Information SecurityUnit 415 min read
Symmetric Key Cryptography: Algorithms, Modes & Applications
Unit 4 of Information Security explores symmetric key cryptography—how identical keys encrypt/decrypt data, core algorithms (DES, AES), modes of operation (ECB, CBC), and real-world uses in banking, e-commerce, and secure messaging. Learn key exchange challenges, performance trade-offs, and why symmetric ciphers domina
TAKEAWAYS:
- Symmetric cryptography uses one shared key for encryption/decryption, enabling fast bulk data protection but requiring secure key distribution.
- Block ciphers (like AES) split data into fixed-size blocks (e.g., 128-bit) and process them sequentially, while stream ciphers encrypt bit-by-bit.
- Modes of operation (e.g., CBC, CFB) determine how blocks are chained or randomized to prevent patterns in ciphertext.
- Key management is the Achilles’ heel: keys must be longer (128+ bits), changed frequently, and distributed securely (e.g., via Diffie-Hellman).
- Real-world use: AES-256 secures WhatsApp end-to-end chats, while DES (now obsolete) was used in early ATM PIN encryption.
- Weaknesses: Vulnerable to brute-force if keys are short (e.g., 56-bit DES) or reused in ECB mode (reveals data patterns).
1. Core Concepts: How Symmetric Cryptography Works
Symmetric cryptography relies on a single secret key shared between sender and receiver. The same key encrypts plaintext into ciphertext and decrypts it back. This contrasts with asymmetric cryptography (Unit 5), which uses a key pair.
Key Properties
- Secrecy: The key must never be exposed; if compromised, all encrypted data is at risk.
- Length: Measured in bits (e.g., 128-bit, 256-bit). Longer keys resist brute-force attacks exponentially.
- Distribution: The hardest problem—keys must be shared securely before encryption (e.g., via a trusted courier or key exchange protocol).
Why Symmetric Ciphers Dominate
- Speed: Hardware-optimized (e.g., AES runs at ~1 Gbps on modern CPUs).
- Efficiency: Low overhead for encrypting large files (e.g., database backups, video streams).
- Use cases: Disk encryption (BitLocker), VPNs, TLS (after initial asymmetric handshake), and file storage.
stateDiagram-v2
[*] --> Plaintext: Data to encrypt
Plaintext --> Encryption: Symmetric Key (e.g., AES-256)
Encryption --> Ciphertext: Unreadable output
Ciphertext --> Decryption: Same symmetric key
Decryption --> Plaintext: Original data
[*]2. Types of Symmetric Ciphers
A. Stream Ciphers
Encrypt data bit-by-bit using a keystream generated from the secret key. Examples:
- RC4: Used in early Wi-Fi (WEP), now deprecated due to vulnerabilities.
- A5/1: Encrypts GSM mobile calls (broken in 2011).
How it works:
- Key → Pseudo-Random Number Generator (PRNG) → Keystream.
- Keystream XORed with plaintext = ciphertext.
- Receiver uses the same key to regenerate the keystream.
Advantages:
- Fast, low latency (ideal for real-time communication).
- No block alignment issues.
Disadvantages:
- Keystream reuse leaks plaintext (e.g., WEP attacks).
- Hard to implement securely (e.g., RC4’s bias vulnerabilities).
B. Block Ciphers
Split data into fixed-size blocks (e.g., 64-bit for DES, 128-bit for AES) and process them. Far more common today.
How it works:
- Plaintext → Split into blocks (padding added if needed).
- Each block encrypted independently or chained (modes of operation).
- Ciphertext blocks reassembled.
3. Classic Symmetric Algorithms
A. Data Encryption Standard (DES)
- Block size: 64-bit (but only 56 bits are key; 8 bits for parity).
- Key size: 56-bit (now obsolete due to brute-force feasibility).
- Structure: Feistel network with 16 rounds of substitution/permutation.
Weaknesses:
- Brute-force: 56-bit key → ~2²⁵⁵ operations (feasible with modern GPUs).
- Meet-in-the-middle attacks: Reduces complexity to 2⁵⁶.
- ECB mode: Reveals patterns (e.g., identical plaintext blocks → identical ciphertext).
