Information SecurityUnit 313 min read
Classical Cryptography: Ciphers, Codes & Steganography
Unit 3 of Information Security explores the foundations of cryptography—substitution ciphers (Caesar, Vigenère), transposition methods, steganography, and their mathematical underpinnings—with real-world examples from eSewa’s transaction logs and Ncell’s SMS-based authentication.
TAKEAWAYS:
- Classical ciphers rely on substitution (replacing symbols) or transposition (rearranging symbols) to obscure messages, with Caesar and Vigenère being the most studied.
- Polyalphabetic ciphers (like Vigenère) break single-letter frequency analysis by using multiple substitution keys, but Kasiski’s test can expose their periodicity.
- Steganography hides messages within innocuous carriers (images, audio) by altering least significant bits (LSB)—unlike cryptography, it denies the existence of a secret message.
- Kerckhoffs’s principle states that a cipher’s security must rely on the key, not secrecy of the algorithm (e.g., Caesar cipher’s shift value).
- Worked examples tie to real scenarios: encoding an eSewa transaction PIN (Caesar), masking a Khalti OTP in an image (steganography), or analyzing Ncell’s SMS routing (transposition).
- Weaknesses of classical ciphers (frequency analysis, brute-force attacks) led to modern cryptography, but they remain foundational for understanding key distribution and authentication.
1. Introduction to Classical Cryptography
Classical cryptography predates computers and relies on manual methods to conceal messages. It is divided into two main categories:
- Ciphers: Transform plaintext into ciphertext using reversible algorithms (e.g., Caesar cipher).
- Codes: Replace words/symbols with predefined substitutes (e.g., military codes).
Why study classical ciphers? They teach core principles like confusion (hiding relationships between plaintext and ciphertext) and diffusion (spreading statistical properties). Modern cryptography builds on these ideas but uses computational hardness (e.g., RSA, AES).
2. Substitution Ciphers
Substitution ciphers replace each symbol (letter, digit) in the plaintext with another symbol. They are classified as:
- Monalphabetic: Single substitution table (e.g., Caesar cipher).
- Polyalphabetic: Multiple substitution tables (e.g., Vigenère cipher).
2.1 Caesar Cipher
How it works:
- Shifts each letter in the plaintext by a fixed number (
k) down the alphabet. - Example:
k=3,A→D,B→E, ...,Z→C.
Mathematical representation:
For a plaintext letter P and ciphertext C:
Worked Example: eSewa PIN Encoding
Suppose eSewa uses a Caesar cipher with k=5 to encode a 4-digit PIN for internal logs.
- Plaintext PIN:
1234 - Convert digits to letters (A=0, B=1, ..., I=8, J=9):
1→B,2→C,3→D,4→E→ Plaintext:BCDE - Apply
k=5:B→G,C→H,D→I,E→J→ Ciphertext:GHIJ - Final encoded PIN:
6789(G=6, H=7, I=8, J=9).
Weaknesses:
- Frequency analysis: Letters like
Ein English appear most often. An attacker can guesskby comparing ciphertext frequencies to known plaintext statistics. - Brute-force: Only 25 possible keys (
k=1to25).
stateDiagram-v2
[*] --> Plaintext: "BCDE"
Plaintext: "BCDE" --> CaesarShift: "Shift +5"
CaesarShift --> Ciphertext: "GHIJ"
Ciphertext: "GHIJ" --> Decrypt: "Shift -5"
Decrypt --> [*]2.2 Vigenère Cipher
How it works:
- Uses a keyword to generate multiple Caesar shifts.
- For each plaintext letter, the shift value is the corresponding keyword letter’s position (A=0, B=1, etc.).
- Example: Keyword =
KEY, Plaintext =ATTACKATDAWNAlign keyword repeatedly:KEYKEYKEYKEYKShifts:K=10,E=4,Y=24→ Apply to each plaintext letter.
Mathematical representation:
For plaintext P_i and key K_i:
Worked Example: Khalti OTP Masking Khalti might use a Vigenère cipher to obscure OTPs in transit.
- Plaintext OTP:
73852 - Convert to letters:
7→H,3→D,8→I,5→F,2→C→HDIFC - Keyword:
KHAL(repeated:KHALKHALKH) - Shifts:
K=10,H=7,A=0,L=11 - Ciphertext:
H(7) + K(10) = QD(3) + H(7) = KI(8) + A(0) = IF(5) + L(11) = QC(2) + K(10) = M - Encoded OTP:
QKIQM
Advantages over Caesar:
- Resists frequency analysis because the same plaintext letter may encrypt to different ciphertext letters (e.g.,
Acould becomeK,Q, orIdepending on the key).
