Information SecurityUnit 311 min read
Symmetric Key Cryptography: DES, AES, and Block Ciphers
Unit 3 of Information Security explores symmetric key cryptography, focusing on Data Encryption Standard (DES), Advanced Encryption Standard (AES), and their operational principles, including block cipher modes, key generation, and security trade-offs. It covers how these algorithms secure data in real-world applicatio
TAKEAWAYS:
- Symmetric key cryptography uses the same key for encryption and decryption, offering speed but requiring secure key distribution.
- DES (56-bit key) and AES (128/192/256-bit keys) are block ciphers that process data in fixed-size chunks (64-bit for DES, 128-bit for AES).
- Substitution-permutation networks (SPNs) like DES use S-boxes and P-boxes to confuse and diffuse plaintext, while AES uses SubBytes, ShiftRows, MixColumns, and AddRoundKey.
- Key scheduling generates round keys dynamically (DES: 16 rounds; AES: 10/12/14 rounds) to resist brute-force attacks.
- Modes of operation (ECB, CBC, CFB, OFB, CTR) determine how block ciphers handle data streams, with CBC and GCM being widely used for authenticated encryption.
- Security trade-offs: AES is faster and more secure than DES but requires larger keys; DES is vulnerable to brute-force and differential cryptanalysis.
1. Introduction to Symmetric Key Cryptography
Symmetric key cryptography is a shared-secret encryption method where the same key is used for both encryption and decryption. It is faster than asymmetric cryptography but faces the key distribution problem (how to securely share the key).
Key Characteristics:
- Speed: Ideal for encrypting large datasets (e.g., files, databases).
- Key Size: Larger keys (e.g., 256-bit in AES) provide stronger security.
- Use Cases: Securing Wi-Fi (WPA2/WPA3), disk encryption (BitLocker), VPNs, and e-commerce transactions.
Real-World Example: eSewa and Khalti
- eSewa and Khalti use AES-256 to encrypt transaction data (e.g., card numbers, OTPs) before transmitting it to banks. This ensures that even if intercepted, the data remains unreadable without the shared key.
- How it works:
- Your phone generates a random AES key for the session.
- The key is encrypted with the merchant’s public key (RSA) and sent securely.
- The merchant decrypts the key with their private key and uses it to encrypt/decrypt messages with you.
2. Data Encryption Standard (DES)
DES is a block cipher that encrypts data in 64-bit blocks using a 56-bit key. It was the U.S. federal standard from 1977 to 2005 but is now considered insecure due to its small key size.
How DES Works: The Feistel Network
DES uses a 16-round Feistel structure, where each round applies:
- Expansion (E-box): Expands 32-bit input to 48 bits.
- Key Mixing (XOR): Combines with a 48-bit subkey.
- Substitution (S-boxes): 8 S-boxes replace 6-bit inputs with 4-bit outputs (non-linear confusion).
- Permutation (P-box): Reorders bits for diffusion.
- Final XOR: Combines with the other half of the block.
stateDiagram-v2
[*] --> DES_Start
DES_Start --> Initial_Permutation
Initial_Permutation --> Round_1
Round_1 --> Split_Block
Split_Block --> Feistel_Round
Feistel_Round --> Round_2
Round_2 --> Round_16
Round_16 --> Final_Permutation
Final_Permutation --> [*]DES Key Schedule
- The 56-bit key is permuted and split into two 28-bit halves (C and D).
- After each round, C and D are left-shifted by 1 or 2 bits and combined to form the 48-bit subkey.
Weaknesses of DES
| Attack | Description |
|---|---|
| Brute Force | 2^56 possible keys (now feasible with GPUs). |
| Differential Cryptanalysis | Analyzes how differences in input affect output. |
| Meet-in-the-Middle | Reduces brute-force complexity to 2^28. |
Example: DES Encryption Trace
Plaintext (64-bit): 00000001 00100011 01000101 01100111
Key (56-bit): 00010011 00110100 01010111 01111001 10011011 11000000 10000010
Steps:
- Initial Permutation (IP) reorders bits.
- Round 1: Apply Feistel function with subkey 1.
- Swap halves after each round (except the last).
- Final Permutation (FP) reverses IP.
(Note: Full manual trace is tedious; focus on understanding the Feistel structure.)
3. Advanced Encryption Standard (AES)
AES is the successor to DES, standardized by NIST in 2001. It supports key sizes of 128, 192, and 256 bits and operates on 128-bit blocks.
AES Structure: Substitution-Permutation Network (SPN)
AES uses 4 transformations repeated in rounds:
- SubBytes: Non-linear substitution using an 8×8 S-box (derived from finite field math).
- ShiftRows: Shifts rows of the 4×4 state matrix cyclically.
- MixColumns: Multiplies each column by a polynomial (diffusion).
- AddRoundKey: XORs the state with a round key.
AES Key Schedule
- 128-bit key: 10 rounds.
- 192-bit key: 12 rounds.
- 256-bit key: 14 rounds.
- Uses Rijndael’s key expansion, which involves:
- RotWord: Rotates a 4-byte word left by 1 byte.
- SubWord: Applies the S-box to each byte.
- Rcon: Adds a round constant.
