Computer Security and Cyber LawUnit 29 min read
Cryptography Basics, Algorithms, and Cryptanalysis Techniques
Unit 2 of Computer Security and Cyber Law explores core cryptography concepts—classical and modern encryption (symmetric/asymmetric), cryptanalysis methods, and real-world applications in secure communications, e-commerce, and digital signatures. Students learn how encryption protects data, how attacks like brute force
Core Concepts: What is Cryptography?
Cryptography is the science of securing information by transforming it into an unreadable format (ciphertext) using mathematical algorithms. Its goal is to ensure confidentiality, integrity, and authenticity of data. Cryptanalysis is the study of breaking these systems to exploit vulnerabilities.
Why Cryptography Matters
- Protects sensitive data (passwords, financial records, medical history).
- Enables secure communications (e.g., WhatsApp end-to-end encryption).
- Supports digital signatures (e.g., eSewa transactions).
- Prevents cybercrimes (fraud, identity theft, data breaches).
mindmap
root((Cryptography))
Confidentiality
Integrity
Authenticity
Non-repudiation
Availability1. Classical Cryptography: Foundations of Encryption
Classical cryptography uses substitution and transposition techniques. Though outdated for modern security, it teaches core principles.
A. Substitution Ciphers
Replace letters/numbers with other symbols. Examples:
- Caesar Cipher: Shift letters by a fixed number (e.g., "ABC" → "DEF" with shift=3).
- Vigenère Cipher: Uses a keyword for shifting (e.g., keyword "KEY" encrypts "ATTACK" as "FYXXQF").
Weakness: Vulnerable to frequency analysis (counting letter occurrences).
flowchart LR A["Plaintext: 'HELLO'"] --> B["Caesar Shift=3"] --> C["Ciphertext: 'KHOOR'"] D["Frequency Analysis"] --> E["Break Cipher"]
B. Transposition Ciphers
Reorder characters without substitution (e.g., "HELLO" → "LHEOL" via columnar transposition).
Weakness: Requires known-plaintext attacks to break.
2. Modern Cryptography: Symmetric vs. Asymmetric
Modern systems use mathematical complexity for security.
A. Symmetric Key Cryptography (Shared Secret)
Same key encrypts/decrypts. Fast but key distribution is hard. Examples:
- AES (Advanced Encryption Standard): Block cipher (128/192/256-bit keys).
- DES (Data Encryption Standard): Older (56-bit key, now insecure).
- Blowfish, Twofish: Alternatives to AES.
Worked Example: AES in eSewa eSewa uses AES-256 to encrypt user transactions. If an attacker intercepts ciphertext, they need attempts to brute-force the key (impossible with current tech).
B. Asymmetric Key Cryptography (Public-Key)
Uses two keys: public (encrypt) and private (decrypt). Solves key distribution. Examples:
- RSA: Relies on prime factorization (hard to reverse).
- ECC (Elliptic Curve Cryptography): Uses elliptic curves for smaller keys (faster).
- Diffie-Hellman: Key exchange protocol.
Comparison Table: Symmetric vs. Asymmetric
| Feature | Symmetric Key | Asymmetric Key |
|---|---|---|
| Speed | Fast | Slow |
| Key Distribution | Hard (shared secret) | Easy (public/private) |
| Use Case | Encrypting large data | Key exchange, signatures |
| Example Algorithms | AES, DES | RSA, ECC, DH |
3. Cryptanalysis: Breaking Encryption
Cryptanalysis exploits weaknesses in algorithms or implementations.
A. Brute Force Attack
Try all possible keys until correct one is found.
- Example: Cracking a 4-digit PIN has attempts.
- Mitigation: Use longer keys (e.g., AES-256).
B. Frequency Analysis
Works on substitution ciphers (e.g., English "E" appears most often).
- Example: In "KHOOR" (Caesar-shifted "HELLO"), "O" is most frequent → likely "E".
C. Differential Cryptanalysis
Exploits patterns in block ciphers (e.g., AES).
- Example: Attacker inputs two plaintexts differing by 1 bit, observes ciphertext changes.
D. Man-in-the-Middle (MITM)
Intercepts communication to decrypt/modify data.
- Example: Fake Wi-Fi hotspot stealing login credentials.
Attacker between Alice and Bob, decrypting/altering messages. (Image: Miraceti, CC BY-SA 3.0, via Wikimedia Commons)
In the Real World
eSewa (Nepal)
- Idea Used: AES-256 encryption for transaction data.
- How: When you pay a bill, your card details are encrypted before transmission. Even if intercepted, the data is unreadable without the key.
Khalti (Nepal)
- Idea Used: RSA for digital signatures and SHA-256 hashing for integrity.