Weaknesses:
- Kasiski’s test: Repeated sequences in ciphertext reveal the keyword length.
- Brute-force: Still vulnerable if the key is short.
3. Transposition Ciphers
Transposition ciphers rearrange symbols without substitution. They preserve letter frequencies but obscure word order.
3.1 Rail Fence Cipher
How it works:
- Write plaintext in a zigzag pattern across a fixed number of "rails," then read row by row.
- Example (2 rails):
A T T A C K A T D A W N→ Rail 1:A T A A D NRail 2:T C K T WCiphertext:ATAA DNTK TW(spaces removed:ATAADNTKTW).
Worked Example: Ncell SMS Routing Ncell’s SMS center might use a transposition cipher to shuffle digits in routing headers to prevent eavesdropping.
- Plaintext routing code:
1234567890 - 3-rail cipher:
Rail 1:
1 3 5 7 9Rail 2:2 4 6 8Rail 3:0Ciphertext:1357924680
Advantages:
- No substitution → harder to break with frequency analysis.
- Simple to implement manually.
Weaknesses:
- Pattern recognition: If the number of rails is known, the ciphertext can be reconstructed.
- No confusion: Letter frequencies remain unchanged.
3.2 Columnar Transposition
How it works:
- Write plaintext in rows of a fixed length, then read columns in a permuted order.
- Example: Keyword
LEMON(length 5) for plaintextCRYPTOGRAPHY: Fill a 5×2 grid:
Column order:C R Y P T O G R A P H YL(4), E(4), M(12), O(14), N(13)→4,4,1,1,3→ Read columns 4,4,1,1,3:P, T, C, O, Y, R, G, A, P, H.
Worked Example: Daraz Order Queue Daraz might use columnar transposition to shuffle order IDs in a database to hide high-value transactions.
- Plaintext order IDs:
ORD123 ORD456 ORD789 - Keyword:
DARAZ(length 5) - Fill a 5×3 grid:
Column order:O R D 1 2 3 O R D 4 5 6 O R D 7 8 9D(3), A(0), R(17), Z(25), A(0)→3,0,1,4,0→ Read columns 3,0,1,4,0:1, O, R, 7, O→1ORD7 O4RD2 3ORD8 9(reconstructed as1ORD7O4RD23ORD89).
4. Steganography: Hiding in Plain Sight
Steganography conceals messages within other data (images, audio, text) so the message’s existence is denied. Unlike cryptography, it does not encrypt—it hides.
4.1 Least Significant Bit (LSB) Method
How it works:
- Replace the least significant bit (LSB) of a carrier’s pixels/bytes with message bits.
- Example: Hide
101(binary for5) in a 24-bit RGB pixel: Original pixel:RGB(100, 150, 200)Binary:R: 1100100G: 10010110B: 11001000Replace LSBs with101000(padded):R: 110010**1**G: 100101**0**0B: 110010**0**0New pixel:RGB(101, 152, 200)(visually identical).
Worked Example: Ncell Image OTP Ncell could embed a 6-digit OTP in a profile picture sent to users.
- OTP:
123456→ Binary:0001 0010 0011 0100 0101 0110 - Hide in LSBs of 6 pixels in an image.
Advantages:
- Undetectable to casual inspection.
- No encryption needed if the carrier is trusted.
Weaknesses:
- Compression: JPEG/PNG compression may destroy hidden data.
- Statistical analysis: LSB changes can be detected with chi-square tests.
4.2 Other Steganography Techniques
| Method | Carrier | Example Use Case |
|---|---|---|
| Audio LSB | MP3/WAV files | Hiding messages in Ncell ringtone files. |
| Text steganography | Whitespace, punctuation | "Meet me at 7AM" → "Meet me at** **7AM". |
| Protocol steganography | HTTP headers | Embedding data in unused header fields. |
5. Cryptanalysis: Breaking Classical Ciphers
Cryptanalysis exploits weaknesses in ciphers to recover plaintext. Key techniques:
5.1 Frequency Analysis
- How it works: Count letter frequencies in ciphertext and compare to known plaintext statistics (e.g.,
Eis most common in English). - Example: In a Caesar cipher, the most frequent ciphertext letter likely decrypts to
E.
Worked Example: Breaking a Caesar Cipher
Ciphertext: HZHUWXUH
- Count frequencies:
H=2,Z=1,U=2,W=1,X=1. - Assume English:
Eis most frequent (12.7%).Happears twice → likelyEorT. - Try
H→E(k=5):CDECDQCD→ Nonsense. - Try
H→T(k=19):ATTACKAT→ Valid plaintext!
5.2 Kasiski’s Test
- How it works: Identify repeated sequences in ciphertext to deduce the keyword length in polyalphabetic ciphers.
