IT225 Computer Security and Cyber Law

Computer Security and Cyber LawUnit 29 min read

Cryptography Basics, Algorithms, and Cryptanalysis Techniques

Unit 2 of Computer Security and Cyber Law explores core cryptography concepts—classical and modern encryption (symmetric/asymmetric), cryptanalysis methods, and real-world applications in secure communications, e-commerce, and digital signatures. Students learn how encryption protects data, how attacks like brute force

Core Concepts: What is Cryptography?

Cryptography is the science of securing information by transforming it into an unreadable format (ciphertext) using mathematical algorithms. Its goal is to ensure confidentiality, integrity, and authenticity of data. Cryptanalysis is the study of breaking these systems to exploit vulnerabilities.

Why Cryptography Matters

  • Protects sensitive data (passwords, financial records, medical history).
  • Enables secure communications (e.g., WhatsApp end-to-end encryption).
  • Supports digital signatures (e.g., eSewa transactions).
  • Prevents cybercrimes (fraud, identity theft, data breaches).
mindmap
  root((Cryptography))
    Confidentiality
    Integrity
    Authenticity
    Non-repudiation
    Availability

1. Classical Cryptography: Foundations of Encryption

Classical cryptography uses substitution and transposition techniques. Though outdated for modern security, it teaches core principles.

A. Substitution Ciphers

Replace letters/numbers with other symbols. Examples:

  • Caesar Cipher: Shift letters by a fixed number (e.g., "ABC" → "DEF" with shift=3).
  • Vigenère Cipher: Uses a keyword for shifting (e.g., keyword "KEY" encrypts "ATTACK" as "FYXXQF").

Weakness: Vulnerable to frequency analysis (counting letter occurrences).

flowchart LR
  A["Plaintext: 'HELLO'"] --> B["Caesar Shift=3"] --> C["Ciphertext: 'KHOOR'"]
  D["Frequency Analysis"] --> E["Break Cipher"]

B. Transposition Ciphers

Reorder characters without substitution (e.g., "HELLO" → "LHEOL" via columnar transposition).

Weakness: Requires known-plaintext attacks to break.


2. Modern Cryptography: Symmetric vs. Asymmetric

Modern systems use mathematical complexity for security.

A. Symmetric Key Cryptography (Shared Secret)

Same key encrypts/decrypts. Fast but key distribution is hard. Examples:

  • AES (Advanced Encryption Standard): Block cipher (128/192/256-bit keys).
  • DES (Data Encryption Standard): Older (56-bit key, now insecure).
  • Blowfish, Twofish: Alternatives to AES.

Worked Example: AES in eSewa eSewa uses AES-256 to encrypt user transactions. If an attacker intercepts ciphertext, they need attempts to brute-force the key (impossible with current tech).

B. Asymmetric Key Cryptography (Public-Key)

Uses two keys: public (encrypt) and private (decrypt). Solves key distribution. Examples:

  • RSA: Relies on prime factorization (hard to reverse).
  • ECC (Elliptic Curve Cryptography): Uses elliptic curves for smaller keys (faster).
  • Diffie-Hellman: Key exchange protocol.

Comparison Table: Symmetric vs. Asymmetric

Feature Symmetric Key Asymmetric Key
Speed Fast Slow
Key Distribution Hard (shared secret) Easy (public/private)
Use Case Encrypting large data Key exchange, signatures
Example Algorithms AES, DES RSA, ECC, DH

3. Cryptanalysis: Breaking Encryption

Cryptanalysis exploits weaknesses in algorithms or implementations.

A. Brute Force Attack

Try all possible keys until correct one is found.

  • Example: Cracking a 4-digit PIN has attempts.
  • Mitigation: Use longer keys (e.g., AES-256).

B. Frequency Analysis

Works on substitution ciphers (e.g., English "E" appears most often).

  • Example: In "KHOOR" (Caesar-shifted "HELLO"), "O" is most frequent → likely "E".

C. Differential Cryptanalysis

Exploits patterns in block ciphers (e.g., AES).

  • Example: Attacker inputs two plaintexts differing by 1 bit, observes ciphertext changes.

D. Man-in-the-Middle (MITM)

Intercepts communication to decrypt/modify data.