- How: When you authorize a payment, Khalti signs the transaction with its private key. The recipient verifies it with Khalti’s public key to ensure authenticity.
WhatsApp (Global)
- Idea Used: Signal Protocol (ECC + Diffie-Hellman) for end-to-end encryption.
- How: Your messages are encrypted with a key unique to the chat. Even WhatsApp can’t read them.
Nepal Rastra Bank (NRB) Transactions
- Idea Used: PKI (Public Key Infrastructure) for secure banking.
- How: When you transfer money via online banking, your request is signed with your digital certificate (asymmetric key pair). The bank verifies the signature before processing.
Daraz (Nepal)
- Idea Used: HTTPS (TLS with RSA/ECC) for secure checkout.
- How: When you enter payment details, your browser and Daraz’s server perform a Diffie-Hellman key exchange to create a session key for AES encryption.
4. Hash Functions: Data Integrity
Hash functions convert input into a fixed-size string (hash). Used for:
- Password storage (e.g.,
password→5f4dcc3b5aa765d61d8327deb882cf99via SHA-256). - Digital signatures (e.g., signing a contract hash).
- File verification (e.g., downloading software).
Properties of a Good Hash Function:
- Deterministic: Same input → same hash.
- Fixed-length output: SHA-256 always produces 256-bit hash.
- Pre-image resistance: Hard to reverse (given hash, find input).
- Collision resistance: Hard to find two inputs with same hash.
Worked Example: Password Cracking If a hacker steals a database with stored hashes (not plaintext passwords), they must:
- Guess passwords.
- Hash each guess.
- Compare to stored hashes.
- Weakness: If passwords are short (e.g., "1234"), they can be cracked in seconds.
- Solution: Use salting (adding random data to input) and slow hashing (e.g., bcrypt).
5. Digital Signatures and Non-Repudiation
Digital signatures prove authenticity and integrity using asymmetric keys. Process:
- Sender hashes the message.
- Encrypts hash with private key → digital signature.
- Sends message + signature.
- Recipient decrypts signature with public key, compares to hashed message.
Example: eSewa uses digital signatures to ensure you cannot deny sending money.
Plaintext → Hash → Private Key → Signature → Public Key → Hash Verification. (Image: Thiagocv, CC BY-SA 4.0, via Wikimedia Commons)
6. Security Trade-offs: Speed vs. Security
| Algorithm | Key Size | Security Level | Speed | Use Case |
|---|---|---|---|---|
| DES | 56-bit | Weak | Very Fast | Legacy systems |
| AES-128 | 128-bit | Strong | Fast | General encryption |
| AES-256 | 256-bit | Very Strong | Slower | High-security applications |
| RSA-2048 | 2048-bit | Strong | Slow | Digital signatures |
| ECC-256 | 256-bit | Strong | Faster than RSA | Mobile apps, IoT |
Why Not Always Use the Strongest?
- Performance: AES-256 is slower than AES-128.
- Compatibility: Older systems may not support large keys.
- Cost: Stronger encryption requires more processing power (e.g., ECC vs. RSA).
Exam Tip
What to Expect in TU/PU Exams
Definitions:
- Explain symmetric vs. asymmetric encryption with examples.
- Define hash function, digital signature, and brute force attack.
Worked Problems:
- Caesar Cipher: Given ciphertext and shift, decrypt.
- AES/DES: Compare key sizes and security.
- RSA: Explain how public/private keys work (no math, just concept).
Short Answers:
- "What is frequency analysis?" → Attack exploiting letter frequencies.
- "How does HTTPS use cryptography?" → TLS with RSA/ECC for key exchange + AES for encryption.
Scenario-Based Questions:
- "A bank uses DES for ATM PINs. Why is this risky?" → 56-bit key is weak; brute force is feasible.
- "How would you secure an e-commerce website?" → HTTPS (TLS), digital signatures, AES for data.
Diagrams:
- Draw AES encryption steps or RSA key pair process.
- Label man-in-the-middle attack or digital signature flow.
Common Mistakes to Avoid
- Mixing symmetric/asymmetric: Remember symmetric = same key; asymmetric = two keys.
- Ignoring key size: AES-128 ≠ AES-256 in security.
- Overcomplicating math: Exams focus on concepts, not calculations (e.g., no RSA modular arithmetic).
- Forgetting real-world ties: Always link theory to eSewa, WhatsApp, or banking in answers.
Quick Revision Checklist
- Can you name 3 symmetric and 3 asymmetric algorithms?
- What’s the difference between hashing and encryption?
- How does frequency analysis break substitution ciphers?
- Why is key distribution harder in symmetric encryption?
- What’s the role of digital signatures in e-commerce?
Based on the TU BITM syllabus for Computer Security and Cyber Law (IT225), unit 2.
Discussion
Loading…