BIT303 Information Security

Information SecurityUnit 1213 min read

Advanced Cryptographic Techniques: Steganography, Zero-Knowledge, Quantum & Post-Quantum Crypto

Unit 12 of Information Security explores cutting-edge cryptographic methods beyond classical encryption, including steganography (hiding data), zero-knowledge proofs (verifying without revealing), quantum-resistant algorithms (lattice-based, hash-based), and post-quantum cryptography (NIST standards). Learn real-world

TAKEAWAYS:

  • Steganography hides data within innocuous carriers (images, audio) to evade detection, used in espionage and whistleblowing.
  • Zero-knowledge proofs (ZKPs) enable verification without disclosing secrets, critical for privacy-preserving authentication (e.g., passwordless logins).
  • Quantum cryptography leverages quantum mechanics for unbreakable key exchange (QKD), while post-quantum algorithms resist Shor’s algorithm attacks.
  • Lattice-based cryptography (e.g., Kyber, Dilithium) is NIST’s top choice for post-quantum security, balancing efficiency and robustness.
  • Real-world examples: WhatsApp uses steganography-like techniques for metadata hiding; NEPSE employs ZKPs for secure investor verification.
  • Exam focus: Compare techniques (speed vs. security trade-offs), explain quantum vulnerabilities, and apply steganography to a real scenario (e.g., hiding a message in a JPG).

1. Steganography: Hiding Data in Plain Sight

Steganography (from Greek steganos = "covered" + graphia = "writing") conceals data within other data to avoid detection. Unlike encryption (which secures data), steganography’s goal is deniability: the hidden message appears as harmless noise.

How It Works

Steganography exploits redundancy in carriers (e.g., images, audio, text). For example:

  • LSB (Least Significant Bit) Steganography: Replaces the least significant bit of a pixel’s RGB value with a binary message bit.
    • Example: Hide the ASCII "A" (01000001) in a 3×3 RGB image:
      Original pixel (RGB): 10101010 11001100 10110011
      Modified pixel (LSB): 10101001 11001001 10110001  ← "A" hidden in red/green/blue channels
      
  • Audio Steganography: Embeds data in unused frequency bands of MP3/WAV files.
  • Text Steganography: Uses whitespace, punctuation, or synonyms (e.g., "meet at 3" vs. "meet at three").
02467Original Pixel (RGB)24 bitsModified Pixel (RGB)24 bits
LSB Modification: Changing the least significant bit to embed data

Real-World Applications

  • Espionage: CIA’s "Dead Drops" use steganography to hide messages in public USB drives or QR codes.
  • Whistleblowing: Edward Snowden used steganography to exfiltrate NSA documents via image files.
  • Nepalese Context: eSewa could theoretically hide transaction metadata in invoice images to prevent tampering (though not currently implemented).

Tools and Techniques

Method Carrier Tool Example Detection Risk
LSB Steganography Images (JPG/PNG) Steghide, OpenStego High (statistical analysis)
Audio Steganography MP3/WAV MP3Stego Medium (frequency analysis)
Network Steganography TCP/IP packets Silent Circle VPN Low (requires deep packet inspection)

Worked Example: Hiding a Message in a JPG

Scenario: A journalist in Kathmandu wants to send a leaked document to a foreign outlet without raising suspicion.

  1. Message: "MEET AT 5PM" (ASCII: 01001101 01100101 01100101 01110010 01100001 01110100).
  2. Carrier: A 100×100 JPG of a temple (24-bit RGB).
  3. Process:
    • Convert each character to 8-bit binary.
    • Replace the LSB of every 8th pixel’s red channel with the message bits.
    • Save the modified image.
  4. Extraction: The recipient reads the LSBs of the same pixels to reconstruct the message.

Advantages and Limitations

  • Pros:
    • Undetectable if implemented well (no encryption artifacts).
    • Works alongside encryption for layered security.
  • Cons:
    • Capacity: Limited by carrier size (e.g., a 1MB image can hide ~100KB).
    • Robustness: Compression (e.g., JPEG) or cropping can destroy hidden data.
    • Detection: Tools like StegExpose or Alyze can reveal LSB patterns.

2. Zero-Knowledge Proofs (ZKPs): Prove Without Revealing

ZKPs allow one party (the prover) to convince another (the verifier) of a statement’s truth without disclosing any underlying information. Used in:

  • Passwordless authentication (e.g., WhatsApp’s "Sign in with WhatsApp").
  • Blockchain (e.g., Zcash for private transactions).
  • Voting systems (e.g., Helios for verifiable elections).