- Steps:
- Find repeated sequences (e.g.,
XUHappears at positions 1 and 7). - Calculate distances between sequences:
7-1=6→ possible keyword length. - Test divisors of the distance (e.g., 6 → possible lengths: 1, 2, 3, 6).
- Find repeated sequences (e.g.,
6. Kerckhoffs’s Principle and Modern Relevance
Kerckhoffs’s Principle (1883):
"A cryptosystem should be secure even if everything about the system, except the key, is public."
Implications:
- Classical ciphers fail this principle because their algorithms are easily broken (e.g., Caesar cipher’s shift is guessable).
- Modern cryptography (AES, RSA) relies on computational hardness (e.g., factoring large primes).
Real-World Tie-In:
- eSewa’s transaction logs use modern encryption (TLS), but understanding classical ciphers helps explain why key management is critical.
- Ncell’s SMS authentication combines OTPs with hashing (not classical ciphers), but steganography could hide OTPs in images to evade keyloggers.
In the Real World
eSewa Transaction Logs
- Idea Used: Caesar cipher (or stronger) to obscure temporary PINs in logs.
- How: A shifted version of the PIN is stored, and the actual PIN is derived only when needed. Attackers seeing logs would not immediately recognize the PINs.
Khalti OTP Delivery
- Idea Used: Vigenère cipher or steganography to mask OTPs in transit.
- How: If an OTP (
123456) is sent as an image, LSB steganography hides it in the image’s pixels. Even if intercepted, the OTP is invisible without extracting LSBs.
Ncell SMS Routing
- Idea Used: Transposition cipher to shuffle routing headers.
- How: SMS centers use columnar transposition to rearrange digits in routing codes, making it harder for attackers to correlate messages to specific users.
Daraz Order Processing
- Idea Used: Columnar transposition to obscure high-value order IDs.
- How: Orders for expensive items might have their IDs shuffled in databases, so even if a hacker accesses the database, the IDs are not in sequential order.
NEPSE Stock Alerts
- Idea Used: Steganography in audio files.
- How: Stock traders might hide price alerts in MP3 files (e.g., "Buy NTC at 100" embedded in the LSBs of a song), sent via WhatsApp to avoid detection by monitoring tools.
Exam Tip
Define and Differentiate:
- Always start by clearly defining substitution vs. transposition ciphers and cipher vs. code.
- Example answer starter:
"Classical cryptography includes substitution ciphers like Caesar, which replace symbols, and transposition ciphers like rail fence, which rearrange symbols. Unlike codes, which replace entire words, ciphers operate on individual symbols."
Worked Examples Are Mandatory:
- Examiners love step-by-step traces. For Caesar/Vigenère, show:
- Plaintext → Key → Ciphertext (with modular arithmetic).
- For transposition, draw the grid or rail fence.
- Pro Tip: Use Nepali words in examples (e.g., encode "सुरक्षा" in Caesar) to show cultural relevance.
- Examiners love step-by-step traces. For Caesar/Vigenère, show:
Weaknesses and Attacks:
- Link each cipher to its breaking method:
- Caesar → Frequency analysis.
- Vigenère → Kasiski’s test.
- Rail fence → Pattern recognition.
- Example:
"The Vigenère cipher’s security depends on the keyword length. If an attacker finds repeated sequences (e.g., 'XUH' appearing twice), they can apply Kasiski’s test to deduce the keyword length and then perform a known-plaintext attack."
- Link each cipher to its breaking method:
Steganography Tricks:
- Explain LSB method with a pixel example and mention compression resistance.
- Compare to cryptography:
"Unlike AES, which encrypts data, steganography hides data in plain sight. For example, hiding an OTP in an image’s LSBs ensures that even if the image is intercepted, the OTP is not detectable without specialized tools."
Real-World Applications:
- Tie examples to Nepali contexts (e.g., eSewa, Khalti, Ncell) to show practical relevance.
- Avoid generic answers like "used in military." Instead:
"Ncell could use a transposition cipher to shuffle SMS routing codes, making it harder for attackers to map users to specific messages."
Diagrams Save Marks:
- Draw rail fence grids, Vigenère tables, or LSB pixel examples. Label every step.
- For exams with diagram sections, sketch a Caesar shift wheel or a columnar transposition grid.
Common Pitfalls:
- Forgetting modular arithmetic: Always use
mod 26for letters. - Ignoring key length: Vigenère’s security hinges on the keyword length—mention this.
- Confusing steganography with encryption: Stress that steganography hides, while cryptography obscures.
- Forgetting modular arithmetic: Always use
Based on the TU BIM syllabus for Information Security (IT244), unit 3.
Discussion
Loading…