Worked Example: DES Encryption Trace
Assume plaintext = 00000001 00000010 (2 blocks), key = 00010011001100110011001100110011 (56-bit).
- Initial Permutation (IP): Reorders bits.
- Round 1: Split into L₀/R₀, apply Feistel function with subkeys.
- R₀ XORed with f(L₀, subkey₁) → L₁.
- L₀ → R₁.
- Repeat 16 rounds, then final permutation → ciphertext.
B. Advanced Encryption Standard (AES)
- Block size: 128-bit.
- Key sizes: 128, 192, or 256 bits.
- Structure: Substitution-Permutation Network (SPN) with rounds:
- SubBytes: Non-linear substitution via S-box.
- ShiftRows: Shift bytes in columns.
- MixColumns: Linear mixing of bytes.
- AddRoundKey: XOR with round key.
Why AES Replaced DES:
| Feature | DES | AES |
|---|---|---|
| Key size | 56-bit (weak) | 128/192/256-bit (strong) |
| Security | Broken by brute-force | No practical attacks |
| Speed | Slower on modern hardware | Optimized for CPUs/GPUs |
| Standards | Obsolete (NIST 2005) | Global standard (FIPS 197) |
4. Modes of Operation for Block Ciphers
Modes determine how blocks are processed to avoid vulnerabilities like ECB’s pattern leakage.
A. Electronic Codebook (ECB)
- How it works: Each block encrypted independently.
- Problem: Identical plaintext blocks → identical ciphertext (reveals data patterns).
- Example: Encrypting a JPEG with repeated pixel blocks leaks structure.
graph LR
P1["Plaintext Block 1"] -->|"ECB"| C1["Ciphertext Block 1"]
P2["Plaintext Block 2"] -->|"ECB"| C2["Ciphertext Block 2"]
P1 -->|"Same as P1"| P1_copy
P1_copy -->|"ECB"| C1_copy["Same as C1"]Never use ECB for real data!
B. Cipher Block Chaining (CBC)
- How it works: Each block XORed with the previous ciphertext block before encryption.
- First block XORed with an Initialization Vector (IV) (public, random).
- Advantages:
- Hides patterns (same plaintext → different ciphertext).
- IV ensures identical plaintexts encrypt differently.
- Use case: TLS, SSH, disk encryption.
graph LR
IV["IV (Random)"] -->|"XOR"| P1["Plaintext Block 1"] -->|"Encrypt"| C1["Ciphertext Block 1"]
C1 -->|"XOR"| P2["Plaintext Block 2"] -->|"Encrypt"| C2["Ciphertext Block 2"]C. Cipher Feedback (CFB) & Output Feedback (OFB)
- CFB: Turns block cipher into a stream cipher by feeding previous ciphertext into the next encryption.
- OFB: Uses the cipher’s output as a keystream (like a true stream cipher).
- Use case: Real-time encryption (e.g., streaming video).
D. Counter (CTR) Mode
- How it works: Encrypts a counter value (instead of plaintext) to generate a keystream.
- Plaintext XORed with keystream = ciphertext.
- Advantages:
- Parallelizable (encrypt counter blocks in parallel).
- No error propagation (unlike CBC).
- Use case: Encrypting large files (e.g., database backups).
Comparison Table:
| Mode | Pattern Hiding | Parallelizable | Error Propagation | Use Case |
|---|---|---|---|---|
| ECB | ❌ No | ✅ Yes | ❌ None | Never for real data |
| CBC | ✅ Yes | ❌ No | ✅ Yes | TLS, disk encryption |
| CFB/OFB | ✅ Yes | ❌ No (CFB) | ❌ None (OFB) | Real-time streams |
| CTR | ✅ Yes | ✅ Yes | ❌ None | Large files, databases |
5. Key Management: The Hardest Problem
Even the strongest cipher fails if keys are mishandled.
Key Distribution Challenges
- Pre-shared keys: Secure only if exchanged via a trusted channel (e.g., in-person).
- Key exchange protocols: Use asymmetric crypto (e.g., Diffie-Hellman) to establish a symmetric key securely.
Best Practices
- Key Length: Minimum 128 bits (AES-128), 256 bits for long-term secrets.