Advantages of AES Over DES
| Feature | DES | AES |
|---|---|---|
| Key Size | 56-bit (weak) | 128/192/256-bit (strong) |
| Block Size | 64-bit | 128-bit |
| Speed | Slower on modern hardware | Optimized for CPUs/GPUs |
| Security | Vulnerable to brute force | Resistant to known attacks |
| Standards | Obsolete (NIST deprecated) | Current standard (FIPS 197) |
4. Modes of Operation for Block Ciphers
Block ciphers like DES/AES process data in fixed-size blocks, but real data is variable-length. Modes of operation define how to handle:
- Padding (e.g., PKCS#7).
- Chaining (to avoid patterns in identical plaintext blocks).
- Error propagation.
Common Modes
| Mode | Description | Use Case |
|---|---|---|
| ECB | Encrypts each block independently (insecure for repeated data). | Encrypting small, random data. |
| CBC | XORs plaintext with the previous ciphertext block (IV required). | Secure file encryption (e.g., PGP). |
| CFB | Treats the cipher as a stream cipher (feedback mode). | Encrypting streams (e.g., real-time). |
| OFB | Generates a keystream like CFB but without feedback. | High-speed encryption (e.g., TLS). |
| CTR | Encrypts a counter and XORs with plaintext (parallelizable). | Cloud storage (e.g., AWS KMS). |
| GCM | Provides authenticated encryption (combines CTR with a hash). | Secure communications (e.g., VPNs). |
Example: CBC Mode Encryption
Plaintext: Hello, World! (padded to 128 bits)
IV: 00000000 00000000 00000000 00000001
Steps:
- XOR Plaintext Block 1 with IV →
P1 ⊕ IV. - Encrypt with AES →
C1 = AES(K, P1 ⊕ IV). - XOR Plaintext Block 2 with C1 →
P2 ⊕ C1. - Encrypt →
C2 = AES(K, P2 ⊕ C1). - Repeat for all blocks.
sequenceDiagram
participant P as Plaintext
participant IV as Initialization Vector
participant AES as AES Encryption
participant C as Ciphertext
P->>IV: XOR (Block 1)
IV-->>AES: Encrypt
AES-->>C: C1
C->>P: XOR (Block 2)
P->>AES: Encrypt
AES-->>C: C2
Note over C,P: Repeat for all blocks5. Real-World Applications
1. Ncell and NTC: Securing Mobile Data
- Ncell uses AES-128 in CBC mode to encrypt voice calls (VoLTE) and SMS traffic.
- How it works:
- Your phone and the base station share a session key (derived from your SIM’s K).
- AES encrypts the IMSI (identity) and call metadata to prevent eavesdropping.
2. Daraz and NEPSE: Protecting Transactions
- Daraz uses AES-256 to encrypt:
- Credit card numbers (PCI-DSS compliant).
- Order confirmations (preventing tampering).
- NEPSE (Nepal Stock Exchange) encrypts trading data with AES-256 in GCM mode to ensure integrity and confidentiality.
3. Pathao: Ride Data Security
- Pathao encrypts:
- Driver locations (AES-128 in CTR mode for real-time updates).
- Payment details (3D Secure + AES).
- Why AES?
- Faster than RSA for bulk data.
- Resistant to quantum attacks (unlike RSA).
6. Security Considerations
Threats to Symmetric Cryptography
| Threat | Description | Mitigation |
|---|---|---|
| Brute Force | Exhaustive key search (e.g., DES cracked in 22 hours with COPACOBANA). | Use AES-256 or key stretching (PBKDF2). |
| Side-Channel Attacks | Timing/power analysis (e.g., extracting keys from CPU cache). | Use constant-time implementations. |
| Key Management | Losing or leaking the key compromises all data. | Use HSMs (Hardware Security Modules). |
| Weak Keys | Some keys in DES/AES are vulnerable (e.g., all zeros). | Validate keys before use. |
Best Practices
- Always use authenticated encryption (e.g., AES-GCM).
- Rotate keys periodically (e.g., every 24 hours for session keys).
- Combine with asymmetric crypto (e.g., RSA to exchange AES keys).
7. Exam Tip: How to Score Full Marks
Understand the Feistel Network (DES):
- Draw the 16-round structure and explain S-boxes and P-boxes.
- Example question: "Explain the role of S-boxes in DES with an example."
Answer: S-boxes provide non-linearity by replacing 6-bit inputs with 4-bit outputs. For example, S-box 1 maps
000001→0xE(hex).
Compare DES and AES:
- Use a table to highlight differences (key size, rounds, security).
- Example question: "Why is AES preferred over DES?" Answer: AES uses larger keys (128+ bits) and resists modern attacks like differential cryptanalysis.
Modes of Operation:
- ECB is insecure for repeated data; CBC/GCM are preferred.
- Example question: "How does CBC mode prevent patterns in ciphertext?" Answer: Each block is XORed with the previous ciphertext block, so identical plaintext blocks produce different ciphertexts.
Real-World Applications:
- Link AES to eSewa/Khalti (transaction security).
- Link DES to legacy systems (e.g., old banking protocols).
Worked Examples:
- For DES key scheduling, show PC-1 permutation and left shifts.
- For AES, trace one round with a 4×4 state matrix.
8. Common Pitfalls in Exams
- Assuming DES is secure: Always mention its 56-bit weakness.
- Ignoring modes of operation: ECB is not secure for most use cases.
- Forgetting key management: Symmetric crypto’s biggest challenge is key distribution.
- Mixing up AES and RSA: AES is symmetric; RSA is asymmetric.
Based on the TU BIT syllabus for Information Security (BIT303), unit 3.
Discussion
Loading…