Information SecurityUnit 27 min read
Cryptography Basics: Ciphers, Keys, and Security Principles
Unit 2 of Information Security introduces core cryptography concepts—classical and modern ciphers, key types, encryption/decryption processes, and security principles—with real-world examples from Nepalese apps (eSewa, Khalti) and global tech (WhatsApp, NEPSE).
TAKEAWAYS:
- Cryptography transforms data to protect confidentiality, integrity, and authenticity using ciphers and keys.
- Symmetric (shared-key) vs. asymmetric (public-key) encryption differ in key management and performance.
- Substitution and transposition ciphers are classical but flawed; modern systems use block (AES) and stream ciphers.
- Kerckhoffs’s principle and work factor define security assumptions and attacker resistance.
- Diffie-Hellman enables secure key exchange without pre-shared secrets (used in WhatsApp’s end-to-end encryption).
- Brute-force attacks and frequency analysis exploit weak keys or patterns in ciphertext.
1. What Is Cryptography?
Cryptography is the science of securing information by converting plaintext (readable data) into ciphertext (unreadable data) using mathematical algorithms and keys. Its goals are:
- Confidentiality: Only authorized parties can read the data.
- Integrity: Data cannot be altered undetectably.
- Authentication: Verify the sender’s identity.
- Non-repudiation: Prevent the sender from denying they sent the message.
2. Core Concepts: Ciphers and Keys
A. Ciphers: The Transformation Rules
A cipher is an algorithm that performs encryption/decryption. Two main types:
- Substitution Ciphers: Replace units (letters, bits) with others.
- Example: Caesar cipher shifts letters by 3 (
A→D,B→E). - Weakness: Vulnerable to frequency analysis (e.g.,
Eis most common in English).
- Example: Caesar cipher shifts letters by 3 (
- Transposition Ciphers: Rearrange units without substitution.
- Example: Rail fence cipher writes text in zigzag patterns.
- Weakness: Pattern repeats reveal the original order.
B. Keys: The Secret Ingredient
- A key is a value that controls the cipher’s operation.
- Symmetric key: Same key encrypts/decrypts (e.g., AES-128).
- Asymmetric key: Public key encrypts, private key decrypts (e.g., RSA).
- Key space: All possible key values (e.g., 2¹²⁸ for AES-128).
- Work factor: Effort required to break the cipher (higher = more secure).
3. Classical vs. Modern Cryptography
| Feature | Classical Ciphers | Modern Cryptography |
|---|---|---|
| Key Type | Symmetric only | Symmetric and asymmetric |
| Security | Weak (frequency analysis) | Strong (mathematical hardness) |
| Example | Caesar, Vigenère, Enigma | AES, RSA, SHA-256 |
| Use Case | Historical messages | Banking (Khalti), Messaging (WhatsApp) |
Real-World Tie-In:
- eSewa uses TLS (Transport Layer Security), which relies on asymmetric keys (RSA) for secure login and symmetric keys (AES) for encrypting transaction data.
- NEPSE (Nepal Stock Exchange) secures trades with hash functions (SHA-256) to detect tampering in order books.
4. Security Principles
A. Kerckhoffs’s Principle
"A cryptosystem should be secure even if everything about it is public except the key."
- Implication: Security depends on key secrecy, not algorithm secrecy.
- Example: AES is open-source, but its 256-bit keys are hard to crack.
B. Work Factor and Attack Models
| Attack Type | Description | Example |
|---|---|---|
| Brute Force | Try all possible keys | Cracking a 4-digit PIN (10⁴ attempts) |
| Frequency Analysis | Exploit language patterns | Breaking Caesar cipher |
| Differential Crypto | Study cipher’s behavior with inputs | Attacking DES’s S-boxes |
Worked Example: A bank uses a 3-DES cipher (112-bit effective key) for ATM PINs. How many attempts would a brute-force attack need?
- Key space: 2¹¹² ≈ 5.2 × 10³³ attempts.
- Real-world limit: Modern GPUs try ~10¹² keys/second → 5.2 × 10²¹ seconds (1.66 × 10¹⁴ years).
- Conclusion: 3-DES is secure against brute force but slow; banks now use AES-256.
5. Real-World Applications
A. WhatsApp’s End-to-End Encryption
- Uses Signal Protocol, combining:
- Diffie-Hellman key exchange to generate a shared symmetric key.
- AES-256 to encrypt messages.
- SHA-256 for message authentication.
- Why it matters: Even WhatsApp servers can’t read your messages.
B. Khalti’s Secure Transactions
- Step 1: User’s device generates an ephemeral RSA key pair (public/private).
- Step 2: Khalti’s server encrypts a session key with the user’s public key.
- Step 3: AES encrypts the transaction data with the session key.
- Result: No single point of failure for the key.
C. Daraz’s Order Processing
- Problem: Queues for order fulfillment are vulnerable to replay attacks (duplicate orders).
- Solution: Each order gets a unique nonce (number used once) + HMAC-SHA256 hash.
- How it works:
sequenceDiagram Customer->>Daraz: Order + Nonce Daraz->>Database: Store (Order, Nonce, HMAC) Daraz-->>Customer: "Order confirmed (ID: XYZ)" Hacker->>Daraz: Replay (Order, Nonce) Daraz-->>Hacker: "Rejected (HMAC mismatch)"
6. Common Pitfalls and Best Practices
| Mistake | Risk | Fix |
|---|---|---|
| Using weak keys (e.g., 64-bit DES) | Brute-force attacks | Use AES-128/256 or RSA-2048+ |
| Reusing keys | Compromises past communications | Ephemeral keys (e.g., Signal Protocol) |
| Ignoring padding | Vulnerable to padding oracle attacks | Use PKCS#7 or OAEP padding |
| Storing keys in plaintext | Leaks via data breaches | Hardware Security Modules (HSMs) |
Exam Tip:
- Always compare symmetric vs. asymmetric cryptography in tables (speed vs. key management).
- Trace a cipher’s steps (e.g., DES rounds) with a small example (e.g., encrypt "HELLO" with a toy cipher).
- Link real-world systems to principles (e.g., "Khalti uses RSA for authentication because...").
Exam Tip:
- Define clearly: Start answers with "Cryptography is..." or "A cipher is...".
- Draw diagrams: For DES rounds, show:
- Initial Permutation (IP) → 16 rounds → Final Permutation (FP).
- Sub-Key generation: PC-1 → Left/Right shifts → PC-2.
- Calculate key spaces: For a 6-bit key, space = 2⁶ = 64.
- Contrast classical/modern: Use a table or Venn diagram for overlaps (e.g., both use substitution).
- Use Nepalese examples:
- "NTC secures fiber-optic backhaul with AES-128 to prevent eavesdropping."
- "Pathao’s driver app uses HMAC to verify ride requests aren’t tampered with."
Based on the TU BIT syllabus for Information Security (BIT303), unit 2.
Discussion
Loading…