Question 1
A financial institution is implementing a new secure messaging system. The primary requirement is that if the long-term private key of a recipient is compromised, an attacker should not be able to decrypt past messages that were sent to that recipient. Which cryptographic property must the key exchange protocol implement to meet this requirement?
Answer and explanation
Correct answer: B
Perfect Forward Secrecy (PFS) ensures that a session key derived from a set of long-term keys will not be compromised if one of the long-term private keys is compromised in the future. This is achieved by generating new, ephemeral keys for each session and then discarding them. Diffie-Hellman Ephemeral (DHE) and Elliptic Curve Diffie-Hellman Ephemeral (ECDHE) are common key exchange mechanisms that provide PFS.