Information SecurityUnit 1213 min read
Advanced Cryptographic Techniques: Steganography, Zero-Knowledge, Quantum & Post-Quantum Crypto
Unit 12 of Information Security explores cutting-edge cryptographic methods beyond classical encryption, including steganography (hiding data), zero-knowledge proofs (verifying without revealing), quantum-resistant algorithms (lattice-based, hash-based), and post-quantum cryptography (NIST standards). Learn real-world
TAKEAWAYS:
- Steganography hides data within innocuous carriers (images, audio) to evade detection, used in espionage and whistleblowing.
- Zero-knowledge proofs (ZKPs) enable verification without disclosing secrets, critical for privacy-preserving authentication (e.g., passwordless logins).
- Quantum cryptography leverages quantum mechanics for unbreakable key exchange (QKD), while post-quantum algorithms resist Shor’s algorithm attacks.
- Lattice-based cryptography (e.g., Kyber, Dilithium) is NIST’s top choice for post-quantum security, balancing efficiency and robustness.
- Real-world examples: WhatsApp uses steganography-like techniques for metadata hiding; NEPSE employs ZKPs for secure investor verification.
- Exam focus: Compare techniques (speed vs. security trade-offs), explain quantum vulnerabilities, and apply steganography to a real scenario (e.g., hiding a message in a JPG).
1. Steganography: Hiding Data in Plain Sight
Steganography (from Greek steganos = "covered" + graphia = "writing") conceals data within other data to avoid detection. Unlike encryption (which secures data), steganography’s goal is deniability: the hidden message appears as harmless noise.
How It Works
Steganography exploits redundancy in carriers (e.g., images, audio, text). For example:
- LSB (Least Significant Bit) Steganography: Replaces the least significant bit of a pixel’s RGB value with a binary message bit.
- Example: Hide the ASCII "A" (01000001) in a 3×3 RGB image:
Original pixel (RGB): 10101010 11001100 10110011 Modified pixel (LSB): 10101001 11001001 10110001 ← "A" hidden in red/green/blue channels
- Example: Hide the ASCII "A" (01000001) in a 3×3 RGB image:
- Audio Steganography: Embeds data in unused frequency bands of MP3/WAV files.
- Text Steganography: Uses whitespace, punctuation, or synonyms (e.g., "meet at 3" vs. "meet at three").
Real-World Applications
- Espionage: CIA’s "Dead Drops" use steganography to hide messages in public USB drives or QR codes.
- Whistleblowing: Edward Snowden used steganography to exfiltrate NSA documents via image files.
- Nepalese Context: eSewa could theoretically hide transaction metadata in invoice images to prevent tampering (though not currently implemented).
Tools and Techniques
| Method | Carrier | Tool Example | Detection Risk |
|---|---|---|---|
| LSB Steganography | Images (JPG/PNG) | Steghide, OpenStego | High (statistical analysis) |
| Audio Steganography | MP3/WAV | MP3Stego | Medium (frequency analysis) |
| Network Steganography | TCP/IP packets | Silent Circle VPN | Low (requires deep packet inspection) |
Worked Example: Hiding a Message in a JPG
Scenario: A journalist in Kathmandu wants to send a leaked document to a foreign outlet without raising suspicion.
- Message: "MEET AT 5PM" (ASCII:
01001101 01100101 01100101 01110010 01100001 01110100). - Carrier: A 100×100 JPG of a temple (24-bit RGB).
- Process:
- Convert each character to 8-bit binary.
- Replace the LSB of every 8th pixel’s red channel with the message bits.
- Save the modified image.
- Extraction: The recipient reads the LSBs of the same pixels to reconstruct the message.
Advantages and Limitations
- Pros:
- Undetectable if implemented well (no encryption artifacts).
- Works alongside encryption for layered security.
- Cons:
- Capacity: Limited by carrier size (e.g., a 1MB image can hide ~100KB).
- Robustness: Compression (e.g., JPEG) or cropping can destroy hidden data.
- Detection: Tools like StegExpose or Alyze can reveal LSB patterns.
2. Zero-Knowledge Proofs (ZKPs): Prove Without Revealing
ZKPs allow one party (the prover) to convince another (the verifier) of a statement’s truth without disclosing any underlying information. Used in:
- Passwordless authentication (e.g., WhatsApp’s "Sign in with WhatsApp").