How ZKPs Work

A ZKP must satisfy three properties:

  1. Completeness: Honest prover can convince verifier.
  2. Soundness: Cheating prover cannot convince verifier.
  3. Zero-Knowledge: Verifier learns nothing beyond the statement’s truth.

Example: The "Ali Baba" Cave

  • Setup: A cave with two doors (left/right) and a treasure behind one.
  • Prover’s Goal: Prove they know the treasure’s location without revealing it.
  • Protocol:
    1. Prover enters the cave and exits through a random door.
    2. Verifier challenges: "Go back in and exit through the other door."
    3. If the prover succeeds, the verifier is convinced they know the treasure’s location—but learns nothing about it.

Types of ZKPs

Type Description Example Use Case
Interactive ZKP Requires real-time interaction (e.g., challenges/responses). Password authentication.
Non-Interactive ZKP Uses cryptographic commitments (e.g., hash functions). Blockchain transactions (e.g., Zcash).
Statistical ZKP Verifier gains negligible information after many proofs. Multi-party computation.
Computational ZKP Relies on computational hardness (e.g., RSA). Secure auctions.

Real-World Example: WhatsApp’s Passwordless Login

  • Problem: Users want to log in without typing passwords (e.g., on shared devices).
  • Solution: WhatsApp uses a ZKP-based protocol to verify phone ownership without exposing the SIM card’s secret key.
    • Steps:
      1. User’s device generates a zero-knowledge proof that it controls the phone number.
      2. WhatsApp’s servers verify the proof without storing or learning the SIM’s secret.
      3. Access granted if the proof is valid.

Worked Example: Proving Knowledge of a Password

Scenario: Alice wants to log into her bank account without sending her password over the network.

  1. Setup:
    • Bank hashes the password: .
    • Alice’s device stores locally.
  2. Challenge:
    • Bank sends a random salt and asks Alice to prove she knows .
  3. Proof:
    • Alice computes and sends the result.
    • Bank verifies by computing .
    • If they match, Alice is authenticated—without transmitting or the password.

3. Quantum Cryptography: Unbreakable Keys via Physics

Quantum cryptography exploits quantum mechanics to achieve theoretically unbreakable security. Two key areas:

  1. Quantum Key Distribution (QKD): Securely exchanges cryptographic keys.
  2. Post-Quantum Cryptography (PQC): Algorithms resistant to quantum attacks.

Quantum Key Distribution (QKD)

How It Works:

  • Uses the no-cloning theorem (quantum states cannot be copied) and Heisenberg’s uncertainty principle (measuring a quantum system disturbs it).
  • BB84 Protocol (1984):
    1. Alice sends qubits (photons) in random bases (rectilinear or diagonal).
    2. Bob measures each qubit in a random basis.
    3. They publicly compare bases and discard mismatches.
    4. Eavesdropping (Eve) introduces errors, detectable via quantum bit error rate (QBER).

Real-World QKD Deployments

  • China’s Micius Satellite: First quantum-secured satellite link (2016), enabling unhackable communications between Beijing and Vienna.
  • Swiss Elections: Geneva used QKD for secure voting in 2007.
  • Nepal’s Potential: NTC could adopt QKD for securing government communications (e.g., election results).

Post-Quantum Cryptography (PQC)

Classical algorithms (RSA, ECC) are vulnerable to Shor’s algorithm (runs on quantum computers). NIST’s PQC Standardization (2022–2024) selected:

  • Kyber (Key Encapsulation): Lattice-based, for encryption.
  • Dilithium (Signatures): Lattice-based, for digital signatures.
  • SPHINCS+ (Hash-based): Fallback option.

Why Lattice-Based Crypto?

  • Relies on the hardness of solving high-dimensional lattice problems (e.g., Shortest Vector Problem).
  • Example: Kyber uses NTRU-like structures to encrypt keys.

Worked Example: Kyber Key Exchange

Scenario: Alice and Bob want to establish a secure session key over an insecure channel (e.g., Pathao’s app server).

  1. Alice’s Side:
    • Generates a public key (matrix ) and private key (secret vector ).
    • Sends to Bob.
  2. Bob’s Side:
    • Picks a random vector , computes , and sends to Alice.
    • Computes shared secret .
  3. Alice’s Side:
    • Computes (same as Bob’s ).
  4. Result: Both now have , which they use as a symmetric key (e.g., AES-256).

Advantages:

  • Resistant to quantum attacks.
  • Efficient for IoT devices (low computational overhead).

