CSC316 Cryptography

CryptographyUnit 113 min read

Cryptography Basics: Security, Keys, Attacks & Policies

Unit 1 of Cryptography introduces core concepts like confidentiality, integrity, authentication, and cryptographic attacks, while explaining security policies, mechanisms, and the distinction between symmetric/asymmetric cryptography with real-world applications.

TAKEAWAYS:

  • Cryptography protects confidentiality (secrecy), integrity (no tampering), and authentication (identity verification) in digital systems.
  • Symmetric key cryptography uses one shared key (fast but insecure for key distribution), while asymmetric key cryptography uses public/private key pairs (slower but solves key distribution).
  • Denial-of-Service (DoS) attacks disrupt services by overwhelming systems, while cryptanalysis breaks ciphers by exploiting weaknesses.
  • Security policies define rules (e.g., "all emails must be encrypted"), while mechanisms enforce them (e.g., AES encryption).
  • Digital signatures verify authenticity (like a handwritten signature but unforgeable), and MACs (Message Authentication Codes) ensure message integrity without signatures.

1. What is Cryptography?

Cryptography is the science of securing information by transforming it into an unreadable format (ciphertext) using mathematical techniques. Its primary goals are:

ConfidentialityIntegrityAuthenticationNon-repudiationCryptography Goals
Hierarchical breakdown of cryptography’s core goals (textbook-style)

Why is Cryptography Important?

  • E-commerce: Secure credit card transactions (e.g., Daraz, Amazon).
  • Communication: Encrypted chats (WhatsApp, Signal).
  • Government/Military: Classified documents (e.g., NTC’s network security).
  • Blockchain: Bitcoin transactions rely on cryptographic hashing.

A visual of how plaintext → ciphertext → decryption works in AES (Advanced Encryption Standard).


2. Core Cryptographic Concepts

A. Confidentiality, Integrity, and Authentication

Concept Definition Example
Confidentiality Ensures only authorized parties can access data. Encrypted emails (Gmail’s TLS).
Integrity Ensures data is not altered in transit. Hashing files (SHA-256 for software downloads).
Authentication Verifies the identity of users/devices. Digital certificates (HTTPS websites).

B. Security Services vs. Mechanisms

  • Security Policy: Rules defining what security measures are needed (e.g., "All student records must be encrypted").
  • Security Mechanism: Tools that enforce policies (e.g., AES for encryption, firewalls for access control).

Example:

  • Policy: "Nepal Rastra Bank requires all online banking transactions to use 256-bit encryption."
  • Mechanism: The bank uses AES-256 to encrypt data.

A real firewall device blocking unauthorized traffic (like a network security guard).


3. Symmetric vs. Asymmetric Cryptography

Feature Symmetric Key Cryptography Asymmetric Key Cryptography
Key Type Single shared key (secret key). Public key (shared) + Private key (secret).
Speed Fast (used for bulk data). Slow (used for key exchange).
Key Distribution Insecure (must be shared securely). Secure (public key can be shared openly).
Examples AES, DES, 3DES. RSA, ECC, Diffie-Hellman.
Symmetric KeyShared SecretAsymmetric KeyPublic/Private Keys
Key distribution comparison (symmetric uses pre-shared keys)

Worked Example: Symmetric Key in eSewa

  • Scenario: You pay a bill via eSewa.
  • Process:
    1. Your phone and eSewa’s server share a symmetric key (e.g., AES-128).
    2. Your transaction details are encrypted with this key before sending.
    3. The server decrypts using the same key.
  • Problem: If the key is stolen, the entire system is compromised.

Worked Example: Asymmetric Key in Ncell’s Website

  • Scenario: You log into Ncell’s website.
  • Process:
    1. Your browser gets Ncell’s public key (shared openly).
    2. You encrypt your login details with this public key.
    3. Only Ncell’s private key (kept secret) can decrypt it.
  • Advantage: No need to pre-share a secret key!

A visual showing how public keys are like a locked box (anyone can put a message inside), but only the private key (held by the owner) can open it.


4. Cryptographic Attacks

Attackers exploit weaknesses in cryptographic systems. Common attacks include:

A. Denial-of-Service (DoS) Attacks

  • Definition: Overwhelms a system to make it unavailable.
  • Example:
    • Nepal’s NTC Website Crash (2021): Hackers flooded the site with fake requests, causing outages.
    • How it works:
10000HackerVictimServer
DoS attack: 10,000 fake requests/sec (NTC Website 2021)

B. Cryptanalysis (Breaking Ciphers)

  • Brute Force: Trying all possible keys (e.g., cracking a 4-digit PIN in 10,000 attempts).
  • Frequency Analysis: Studying letter/word patterns (used in Caesar ciphers).
  • Differential Cryptanalysis: Exploiting how small input changes affect output (used against DES).

Example:

  • Weak Password Attack: If a system uses MD5 hashing (now considered weak), attackers can use precomputed tables (rainbow tables) to crack passwords.

A diagram showing an attacker trying every possible key combination to unlock a cipher.


5. Digital Signatures and Key Distribution

A. Digital Signatures

  • Definition: A mathematical way to verify authenticity and integrity (like a handwritten signature).
  • How it works:
    1. Sender hashes the message (e.g., SHA-256).
    2. Encrypts the hash with their private key → digital signature.
    3. Receiver decrypts with sender’s public key and compares hashes.
  • Types:
    • Direct Digital Signature: Sender signs directly (e.g., email signatures).
    • Arbitrated Digital Signature: A trusted third party (TTP) verifies (e.g., notary services).