- Key Rotation: Change keys periodically (e.g., every 24 hours for session keys).
- Key Storage:
- Hardware Security Modules (HSMs): Tamper-resistant devices (e.g., used by banks).
- Key Derivation Functions (KDFs): Stretch weak keys (e.g., PBKDF2 for passwords).
- Key Revocation: Mechanisms to invalidate compromised keys (e.g., via a Key Revocation List).
6. Real-World Applications
A. eSewa & Khalti (Nepal)
- What it uses: AES-256 in CBC mode to encrypt transaction data between user apps and servers.
- How it works:
- User enters PIN → hashed with a salt (not stored).
- Session key derived from PIN hash + server nonce.
- Transaction details encrypted with AES-256-CBC before transmission.
- Why symmetric? Speed and efficiency for high-volume transactions.
B. WhatsApp End-to-End Encryption
- What it uses: AES-256 in CTR mode for message encryption.
- How it works:
- Signal Protocol (asymmetric) exchanges a pre-key and ephemeral key.
- Both sides derive a session key using Diffie-Hellman.
- AES-256-CTR encrypts messages with a counter to ensure uniqueness.
- Real-world impact: Even WhatsApp metadata (timestamps, "seen" receipts) is encrypted.
C. NTC & Ncell Network Security
- What it uses: AES-128 in CTR mode for encrypting mobile data (4G/LTE).
- How it works:
- User authenticates via SIM card (shared secret with network).
- Session key derived for the duration of the call/data session.
- AES-CTR encrypts all traffic, including voice (VoLTE) and internet data.
- Vulnerability: If the session key is leaked (e.g., via IMSI catchers), all traffic is exposed.
D. Bank ATM PIN Encryption (Legacy Systems)
- What it uses: DES in ECB mode (still found in old ATMs).
- How it works:
- User enters PIN → converted to binary → encrypted with a master key (stored in ATM).
- Ciphertext sent to bank for verification.
- Why it’s broken:
- 56-bit DES → brute-forced in hours with modern GPUs.
- ECB mode leaks PIN patterns (e.g., "1234" always encrypts to the same ciphertext).
7. Attacks on Symmetric Cryptography
| Attack | Description | Example Target |
|---|---|---|
| Brute-force | Try all possible keys until correct one is found. | DES (56-bit) |
| Meet-in-the-middle | Precompute all possible encryptions/decryptions to reduce key space. | DES |
| Known-plaintext | Attacker knows some plaintext → deduces key. | ECB mode images |
| Chosen-plaintext | Attacker can choose plaintext to encrypt and observe ciphertext. | Weak PRNGs in stream ciphers |
| Side-channel | Exploits physical leaks (e.g., power consumption, timing). | Smart cards |
| Replay attacks | Captures and reuses old ciphertext (e.g., in CBC without IV). | Network protocols |
Worked Example: ECB Attack on a JPEG
- Attacker captures ciphertext of a JPEG with repeated 8×8 pixel blocks.
- Identical ciphertext blocks → identical plaintext blocks.
- By analyzing block frequencies, attacker reconstructs the image structure.
8. Hybrid Cryptosystems: Best of Both Worlds
Symmetric ciphers are fast but need secure key exchange. Asymmetric ciphers solve key distribution but are slow. Hybrid systems combine both:
- Asymmetric crypto (e.g., RSA) exchanges a session key.
- Symmetric crypto (e.g., AES) encrypts the actual data.
Example: TLS Handshake
sequenceDiagram
Client->>Server: Hello (supports AES, RSA)
Server->>Client: Hello, Certificate (RSA public key)
Client->>Server: PreMasterSecret (encrypted with RSA)
Client-->>Client: Session Key = PRF(PreMasterSecret, ClientRandom, ServerRandom)
Client->>Server: EncryptedHandshake (AES-256-CBC)
Server->>Client: EncryptedHandshake (AES-256-CBC)
Note over Client,Server: All further traffic encrypted with AES-256Exam Tip
What Examiners Look For
- Algorithm Details:
- Draw and label the AES round structure (SubBytes, ShiftRows, etc.).
- Explain DES’s Feistel network and why it’s vulnerable to meet-in-the-middle.