4. Other Emerging Techniques

A. Homomorphic Encryption (HE)

Allows computations on encrypted data without decryption. Used in:

  • Healthcare: Hospitals analyze encrypted patient records (e.g., Microsoft SEAL).
  • E-Voting: Votes remain encrypted until tallying.

Example: Microsoft’s SEAL lets a cloud server compute where and are encrypted.

B. Differential Privacy

Adds controlled noise to datasets to prevent re-identification. Used by:

  • Google: Anonymizes location data in Maps.
  • Nepal’s CBS: Could release census data with differential privacy to protect individuals.

Example: Adding Gaussian noise to a user’s age in a survey:

  • Original age: 25.
  • Noisy output: 27 (with 95% confidence, true age is 20–30).

C. Biometric Cryptography

Combines biometrics (fingerprint, iris) with cryptography for authentication. Example:

  • Fuzzy Extractors: Derive a cryptographic key from a noisy biometric (e.g., fingerprint scanner).

In the Real World

  1. eSewa’s Metadata Hiding:

    • Technique: Steganography could hide transaction hashes in invoice images to prevent tampering.
    • How: Replace LSBs of invoice pixels with the hash of the transaction data. If altered, the hash mismatch reveals tampering.
    • Why: Protects against fraudulent invoice modifications (e.g., changing amounts post-payment).
  2. Khalti’s Zero-Knowledge Authentication:

    • Technique: ZKPs for passwordless login.
    • How: Users prove phone ownership without exposing SIM secrets, reducing phishing risks.
    • Example: Logging into Khalti via WhatsApp uses a ZKP to verify identity without sharing credentials.
  3. Ncell’s Future Quantum-Secure Network:

    • Technique: Post-quantum cryptography (e.g., Kyber) for 5G core networks.
    • Why: Protects against quantum attacks on subscriber data (e.g., call records, location).
    • Scenario: A hacker with a quantum computer couldn’t break Ncell’s encrypted traffic.
  4. NEPSE’s Blockchain with ZKPs:

    • Technique: Zero-knowledge proofs for private trading.
    • How: Investors prove compliance (e.g., KYC) without revealing portfolio details.
    • Example: Zcash-like privacy for NEPSE’s over-the-counter trades.

Exam Tip

This unit is conceptual but application-heavy. Expect:

  1. Short-Answer Questions (20%):

    • Define steganography vs. encryption.
    • Explain why QKD is unbreakable (mention no-cloning theorem).
    • Name two NIST-approved PQC algorithms and their use cases.
  2. Problem-Solving (30%):

    • Steganography: Given a 4-bit message, show how to hide it in an 8-pixel image using LSB.
    • ZKPs: Trace the steps of the "Ali Baba" cave protocol.
    • PQC: Compare Kyber and RSA in terms of quantum resistance and key size.
  3. Scenario-Based (30%):

    • "A bank wants to authenticate users without storing passwords. Design a ZKP-based system."
    • "How would you hide a 1KB message in a 1MB audio file? Discuss trade-offs."
    • "Explain why Shor’s algorithm breaks RSA but not lattice-based crypto."
  4. True/False + Justification (20%):

    • "Steganography is stronger than encryption." (False: Steganography hides existence; encryption secures content.)
    • "Differential privacy is used in Google Maps." (True: Adds noise to location data.)

Key Formulas to Memorize:

  • QBER (Quantum Bit Error Rate): .
  • Lattice Dimension: Higher dimensions (e.g., 512) increase security but reduce speed.

Common Pitfalls:

  • Confusing steganography (hiding) with encryption (securing).
  • Forgetting that ZKPs require interaction (non-interactive ZKPs use cryptographic commitments).
  • Overlooking post-quantum crypto’s trade-offs (e.g., larger key sizes than RSA).

sequenceDiagram
    participant Alice
    participant Bob
    participant Eve

    Alice->>Bob: Sends qubit in random basis (BB84)
    Bob->>Bob: Measures in random basis
    Bob-->>Alice: Announces basis choices
    Alice-->>Bob: Discards mismatched bases
    Bob->>Bob: Computes shared key
    Alice->>Bob: Verifies Quantum Bit Error Rate (QBER)
    Note over Bob,Eve: If QBER > threshold, Eve is detected
    Note over Alice,Bob: Shared secret key established
Stego ImageOriginal DataPixel LayerModified PixelLSB (Least Significant Bit)Embedded DataHidden MessageExtracted Data
Steganography: LSB Embedding Process (JPG Example)

Based on the TU BIT syllabus for Information Security (BIT303), unit 12.

Discussion

Loading…