A security architect for a financial services firm is designing a new data protection scheme for account numbers stored in a PostgreSQL database. The business requires that the same account number always transforms to the same ciphertext so that existing equality-based lookups and unique constraints continue to work, while the raw values must remain unreadable to database administrators. Which cryptographic approach should the architect select?
AES-SIV is a misuse-resistant AEAD mode that produces a deterministic ciphertext for a given plaintext and associated data, so identical account numbers map to identical ciphertext. This preserves equality searches, joins, and unique indexes while keeping values unreadable to DBAs who lack the key, satisfying the stated business requirement.
Why this answer
The requirement for repeatable ciphertext that still supports equality lookups points to a deterministic authenticated encryption mode. AES-SIV derives its nonce from the plaintext and associated data, so the same input always yields the same output while still providing integrity. Randomized modes and salted hashing break the equality-search property the database design depends on.
Exam trap
The trap here is assuming that any authenticated encryption mode preserves equality lookups, when in fact only deterministic modes do so.