Applied Cryptography and Key Management Questions

Selecting and applying cryptographic primitives correctly: symmetric and asymmetric encryption, hashing, digital signatures, key derivation, secure random number generation, and public key infrastructure. Covers key lifecycle management, key exchange and distribution, choosing appropriate algorithms for a given constraint set including resource-constrained environments, and the forward-looking side of algorithm lifecycle: cryptographic agility and algorithm-migration strategy, forward secrecy, and the post-quantum cryptography transition and planning upgrades without breaking existing data or interoperability. The applied-crypto engineering layer, distinct from compliance-driven crypto standards.

HardSystem Design
31 practiced

Architect a feature-flag-driven rollout system that lets you switch which symmetric encryption algorithm is used in live traffic without downtime. Include client/server negotiation, tagging ciphertexts with algorithm and key-version, dual-write modes, a bulk re-encryption strategy for already-stored blobs, the metrics you'd watch, and automated rollback triggers.

EasyTechnical
34 practiced

Explain the 'quantum threat timeline' and its practical implications for long-term confidentiality. Describe the 'harvest-now, decrypt-later' threat model, give a reasonable range for when a large-scale quantum computer could threaten RSA/ECC, and explain how that timeline should influence which assets get prioritized for migration and what cryptoperiods you'd set.

MediumTechnical
32 practiced

Design a benchmark suite to measure symmetric and asymmetric cryptographic operation performance for a latency-sensitive service: throughput, latency percentiles (p50/p95/p99), CPU cycles per operation, and memory/cache behavior. What warmup considerations, power-saving-feature controls, and JIT-runtime effects do you need to account for to get statistically meaningful numbers?

HardSystem Design
46 practiced

Design a scalable PKI and key-management solution for 10 million IoT devices, many with intermittent connectivity and limited TPM/HSM capability. Address secure provisioning, key storage choices, rotation, revocation strategies where CRL/OCSP don't fit well, OTA updates, and how you'd bootstrap a root of trust.

HardTechnical
26 practiced

Design a scheme using HKDF to derive multiple independent keys (an encryption key, a MAC key, an IV/nonce seed, and a key-encryption key) from a single per-tenant master secret in a multi-tenant SaaS environment. Specify how you use extract and expand, what goes into your salt and info/context strings for domain separation, and how you handle per-tenant rotation and forward/backward compatibility. Then analyze what an attacker who compromises one derived key can and cannot recover about the master secret or the other derived keys.

Unlock Full Question Bank

Get access to all Applied Cryptography and Key Management interview questions and detailed answers.

Sign in to Continue

Join thousands of developers preparing for their dream job.