- Blockchain (e.g., Zcash for private transactions).
- Voting systems (e.g., Helios for verifiable elections).
How ZKPs Work
A ZKP must satisfy three properties:
- Completeness: Honest prover can convince verifier.
- Soundness: Cheating prover cannot convince verifier.
- Zero-Knowledge: Verifier learns nothing beyond the statement’s truth.
Example: The "Ali Baba" Cave
- Setup: A cave with two doors (left/right) and a treasure behind one.
- Prover’s Goal: Prove they know the treasure’s location without revealing it.
- Protocol:
- Prover enters the cave and exits through a random door.
- Verifier challenges: "Go back in and exit through the other door."
- If the prover succeeds, the verifier is convinced they know the treasure’s location—but learns nothing about it.
Types of ZKPs
| Type | Description | Example Use Case |
|---|---|---|
| Interactive ZKP | Requires real-time interaction (e.g., challenges/responses). | Password authentication. |
| Non-Interactive ZKP | Uses cryptographic commitments (e.g., hash functions). | Blockchain transactions (e.g., Zcash). |
| Statistical ZKP | Verifier gains negligible information after many proofs. | Multi-party computation. |
| Computational ZKP | Relies on computational hardness (e.g., RSA). | Secure auctions. |
Real-World Example: WhatsApp’s Passwordless Login
- Problem: Users want to log in without typing passwords (e.g., on shared devices).
- Solution: WhatsApp uses a ZKP-based protocol to verify phone ownership without exposing the SIM card’s secret key.
- Steps:
- User’s device generates a zero-knowledge proof that it controls the phone number.
- WhatsApp’s servers verify the proof without storing or learning the SIM’s secret.
- Access granted if the proof is valid.
- Steps:
Worked Example: Proving Knowledge of a Password
Scenario: Alice wants to log into her bank account without sending her password over the network.
- Setup:
- Bank hashes the password: .
- Alice’s device stores locally.
- Challenge:
- Bank sends a random salt and asks Alice to prove she knows .
- Proof:
- Alice computes and sends the result.
- Bank verifies by computing .
- If they match, Alice is authenticated—without transmitting or the password.
3. Quantum Cryptography: Unbreakable Keys via Physics
Quantum cryptography exploits quantum mechanics to achieve theoretically unbreakable security. Two key areas:
- Quantum Key Distribution (QKD): Securely exchanges cryptographic keys.
- Post-Quantum Cryptography (PQC): Algorithms resistant to quantum attacks.
Quantum Key Distribution (QKD)
How It Works:
- Uses the no-cloning theorem (quantum states cannot be copied) and Heisenberg’s uncertainty principle (measuring a quantum system disturbs it).
- BB84 Protocol (1984):
- Alice sends qubits (photons) in random bases (rectilinear or diagonal).
- Bob measures each qubit in a random basis.
- They publicly compare bases and discard mismatches.
- Eavesdropping (Eve) introduces errors, detectable via quantum bit error rate (QBER).
Real-World QKD Deployments
- China’s Micius Satellite: First quantum-secured satellite link (2016), enabling unhackable communications between Beijing and Vienna.
- Swiss Elections: Geneva used QKD for secure voting in 2007.
- Nepal’s Potential: NTC could adopt QKD for securing government communications (e.g., election results).
Post-Quantum Cryptography (PQC)
Classical algorithms (RSA, ECC) are vulnerable to Shor’s algorithm (runs on quantum computers). NIST’s PQC Standardization (2022–2024) selected:
- Kyber (Key Encapsulation): Lattice-based, for encryption.
- Dilithium (Signatures): Lattice-based, for digital signatures.
- SPHINCS+ (Hash-based): Fallback option.
Why Lattice-Based Crypto?
- Relies on the hardness of solving high-dimensional lattice problems (e.g., Shortest Vector Problem).
- Example: Kyber uses NTRU-like structures to encrypt keys.
Worked Example: Kyber Key Exchange
Scenario: Alice and Bob want to establish a secure session key over an insecure channel (e.g., Pathao’s app server).
- Alice’s Side:
- Generates a public key (matrix ) and private key (secret vector ).
- Sends to Bob.
- Bob’s Side:
- Picks a random vector , computes , and sends to Alice.
- Computes shared secret .
- Alice’s Side:
- Computes (same as Bob’s ).
- Result: Both now have , which they use as a symmetric key (e.g., AES-256).
