CSC316 Cryptography

CryptographyUnit 812 min read

Network Security & Protocols: CIA Triad, IPSec, SSL/TLS, Kerberos, Attacks & Real-World Apps

Unit 8 of Cryptography explores how cryptographic protocols secure networks, covering the CIA triad, IPSec, SSL/TLS, Kerberos, authentication systems, and common attacks like MITM. It ties theory to real-world systems (eSewa, WhatsApp, Ncell) and includes hands-on examples like encrypting a Daraz order or analyzing a N

TAKEAWAYS:

  • The CIA triad (Confidentiality, Integrity, Availability) defines core security goals, while protocols like IPSec and SSL/TLS enforce them in practice.
  • IPSec (AH + ESP) secures IP traffic via authentication headers and encrypted payloads, while SSL/TLS (handshake → symmetric session) protects web apps like eSewa.
  • Kerberos uses ticket-based authentication to prevent replay attacks in systems like Ncell’s internal networks.
  • Attacks (MITM, meet-in-the-middle) exploit protocol weaknesses; countermeasures include digital signatures and perfect forward secrecy.
  • Message Authentication Codes (MACs) and hash functions (MD4/MD5) verify data integrity, critical for bank transactions or NEPSE trades.
  • Real-world layered security (e.g., WhatsApp’s end-to-end encryption + transport-layer TLS) combines multiple protocols for defense-in-depth.

Core Concepts: The CIA Triad and Security Services

Security is not a single tool but a layered framework built on three pillars: Confidentiality, Integrity, and Availability (the CIA triad). These principles guide every protocol and mechanism in network security.

The CIA Triad

mindmap
  root((CIA Triad))
    Confidentiality["Prevents unauthorized access\n* Encryption (AES, RSA)\n* Access controls (firewalls, ACLs)"]
    Integrity["Ensures data is unaltered\n* Hash functions (SHA-256)\n* Digital signatures (ECDSA)\n* Checksums (CRC)"]
    Availability["Guarantees system uptime\n* Redundancy (load balancers)\n* DDoS protection (rate limiting)\n* Backup systems"]

Why it matters:

  • eSewa uses confidentiality (TLS 1.3) to encrypt user payments.
  • NEPSE relies on integrity (blockchain-like digests) to prevent trade manipulation.
  • Ncell’s network prioritizes availability with redundant towers to avoid outages.

Protocol Deep Dive: IPSec (Internet Protocol Security)

IPSec is a suite of protocols (AH, ESP, IKE) that secures IP-layer communication, often used in VPNs or government networks (e.g., NTC’s backbone).

08162431Version4 bitsIHL4 bitsType of Service8 bitsTotal Length16 bitsIdentification16 bitsFlags3 bitsFragment Offset13 bitsTTL8 bitsProtocol8 bitsHeader Checksum16 bitsSource IP32 bitsDestination IP32 bits
IPv4 Header (20-byte base) with IPSec AH/ESP inserted between IP header and payload.

How IPSec Works

  1. Authentication Header (AH): Verifies packet origin via HMAC (hash-based MAC).
  2. Encapsulating Security Payload (ESP): Encrypts packet payload (e.g., with AES).
  3. Internet Key Exchange (IKE): Establishes secure keys via Diffie-Hellman + digital signatures.
ApplicationTransportNetworkData LinkPhysical
IPSec operates at the Network Layer (Layer 3) of the OSI model, securing IP packets.

Real-World Example:

  • NTC’s fiber-optic network uses IPSec to protect data between regional offices, ensuring confidentiality (ESP) and integrity (AH).
  • Worked Example: Encrypting a Daraz order (IP packet) with ESP:
    Original Packet: [IP Header][Order Data: "UserID=123, Item=Laptop"]
    ESP-Encrypted:   [IP Header][ESP Header][AES-256(Order Data)][MAC]
    

IPSec Modes

Mode Description Use Case
Transport Encrypts only payload (not outer IP header). Host-to-host (e.g., bank servers).
Tunnel Encrypts entire IP packet + new outer header (for VPNs). Site-to-site (e.g., Ncell HQ → towers).

Advantages:

  • Works at network layer (OSI Layer 3), transparent to apps.
  • Supports both authentication and encryption.

