Skip to main content

Protect data with applied cryptography

Learn cryptographic primitives, key systems, data lifecycle controls, storage protection, and migration without inventing protocols.

Learning outcomes

  • Distinguish hashes, MACs, signatures, authenticated encryption, key derivation, and random generation.
  • Design key custody, envelope encryption, record formats, nonce rules, recovery, and rotation.
  • Apply classification, minimization, retention, and secure deletion across every data copy.
  • Inventory and migrate cryptography, including post-quantum changes, without downgrade or hidden dependencies.

Scenario

A multi-tenant service stores recovery credentials and signed audit artifacts for several years. It must protect database and backup compromise, isolate tenant key use, restore data, remove expired records, and migrate algorithms without losing availability or verification.

Ordered learning units

  1. Concept

    Data Classification

    Assign data sensitivity, criticality, ownership, use, sharing, retention, and recovery requirements that drive technical controls.

  2. Guide

    Protect the data lifecycle

    Control collection, use, sharing, storage, logging, backup, recovery, retention, deletion, and sanitization for one data class.

  3. Concept

    Cryptographic Hash Function

    Map data to a fixed-length digest with defined preimage, second-preimage, and collision resistance for the selected use.

  4. Concept

    Message Authentication Code (MAC)

    Verify message integrity and shared-key origin with a standard MAC while controlling key scope, context, replay, and verification.

  5. Concept

    Digital Signature

    Bind a defined message to a private signing key and verify it through an authenticated public key, purpose, and context.

  6. Concept

    Key Derivation Function (KDF)

    Derive purpose-separated cryptographic keys from suitable key material with a standard KDF, salt, context, and output length.

  7. Concept

    Nonce and Initialization Vector

    Apply the exact uniqueness, unpredictability, length, and state rules that a cryptographic construction requires for each key.

  8. Concept

    Cryptographic Key Management

    Control cryptographic key purpose, generation, custody, distribution, use, rotation, compromise, recovery, and destruction.

  9. Concept

    Key Management Service and HSM

    Separate key lifecycle orchestration, hardware protection, cryptographic operations, workload authorization, and application data policy.

  10. Concept

    Envelope Encryption

    Encrypt data with a data-encryption key and protect that key under a separately stored key-encryption key or key service.

  11. Guide

    Design application cryptography

    Select a standard construction and define keys, nonces, context, record format, failure behavior, tests, and migration before coding.

  12. Concept

    Cryptographic Agility

    Inventory and replace algorithms, parameters, protocols, keys, libraries, certificates, and stored formats without hidden dependencies.

  13. Concept

    Post-Quantum Cryptography

    Prepare public-key systems for quantum-resistant key establishment and signatures through inventory, standards, testing, and migration.

  14. Guide

    Plan a cryptographic migration

    Inventory cryptographic dependencies and migrate protocols, algorithms, keys, certificates, code, hardware, and stored data safely.

Evaluation questions

  • Which security property and threat boundary does each cryptographic mechanism protect?
  • Are key purpose, scope, custody, nonce, context, record format, authorization, and failure behavior explicit?
  • Can every data copy be found, recovered, retained, deleted, and sanitized according to its classification?
  • Can the system migrate and reject old cryptography without hidden consumers, downgrade, or loss of required data?

Completion conditions

  • Produce a plaintext, ciphertext, key, identity, copy, and recovery map for one sensitive data class.
  • Implement or review a versioned authenticated-encryption record and its negative tests without designing a new primitive.
  • Run one key rotation, one isolated backup restore, one deletion verification, and one old-format rejection test.

Sources and further reading

Get a Personalized Demo

Schedule a Call with a Pomerium Engineer

Get a Demo