CryptographyUnit 49 min read
Block Cipher Modes & Symmetric Techniques: Modes, Feistel, AES, IDEA
Unit 4 of Cryptography explores how block ciphers like AES and IDEA encrypt data in chunks, the Feistel network structure, and advanced modes (ECB, CBC, CFB, OFB, CTR). It covers key scheduling, weak keys, and real-world applications in secure communications and financial transactions.
TAKEAWAYS:
- Block ciphers process data in fixed-size blocks (e.g., 64/128 bits) using modes like ECB, CBC, or CTR to ensure confidentiality and integrity.
- The Feistel structure (used in DES) splits each round into expansion, S-box substitution, and permutation for diffusion and confusion.
- AES uses a substitution-permutation network with 10–14 rounds, key expansion, and S-boxes to resist cryptanalysis.
- Weak keys in DES (e.g., all-zero or complementary keys) reduce security; IDEA avoids this by using modular arithmetic.
- Modes like CBC add initialization vectors (IVs) to prevent identical plaintexts from producing identical ciphertexts.
- Real-world systems (e.g., eSewa for payment encryption, Ncell for SIM card authentication) rely on AES-CBC or IDEA for secure data transmission.
1. Block Ciphers: Basics and Structure
Block ciphers encrypt fixed-size blocks (e.g., 64 bits in DES, 128 bits in AES) using a symmetric key. Unlike stream ciphers (which encrypt bit-by-bit), block ciphers apply transformations like substitution, permutation, and modular arithmetic to scramble data.
Key Concepts
- Plaintext Block (P): Input data divided into fixed-size chunks (e.g., 16 bytes for AES).
- Ciphertext Block (C): Encrypted output of the same size.
- Key (K): Symmetric key shared between sender and receiver.
- Rounds: Multiple iterations of transformations to ensure security.
Why Block Ciphers?
- Efficiency: Process data in chunks (faster than stream ciphers for large files).
- Standardization: Used in TLS (HTTPS), Wi-Fi (WPA2), and disk encryption (BitLocker).
- Security: Resistant to known-plaintext attacks when modes like CBC are used.
classDiagram
class BlockCipher {
+encrypt(P, K) C
+decrypt(C, K) P
+rounds: int
+blockSize: int
}
class AES {
+blockSize: 128 bits
+rounds: 10-14
+keySize: 128/192/256 bits
}
class DES {
+blockSize: 64 bits
+rounds: 16
+keySize: 56 bits
}
BlockCipher <|-- AES
BlockCipher <|-- DES2. Feistel Network: The Backbone of DES
The Feistel structure (used in DES and 3DES) splits each round into:
- Expansion: Expand half the block to match the key size.
- Substitution (S-boxes): Replace bits with non-linear values (e.g., DES uses 8 S-boxes).
- Permutation (P-box): Rearrange bits for diffusion.
- XOR with Key: Combine with a subkey.
How It Works
- Round Function (F):
Lᵢ₊₁ = Rᵢ Rᵢ₊₁ = Lᵢ ⊕ F(Rᵢ, Kᵢ) - Final Swap: After all rounds, swap
LandRto reverse the process.
Example: DES Round
stateDiagram-v2
[*] --> FeistelRound: Start
FeistelRound --> Expand: Expand Rᵢ
Expand --> SBox: Apply S-boxes
SBox --> XOR: XOR with Kᵢ
XOR --> Lᵢ₊₁: Lᵢ₊₁ = Rᵢ
XOR --> Rᵢ₊₁: Rᵢ₊₁ = Lᵢ ⊕ F(Rᵢ, Kᵢ)
Rᵢ₊₁ --> [*]3. Advanced Symmetric Ciphers: AES and IDEA
A. AES (Advanced Encryption Standard)
- Block Size: 128 bits.
- Key Sizes: 128, 192, or 256 bits.
- Rounds: 10 (128-bit key), 12 (192-bit), or 14 (256-bit).
- Transformations:
- SubBytes: Non-linear substitution using S-boxes.
- ShiftRows: Cyclic shifts of rows.
- MixColumns: Linear mixing of columns.
- AddRoundKey: XOR with round key.
Key Expansion in AES
- Derives round keys from the main key using Rijndael’s key schedule.
- Example: For a 128-bit key, the first round key is the key itself; subsequent keys are generated via
RCONandSubBytes.
Weak Keys in DES
- All-zero key: Produces trivial ciphertext.
- Complementary keys (e.g.,
0x01234567and0xFEDCBA98): Weak against differential cryptanalysis. - IDEA avoids this by using modular arithmetic (addition, multiplication, XOR).