Advantages:
- Resistant to quantum attacks.
- Efficient for IoT devices (low computational overhead).
4. Other Emerging Techniques
A. Homomorphic Encryption (HE)
Allows computations on encrypted data without decryption. Used in:
- Healthcare: Hospitals analyze encrypted patient records (e.g., Microsoft SEAL).
- E-Voting: Votes remain encrypted until tallying.
Example: Microsoft’s SEAL lets a cloud server compute where and are encrypted.
B. Differential Privacy
Adds controlled noise to datasets to prevent re-identification. Used by:
- Google: Anonymizes location data in Maps.
- Nepal’s CBS: Could release census data with differential privacy to protect individuals.
Example: Adding Gaussian noise to a user’s age in a survey:
- Original age: 25.
- Noisy output: 27 (with 95% confidence, true age is 20–30).
C. Biometric Cryptography
Combines biometrics (fingerprint, iris) with cryptography for authentication. Example:
- Fuzzy Extractors: Derive a cryptographic key from a noisy biometric (e.g., fingerprint scanner).
In the Real World
eSewa’s Metadata Hiding:
- Technique: Steganography could hide transaction hashes in invoice images to prevent tampering.
- How: Replace LSBs of invoice pixels with the hash of the transaction data. If altered, the hash mismatch reveals tampering.
- Why: Protects against fraudulent invoice modifications (e.g., changing amounts post-payment).
Khalti’s Zero-Knowledge Authentication:
- Technique: ZKPs for passwordless login.
- How: Users prove phone ownership without exposing SIM secrets, reducing phishing risks.
- Example: Logging into Khalti via WhatsApp uses a ZKP to verify identity without sharing credentials.
Ncell’s Future Quantum-Secure Network:
- Technique: Post-quantum cryptography (e.g., Kyber) for 5G core networks.
- Why: Protects against quantum attacks on subscriber data (e.g., call records, location).
- Scenario: A hacker with a quantum computer couldn’t break Ncell’s encrypted traffic.
NEPSE’s Blockchain with ZKPs:
- Technique: Zero-knowledge proofs for private trading.
- How: Investors prove compliance (e.g., KYC) without revealing portfolio details.
- Example: Zcash-like privacy for NEPSE’s over-the-counter trades.
Exam Tip
This unit is conceptual but application-heavy. Expect:
Short-Answer Questions (20%):
- Define steganography vs. encryption.
- Explain why QKD is unbreakable (mention no-cloning theorem).
- Name two NIST-approved PQC algorithms and their use cases.
Problem-Solving (30%):
- Steganography: Given a 4-bit message, show how to hide it in an 8-pixel image using LSB.
- ZKPs: Trace the steps of the "Ali Baba" cave protocol.
- PQC: Compare Kyber and RSA in terms of quantum resistance and key size.
Scenario-Based (30%):
- "A bank wants to authenticate users without storing passwords. Design a ZKP-based system."
- "How would you hide a 1KB message in a 1MB audio file? Discuss trade-offs."
- "Explain why Shor’s algorithm breaks RSA but not lattice-based crypto."
True/False + Justification (20%):
- "Steganography is stronger than encryption." (False: Steganography hides existence; encryption secures content.)
- "Differential privacy is used in Google Maps." (True: Adds noise to location data.)
Key Formulas to Memorize:
- QBER (Quantum Bit Error Rate): .
- Lattice Dimension: Higher dimensions (e.g., 512) increase security but reduce speed.
Common Pitfalls:
- Confusing steganography (hiding) with encryption (securing).
- Forgetting that ZKPs require interaction (non-interactive ZKPs use cryptographic commitments).
- Overlooking post-quantum crypto’s trade-offs (e.g., larger key sizes than RSA).
sequenceDiagram
participant Alice
participant Bob
participant Eve
Alice->>Bob: Sends qubit in random basis (BB84)
Bob->>Bob: Measures in random basis
Bob-->>Alice: Announces basis choices
Alice-->>Bob: Discards mismatched bases
Bob->>Bob: Computes shared key
Alice->>Bob: Verifies Quantum Bit Error Rate (QBER)
Note over Bob,Eve: If QBER > threshold, Eve is detected
Note over Alice,Bob: Shared secret key establishedBased on the TU BIT syllabus for Information Security (BIT303), unit 12.
Discussion
Loading…