryptography is a system: algorithm + key + implementation + lifecycle + trust. Weakness in any part can undermine the protection.

๐Ÿ“š Sources & Further Reading Authoritative cryptographic and PKI references