4. Block Cipher Modes of Operation
Modes define how blocks are encrypted to handle:
- Identical plaintext blocks (e.g., in ECB, same input → same output).
- Error propagation (e.g., CBC corrupts only one block if a bit flips).
Common Modes
| Mode | Description | Use Case | Security Notes |
|---|---|---|---|
| ECB | Encrypt each block independently. | Small files, no IV needed. | Vulnerable to pattern analysis. |
| CBC | XOR plaintext with previous ciphertext (IV for first block). | Secure files, TLS. | IV must be random; errors propagate. |
| CFB | Turn block cipher into a stream cipher (feedback mode). | Real-time encryption (e.g., SSH). | Errors affect subsequent blocks. |
| OFB | Similar to CFB but uses previous keystream (no error propagation). | High-speed encryption. | Requires secure keystream generation. |
| CTR | Encrypt counter blocks; XOR with plaintext. | Parallelizable (e.g., AES-CTR). | Counter must be unique per key. |
Example: CBC Mode
- IV (Initialization Vector) is randomly generated.
- For each block:
Cᵢ = E(K, Pᵢ ⊕ Cᵢ₋₁) - Decryption:
Pᵢ = D(K, Cᵢ) ⊕ Cᵢ₋₁
sequenceDiagram
participant Sender as Sender
participant Receiver as Receiver
Sender->>Receiver: IV (Random)
loop For each block
Sender->>Sender: Pᵢ ⊕ Cᵢ₋₁
Sender->>Receiver: Cᵢ = E(K, Pᵢ ⊕ Cᵢ₋₁)
Receiver->>Receiver: Pᵢ = D(K, Cᵢ) ⊕ Cᵢ₋₁
end5. Real-World Applications
A. eSewa (Nepal)
- Use Case: Secure online payments.
- Cryptography: AES-256 in CBC mode to encrypt transaction data.
- Why? Prevents tampering and ensures confidentiality.
B. Ncell SIM Card Authentication
- Use Case: User authentication via PIN/SIM.
- Cryptography: Triple DES (3DES) in ECB mode for legacy systems.
- Why? Balances security and compatibility with old hardware.
C. Daraz Order Processing
- Use Case: Secure order queues.
- Cryptography: AES-CTR for encrypting order IDs and customer data.
- Why? Parallelizable for high throughput; no error propagation.
Worked Example: AES in Kathmandu Traffic Routes
- Scenario: GPS data encryption for ride-sharing apps (e.g., Pathao).
- Problem: Two identical GPS coordinates (e.g.,
27.7172° N, 85.3240° E) must not produce the same ciphertext. - Solution: Use AES-CBC with a random IV for each transmission.
Plaintext: [27.7172, 85.3240] (repeated) IV: Random 16-byte value Ciphertext: E(K, P₁ ⊕ IV), E(K, P₂ ⊕ C₁) → Unique outputs!
6. Weak Keys and Cryptanalysis
Weak Keys in DES
- All-zero key:
0x0000000000000000→ Trivial ciphertext. - Complementary keys:
Kand~K(bitwise NOT) produce weak diffusion. - IDEA’s Advantage: Uses modular operations (addition, multiplication) to avoid such weaknesses.
Differential Cryptanalysis
- Attack: Exploits how differences in plaintext affect ciphertext.
- Countermeasure: Increase rounds (e.g., AES has 10–14 rounds).
Linear Cryptanalysis
- Attack: Finds linear approximations between plaintext and ciphertext.
- Countermeasure: Use S-boxes with high non-linearity (e.g., AES S-box).
Exam Tip
Modes of Operation:
- ECB: Avoid in real systems (patterns leak).
- CBC: Most common; remember IV must be random.
- CTR: Preferred for high-speed encryption (e.g., TLS 1.3).
Feistel Structure:
- DES: 16 rounds, 56-bit key.
- 3DES: Applies DES 3 times (EDE) for stronger security.
AES Details:
- Key Expansion: Derive round keys from the main key.
- S-boxes: Non-linear substitution to resist attacks.
Weak Keys:
- DES: All-zero, complementary keys.
- IDEA: No weak keys due to modular arithmetic.
Worked Examples:
- For Hill Cipher (past exam questions), show matrix inversion.
- For AES key expansion, trace the first round key derivation.
Past Exam Patterns:
- Short Answers: Define CBC, ECB, or Feistel structure.
- Calculations: Decrypt using Hill Cipher or compute AES round keys.
- Comparisons: Differentiate between stream and block ciphers.
Based on the TU BSc CSIT syllabus for Cryptography (CSC316), unit 4.
Discussion
Loading…