Example:

  • Nepal’s Digital Signature Project: Used for e-governance to verify official documents.

B. Key Distribution

Method Description Example
Public Key Distribution Public keys are shared openly; private keys are kept secret. HTTPS websites (SSL/TLS).
Secret Key Distribution Keys must be shared securely (e.g., via courier or secure channels). Bank ATM PINs (shared in person).
Key Exchange Protocols Securely exchange keys over insecure channels (e.g., Diffie-Hellman). WhatsApp’s end-to-end encryption.

Worked Example: WhatsApp’s Key Exchange

  1. Alice and Bob generate public/private key pairs.
  2. They exchange public keys over the internet.
  3. They derive a shared symmetric key using Diffie-Hellman.
  4. All messages are encrypted with this symmetric key.

A sequence diagram showing how Alice and Bob compute a shared secret without transmitting it.


6. Message Authentication Codes (MACs)

  • Definition: A short piece of information used to authenticate a message (ensures integrity and authenticity).
  • How it works:
    1. Sender computes MAC = HMAC(key, message).
    2. Sends (message, MAC) to receiver.
    3. Receiver recomputes HMAC(key, message) and compares.
  • Limitations:
    • Requires a shared secret key (like symmetric cryptography).
    • Not non-repudiable (sender can deny sending).

Example:

  • Khalti’s Transaction Verification: Uses MACs to ensure payment details are not tampered with.

7. Security Policies and Mechanisms

A. Security Policy

  • Definition: A set of rules defining how security is achieved (e.g., "All passwords must be 12+ characters").
  • Example:
    • Nepal’s Cybersecurity Strategy (2022): Mandates encryption for all government data.

B. Security Mechanism

  • Definition: The actual tools/algorithms enforcing policies (e.g., firewalls, encryption).
  • Example:
    • NTC’s Firewall: Blocks unauthorized access to its network.

Comparison:

Policy Mechanism
"All emails must be encrypted." PGP/GPG encryption software.
"No public Wi-Fi for banking." VPN for secure connections.

8. Block Cipher vs. Stream Cipher

Feature Block Cipher Stream Cipher
Input Fixed-size blocks (e.g., 128-bit). One bit/byte at a time.
Speed Slower (due to block processing). Faster (real-time encryption).
Error Propagation Error in one block affects only that block. Error propagates indefinitely.
Examples AES, DES. RC4, ChaCha20.

Example:

  • Block Cipher: AES encrypts a 16-byte chunk of data at a time.
  • Stream Cipher: Used in live video calls (e.g., Zoom’s encryption).

In the Real World

  1. eSewa’s Encryption:

    • Idea Used: Symmetric key cryptography (AES-256) for fast transaction processing.
    • How: When you pay a bill, eSewa encrypts your card details with a shared key between your phone and their server.
  2. Khalti’s MACs:

    • Idea Used: Message Authentication Codes (HMAC-SHA256) to prevent fraud.
    • How: After you authorize a payment, Khalti generates a MAC. If the MAC doesn’t match during verification, the transaction is rejected.
  3. Ncell’s HTTPS (SSL/TLS):

    • Idea Used: Asymmetric key cryptography (RSA/ECC) for secure key exchange.
    • How: When you log in, your browser and Ncell’s server perform a Diffie-Hellman handshake to agree on a symmetric key for fast encryption.
  4. Nepal Stock Exchange (NEPSE) Security:

    • Idea Used: Digital signatures for trading orders.
    • How: Brokers sign orders with their private keys; NEPSE verifies them using public keys to prevent forgery.
  5. Pathao’s Ride Requests:

    • Idea Used: Integrity checks (hashing) to detect tampered ride data.
    • How: Pathao computes a hash of your ride details (pickup/drop location). If altered, the hash won’t match, and the ride is flagged.

Exam Tip

This unit tests conceptual understanding and real-world applications. Focus on:

  1. Definitions: Know the exact meanings of confidentiality, integrity, authentication, non-repudiation, DoS, MAC, and digital signatures.
  2. Comparisons: Be ready to differentiate between:
    • Symmetric vs. asymmetric cryptography.
    • Block ciphers vs. stream ciphers.
    • Direct vs. arbitrated digital signatures.
  3. Examples: Relate concepts to Nepali services (eSewa, Khalti, Ncell, NTC) or global tech (WhatsApp, Google, banks).
  4. Diagrams: Practice drawing:
    • Symmetric/asymmetric key workflows.
    • Digital signature processes.
    • DoS attack sequences.
  5. Policy vs. Mechanism: Always give one policy + one mechanism in examples (e.g., "Policy: Encrypt emails. Mechanism: Use PGP.").
  6. Weaknesses: Know limitations of MACs (no non-repudiation) and symmetric key distribution (key exchange problem).

Common Pitfalls:

  • Confusing MACs (for integrity) with digital signatures (for authentication + non-repudiation).
  • Forgetting that symmetric keys must be shared securely, while asymmetric keys solve this problem.
  • Mixing up block ciphers (fixed-size blocks) and stream ciphers (continuous data).

Final Checklist Before Exam: ✅ Can you explain confidentiality, integrity, authentication with examples? ✅ Can you draw a symmetric vs. asymmetric key workflow? ✅ Do you know two real-world uses of cryptography in Nepal (e.g., eSewa, Khalti)? ✅ Can you describe a DoS attack and a cryptanalysis method? ✅ Can you differentiate policy vs. mechanism with an example?

Based on the TU BSc CSIT syllabus for Cryptography (CSC316), unit 1.

Discussion

Loading…