  • Example: Fake Wi-Fi hotspot stealing login credentials.

man-in-the-middle attack labelled diagram**Attacker between Alice and Bob, decrypting/altering messages. (Image: Miraceti, CC BY-SA 3.0, via Wikimedia Commons)


In the Real World

  1. eSewa (Nepal)

    • Idea Used: AES-256 encryption for transaction data.
    • How: When you pay a bill, your card details are encrypted before transmission. Even if intercepted, the data is unreadable without the key.
  2. Khalti (Nepal)

    • Idea Used: RSA for digital signatures and SHA-256 hashing for integrity.
    • How: When you authorize a payment, Khalti signs the transaction with its private key. The recipient verifies it with Khalti’s public key to ensure authenticity.
  3. WhatsApp (Global)

    • Idea Used: Signal Protocol (ECC + Diffie-Hellman) for end-to-end encryption.
    • How: Your messages are encrypted with a key unique to the chat. Even WhatsApp can’t read them.
  4. Nepal Rastra Bank (NRB) Transactions

    • Idea Used: PKI (Public Key Infrastructure) for secure banking.
    • How: When you transfer money via online banking, your request is signed with your digital certificate (asymmetric key pair). The bank verifies the signature before processing.
  5. Daraz (Nepal)

    • Idea Used: HTTPS (TLS with RSA/ECC) for secure checkout.
    • How: When you enter payment details, your browser and Daraz’s server perform a Diffie-Hellman key exchange to create a session key for AES encryption.

4. Hash Functions: Data Integrity

Hash functions convert input into a fixed-size string (hash). Used for:

  • Password storage (e.g., password → 5f4dcc3b5aa765d61d8327deb882cf99 via SHA-256).
  • Digital signatures (e.g., signing a contract hash).
  • File verification (e.g., downloading software).

Properties of a Good Hash Function:

  • Deterministic: Same input → same hash.
  • Fixed-length output: SHA-256 always produces 256-bit hash.
  • Pre-image resistance: Hard to reverse (given hash, find input).
  • Collision resistance: Hard to find two inputs with same hash.

Worked Example: Password Cracking If a hacker steals a database with stored hashes (not plaintext passwords), they must:

  1. Guess passwords.
  2. Hash each guess.
  3. Compare to stored hashes.
  • Weakness: If passwords are short (e.g., "1234"), they can be cracked in seconds.
  • Solution: Use salting (adding random data to input) and slow hashing (e.g., bcrypt).

5. Digital Signatures and Non-Repudiation

Digital signatures prove authenticity and integrity using asymmetric keys. Process:

  1. Sender hashes the message.
  2. Encrypts hash with private key → digital signature.
  3. Sends message + signature.
  4. Recipient decrypts signature with public key, compares to hashed message.

Example: eSewa uses digital signatures to ensure you cannot deny sending money.

digital signature process labelled diagram**Plaintext → Hash → Private Key → Signature → Public Key → Hash Verification. (Image: Thiagocv, CC BY-SA 4.0, via Wikimedia Commons)


6. Security Trade-offs: Speed vs. Security

Algorithm Key Size Security Level Speed Use Case
DES 56-bit Weak Very Fast Legacy systems
AES-128 128-bit Strong Fast General encryption
AES-256 256-bit Very Strong Slower High-security applications
RSA-2048 2048-bit Strong Slow Digital signatures
ECC-256 256-bit Strong Faster than RSA Mobile apps, IoT

Why Not Always Use the Strongest?

  • Performance: AES-256 is slower than AES-128.
  • Compatibility: Older systems may not support large keys.
  • Cost: Stronger encryption requires more processing power (e.g., ECC vs. RSA).

Exam Tip

What to Expect in TU/PU Exams

  1. Definitions:

    • Explain symmetric vs. asymmetric encryption with examples.
    • Define hash function, digital signature, and brute force attack.
  2. Worked Problems:

    • Caesar Cipher: Given ciphertext and shift, decrypt.
    • AES/DES: Compare key sizes and security.
    • RSA: Explain how public/private keys work (no math, just concept).
  3. Short Answers:

    • "What is frequency analysis?" → Attack exploiting letter frequencies.
    • "How does HTTPS use cryptography?" → TLS with RSA/ECC for key exchange + AES for encryption.
  4. Scenario-Based Questions:

    • "A bank uses DES for ATM PINs. Why is this risky?" → 56-bit key is weak; brute force is feasible.
    • "How would you secure an e-commerce website?" → HTTPS (TLS), digital signatures, AES for data.
  5. Diagrams:

    • Draw AES encryption steps or RSA key pair process.
    • Label man-in-the-middle attack or digital signature flow.

Common Mistakes to Avoid

  • Mixing symmetric/asymmetric: Remember symmetric = same key; asymmetric = two keys.
  • Ignoring key size: AES-128 ≠ AES-256 in security.
  • Overcomplicating math: Exams focus on concepts, not calculations (e.g., no RSA modular arithmetic).
  • Forgetting real-world ties: Always link theory to eSewa, WhatsApp, or banking in answers.

Quick Revision Checklist

  • Can you name 3 symmetric and 3 asymmetric algorithms?
  • What’s the difference between hashing and encryption?
  • How does frequency analysis break substitution ciphers?
  • Why is key distribution harder in symmetric encryption?
  • What’s the role of digital signatures in e-commerce?

Based on the TU BITM syllabus for Computer Security and Cyber Law (IT225), unit 2.

Discussion

Loading…