CACS459 Information Security

Information SecurityUnit 411 min read

Asymmetric Cryptography & Digital Signatures: RSA, ECC, DSS, and Real-World Use

Unit 4 of Information Security explores asymmetric key cryptography (RSA, ECC, ElGamal), digital signatures (DSS, RSA-based), key generation, and their applications in secure communication, authentication, and e-commerce—with worked examples, comparisons, and real-world ties to eSewa, Ncell, and NEPSE.

Key points

  • Asymmetric cryptography uses **public/private key pairs** (unlike symmetric keys) for secure key exchange, digital signatures, and encryption (e.g., RSA, ECC).
  • **RSA** relies on hard factorization of large primes (p, q) and modular arithmetic; **ECC** uses elliptic curves for smaller keys with equivalent security.
  • Digital signatures (DSS, RSA-based) **prove authenticity and non-repudiation** by signing messages with a private key and verifying with a public key.
  • **Key generation** in RSA involves choosing primes, computing φ(n), and selecting e/d pairs; in ECC, it uses curve parameters and private key scalar multiplication.
  • **Applications**: TLS/SSL (HTTPS), PGP email encryption, blockchain (Bitcoin), and eSewa’s secure transactions.
  • **Weaknesses**: RSA’s slow speed for large data, ECC’s complexity, and side-channel attacks on implementations.

Core Concepts: Symmetric vs. Asymmetric Cryptography

Asymmetric cryptography solves symmetric cryptography’s key distribution problem by using two mathematically linked keys:

  • Public Key (PK): Shared openly (e.g., on a website or in a certificate).
  • Private Key (SK): Kept secret by the owner.
Symmetric Cryptography[object Object]Asymmetric Cryptography[object Object]
Comparison: Symmetric vs. Asymmetric Cryptography key properties

Unlike symmetric keys (e.g., AES), asymmetric keys cannot be derived from each other—only via computational hardness assumptions (e.g., factoring, discrete logarithms).

Why asymmetric?

  • Secure key exchange: Diffie-Hellman (not covered here) or RSA can share a symmetric key over an insecure channel.
  • Digital signatures: Prove a message came from you (non-repudiation).
  • Authentication: Verify identities (e.g., HTTPS certificates).

1. RSA: The Workhorse of Asymmetric Cryptography

RSA (Rivest-Shamir-Adleman) is the most widely used asymmetric algorithm, relying on the difficulty of factoring large primes.

016324863Public Key (e, n)32 bitsPrivate Key (d, n)32 bitsPlaintext (m)32 bitsCiphertext (c)32 bits
RSA key and message structure (simplified 64-bit example)
sequenceDiagram
    participant Alice
    participant Bob
    participant eSewa
    Alice->>eSewa: Transaction Request (encrypted with eSewa's Public Key)
    eSewa-->>Alice: Signed Receipt (encrypted with eSewa's Private Key)
    Note right of eSewa: **RSA Encryption**: Only eSewa can decrypt
    Alice->>Bob: Payment Confirmation (digitally signed with eSewa's Private Key)
    Bob->>Alice: Verification (using eSewa's Public Key)
    Note right of Bob: **RSA Signature**: Proves authenticity

How RSA Works

  1. Key Generation:

    • Choose two large primes p and q (e.g., 61 and 59 in examples, but real-world uses 1024+ bits).
    • Compute n = p × q (modulus) and φ(n) = (p–1)(q–1) (Euler’s totient).
    • Pick e (public exponent, usually 65537) such that 1 < e < φ(n) and gcd(e, φ(n)) = 1.
    • Compute d (private exponent) as the modular inverse of e mod φ(n): .
  2. Encryption: For a message m (as an integer < n), ciphertext c is: .

  3. Decryption: .

Worked Example: RSA with p=5, q=19, m=4

stateDiagram-v2
    [*] --> KeyGen: p=5, q=19
    KeyGen --> Compute: n = 5×19 = 95
    Compute --> Compute: φ(n) = 4×18 = 72
    Compute --> Choose: e=5 (since gcd(5,72)=1)
    Choose --> Compute: d = 5⁻¹ mod 72 = 29 (since 5×29 ≡ 1 mod 72)
    KeyGen --> PublicKey: (e=5, n=95)
    KeyGen --> PrivateKey: (d=29, n=95)
    PublicKey --> Encrypt: c = 4⁵ mod 95 = 1024 mod 95 = 34
    Encrypt --> Decrypt: m = 34²⁹ mod 95 = 4
    Decrypt --> [*]

Step-by-Step Calculation:

  1. n = 5 × 19 = 95
  2. φ(n) = (5–1)(19–1) = 4 × 18 = 72
  3. Choose e = 5 (must be coprime with 72; gcd(5,72)=1).
  4. Find d such that . Testing: ⇒ d = 29.
  5. Encrypt m=4: .
  6. Decrypt c=34: . Use modular exponentiation (e.g., square-and-multiply):
    • Break 29 into binary: 11101.
    • Compute step-by-step: Combine: .

RSA in the Real World

  1. eSewa Payments:

    • When you pay bills via eSewa, your public key (embedded in the app) encrypts your transaction details. The private key (held securely by eSewa’s servers) decrypts and verifies the payment.
    • Digital signatures ensure the transaction request is authentic (not spoofed).
  2. Ncell’s SIM Card Authentication:

    • Your SIM card stores an RSA private key for authenticating to the Ncell network. The network holds your public key to verify your identity when you make calls/data requests.
  3. NEPSE (Nepal Stock Exchange):

    • Investors use RSA-signed certificates to authenticate trades. The exchange’s servers verify signatures to prevent fraudulent orders.