- Mode Comparisons:
- Contrast ECB vs. CBC vs. CTR in terms of security and use cases.
- Know when OFB/CFB are used (stream-like behavior).
- Key Management:
- Define key rotation, IV reuse risks, and HSMs.
- Explain why DES is obsolete (brute-force, small key size).
- Real-World Applications:
- Link AES-CTR to WhatsApp or CBC to TLS.
- Critique DES in ECB mode (e.g., ATM PIN leaks).
- Attack Scenarios:
- Describe a known-plaintext attack on ECB or brute-force on DES.
- Explain side-channel attacks (e.g., timing attacks on smart cards).
Common Mistakes to Avoid
- Confusing modes: ECB is never secure; CBC requires a random IV.
- Key size assumptions: Always state "AES-256" not just "AES."
- Ignoring IVs: Reusing IVs in CBC/OFB leaks plaintext.
- Overlooking hybrid systems: TLS uses both asymmetric (RSA/ECDH) and symmetric (AES).
Sample Exam Questions & Answers
Q1: "Explain how AES-256 encrypts a 256-bit plaintext block in one round. Draw the structure." Answer:
- AddRoundKey: XOR plaintext with round key (256 bits).
- SubBytes: Replace each byte with S-box value.
- ShiftRows: Shift rows left (0, 1, 2, 3 bytes).
- MixColumns: Multiply each column by a matrix. (Draw the 4-step diagram here.)
Q2: "Why is DES vulnerable to a meet-in-the-middle attack? How does AES avoid this?" Answer:
- DES: Attacker precomputes all possible encryptions/decryptions for half the key space (2⁵⁶ → 2²⁸).
- AES: 128-bit key → 2¹²⁸ possibilities (feasible only with quantum computers).
Q3: "A bank uses DES-ECB to encrypt ATM PINs. Explain how an attacker could recover the PIN with minimal effort." Answer:
- Capture ciphertexts from multiple PINs (e.g., "1234" → C₁, "5678" → C₂).
- Since ECB leaks patterns, attacker builds a rainbow table mapping common PINs to ciphertexts.
- Match observed ciphertexts to table → recover PINs.
In the Real World
Khalti’s Transaction Security
- Idea Used: AES-256-CBC for encrypting payment details between merchant apps and Khalti’s servers.
- How It Works: Each transaction generates a random IV and session key (derived from user credentials). The merchant’s app encrypts the amount, merchant ID, and user wallet address before sending to Khalti’s API. If an attacker intercepts the ciphertext, they gain no information without the session key (which expires after 5 minutes).
Pathao Driver-Passenger Matching
- Idea Used: Stream cipher (ChaCha20) for real-time location updates between driver and passenger apps.
- Why Symmetric? Pathao needs low latency (location updates every 2 seconds) and high throughput (hundreds of concurrent rides). ChaCha20 (a modern stream cipher) is faster than AES on mobile devices and resists replay attacks via a counter mode.
Nepal Stock Exchange (NEPSE) Data Integrity
- Idea Used: HMAC-SHA256 (hash-based MAC) combined with AES-128 for authenticating and encrypting stock trade data.
- Real Scenario: When you buy shares via Merosecurities, your trade request is:
- Encrypted with AES-128-CTR (for confidentiality).
- Signed with HMAC-SHA256 (to ensure the trade wasn’t altered in transit).
- Attack Prevention: If a hacker alters the ciphertext, the HMAC fails, and NEPSE’s system rejects the trade.
Final Visual Summary
mindmap
root((Symmetric Key Cryptography))
Concepts
One Key for Enc/Dec
Speed > Asymmetric
Types
Stream Ciphers
RC4 (Deprecated)
ChaCha20 (Modern)
Block Ciphers
DES (Obsolete)
AES (Standard)
Modes
ECB (Insecure)
CBC (Secure, Needs IV)
CTR (Parallelizable)
OFB/CFB (Stream-like)
Attacks
Brute-force (DES)
ECB Pattern Leakage
Side-channel (Timing)
Real-World
WhatsApp (AES-CTR)
Khalti (AES-CBC)
NTC (AES-128)Based on the TU BITM syllabus for Information Security (IT244), unit 4.
Discussion
Loading…