2. Elliptic Curve Cryptography (ECC): Smaller Keys, Same Security

ECC provides equivalent security to RSA but with smaller key sizes (e.g., 256-bit ECC ≈ 3072-bit RSA). It uses elliptic curves over finite fields.

[object Object][object Object][object Object]Pathao AppDriver DevicePathao Server
Pathao’s ECC workflow: 256-bit keys vs. RSA’s 2048-bit for equivalent security (real-world example)

Key Concepts

  • Elliptic Curve: Defined by over a finite field .
  • Discrete Logarithm Problem (ECDLP): Hard to compute given , where is a base point.
  • Key Generation:
    1. Choose a curve and base point .
    2. Pick a private key (random integer).
    3. Public key (scalar multiplication).

ECC vs. RSA: Comparison

Feature RSA ECC
Key Size (bits) 2048–4096 256–521
Security Level 2048 ≈ 112-bit security 256 ≈ 128-bit security
Speed Slower (modular exponentiation) Faster (scalar multiplication)
Bandwidth Higher (larger keys) Lower (smaller keys)
Use Cases TLS, PGP, SSH Mobile apps, IoT, blockchain

Why ECC?

  • Mobile Devices: Pathao’s driver-app uses ECC for lightweight authentication.
  • IoT: Smart meters in Kathmandu use ECC to secure communications with low power.
  • Blockchain: Bitcoin’s secp256k1 curve is an ECC variant.

3. Digital Signatures: Proving Authenticity

Digital signatures bind a message to a signer’s identity using asymmetric cryptography. Two main approaches:

  1. RSA-Based Signatures:
    • Sign: (private key).
    • Verify: . If , signature is valid.
  2. DSS (Digital Signature Standard):
    • Uses DSA (Digital Signature Algorithm) or ECDSA (Elliptic Curve DSA).
    • More efficient for large messages.
Message (m)Original dataHash (H(m))Fixed-length digestPrivate Key (SK)Signer’s secretSignature (S)Verifiable proof
Digital signature process: Hashing + private key = unforgeable proof

How DSS Works (DSA)

  1. Key Generation:
    • Choose a prime , subgroup generator , and hash function (e.g., SHA-256).
    • Pick private key , compute public key .
  2. Signing:
    • Hash message to get .
    • Pick random , compute: , .
  3. Verification:
    • Compute , , , .
    • If , signature is valid.

Real-World Example: WhatsApp Messages

  • When you send a message on WhatsApp:
    1. Your device signs the message with your private key (ECDSA).
    2. The recipient’s device verifies the signature using your public key (from WhatsApp’s server).
    3. If verification fails, the message is flagged as tampered or spoofed.

4. Security Considerations

Threat RSA ECC Mitigation
Brute Force Factor Solve ECDLP Use large keys (2048+ bits RSA, 256+ ECC)
Side-Channel Timing attacks Power analysis Constant-time implementations
Key Leakage Private key exposure Private key exposure Hardware Security Modules (HSMs)
Quantum Risk Shor’s algorithm breaks it Shor’s algorithm breaks it Post-quantum algorithms (e.g., lattice-based)

Exam Tip: Always mention key size and mathematical hardness when discussing security!


5. Playfair and Vernam Ciphers (Bonus: Symmetric Context)

While not asymmetric, these are often confused in exams:

  • Playfair Cipher:

    • Uses a 5×5 matrix and digraphs (pairs of letters).
    • Confusion: Substitutes letters; Diffusion: Shuffles positions.
    • Example: Encrypt "TRIBHUVAN" with key "BES":
      1. Create matrix with key "BES" + fill remaining letters (skip 'J').
      2. Split message into digraphs: TR IB HU VA NN (pad with 'X' if odd).
      3. Encrypt each pair (e.g., "TR" → "BO", "IB" → "QM").
  • Vernam Cipher:

    • One-time pad (perfect secrecy if key is truly random and never reused).
    • XOR message with key: , .

Exam Tip: How to Score Full Marks

  1. For RSA/ECC Questions:

    • Always show all steps of key generation (p, q, n, φ(n), e, d).
    • Use modular arithmetic explicitly (e.g., ).
    • For decryption, explain modular exponentiation (square-and-multiply).
  2. For Digital Signatures:

    • Draw a signature process diagram (signer → hash → sign → verify).
    • Compare RSA vs. DSS in a table (speed, key size, use cases).
  3. Common Pitfalls:

    • Forgetting to reduce modulo n in RSA operations.
    • Miscomputing φ(n) as instead of .
    • Ignoring padding schemes (e.g., OAEP for RSA) in real-world use.
  4. Past Exam Patterns:

    • 5-mark questions: Key generation + encryption/decryption (show all steps).
    • 2-mark questions: Define terms (e.g., "What is a digital signature?" → "A mathematical scheme to verify authenticity and integrity using private/public keys").
    • 3-mark questions: Compare algorithms (e.g., RSA vs. ECC) or explain a concept (e.g., "Why is ECDLP hard?").

Final Note: Asymmetric cryptography is the backbone of secure communications today. Master RSA’s math, understand ECC’s efficiency, and always relate digital signatures to real-world trust (e.g., eSewa, Ncell, or WhatsApp). Practice with small primes (like p=5, q=19) to grasp the mechanics before tackling larger keys.

In the real world

  • eSewa/Khalti Payments: Uses RSA encryption to secure transaction data between user devices and servers, and RSA digital signatures to authenticate payment requests (preventing spoofing).
  • Ncell SIM Authentication: Stores an RSA private key on the SIM card to authenticate calls/data requests; the network verifies using the public key stored in its database.
  • WhatsApp End-to-End Encryption: Relies on ECDSA digital signatures to prove messages originate from the claimed sender (visible in the '✓ Verified' badge).

Based on the TU BCA syllabus for Information Security (CACS459), unit 4.

Discussion

Loading…