Disadvantages:

  • Complexity: Requires manual key management (IKEv2 helps).
  • Performance overhead: ~10–20% latency increase.

SSL/TLS: Securing the Web (eSewa, WhatsApp, Google)

SSL/TLS is the de facto standard for securing web traffic (HTTPS) and apps (WhatsApp, Khalti). It uses asymmetric cryptography (RSA/ECC) for key exchange and symmetric cryptography (AES) for bulk data.

TLS Handshake (Simplified)

sequenceDiagram
    participant C as Client (e.g., Browser)
    participant S as Server (e.g., eSewa)
    C->>S: ClientHello (Supported Ciphers)
    S->>C: ServerHello + Certificate (CA-signed)
    C->>S: PreMasterSecret (RSA-encrypted)
    S->>C: Session Key (Symmetric, e.g., AES-256)
    C->>S: Finished (MAC of handshake)
    S->>C: Finished

Key Steps:

  1. Certificate Validation: Server proves identity via a CA-signed certificate (e.g., Let’s Encrypt for Daraz).
  2. Key Exchange: Client and server derive a symmetric session key (ECDHE for forward secrecy).
  3. Session Establishment: Data encrypted with AES-GCM.

Real-World Example:

  • WhatsApp uses TLS for server-to-server communication (e.g., Nepal → Singapore data centers).
  • Khalti uses TLS 1.3 to encrypt payment tokens during checkout.

TLS vs. IPSec

Feature TLS IPSec
Layer Application/Transport (5–7) Network (3)
Use Case Web (HTTPS), APIs VPNs, IPsec tunnels
Key Exchange RSA/ECDHE IKE (DH + signatures)
Performance Lower latency (no IP overhead) Higher overhead (tunneling)

Authentication Protocols: Kerberos (Ncell, Banks)

Kerberos is a ticket-based authentication system used in enterprise networks (e.g., Ncell’s internal systems, bank ATMs) to prevent replay attacks.

How Kerberos Works

sequenceDiagram
    participant U as User
    participant AS as Authentication Server
    participant TGS as Ticket Granting Server
    participant S as Service (e.g., Ncell Database)
    U->>AS: Request TGT (Timestamp + ID)
    AS->>U: TGT (Encrypted with K_user)
    U->>TGS: TGT + Service Request
    TGS->>U: Service Ticket (Encrypted with K_service)
    U->>S: Service Ticket + Authenticator
    S->>U: Access Granted

Key Components:

  1. Ticket Granting Ticket (TGT): Short-lived credential from AS.
  2. Service Ticket: Grants access to a specific service (e.g., Ncell’s billing system).
  3. Session Key: Derived from TGT for service communication.

Why Kerberos?

  • No password transmission: Avoids MITM attacks on login credentials.
  • Time-stamped tickets: Prevents replay attacks (critical for bank transactions).

Real-World Example:

  • Ncell’s internal network uses Kerberos to authenticate employees accessing the billing database, ensuring only authorized staff can process data.

Attacks on Protocols: MITM and Meet-in-the-Middle

Even secure protocols can be broken if misconfigured. Two classic attacks:

[object Object][object Object][object Object][object Object]AliceBobMallory
MITM on DH: Mallory computes two shared keys (g^ab and g^cb) to decrypt both sides.

1. Man-in-the-Middle (MITM) Attack on Diffie-Hellman

Scenario: Alice and Bob exchange keys over an untrusted network (e.g., public Wi-Fi at a café). Attack:

sequenceDiagram
    participant A as Alice
    participant M as Mallory (Attacker)
    participant B as Bob
    A->>M: Public Key (g^a mod p)
    M->>B: Public Key (g^c mod p)  # Mallory's fake key
    B->>M: Public Key (g^b mod p)
    M->>A: Public Key (g^c mod p)  # Mallory's fake key
    M->>M: Computes Shared Keys (g^bc mod p)
    M->>A: Decrypts Alice's Traffic
    M->>B: Decrypts Bob's Traffic

Worked Example (from past exam):

  • Given: Prime p = 19, root g = 10, Alice’s private a = 5, Mallory’s random c = 4.
  • Alice’s public: .
  • Bob’s public: (unknown to Mallory).
  • Mallory’s shared key: (computed after intercepting Bob’s public key).

Countermeasure: Use Ephemeral Diffie-Hellman (ECDHE) with forward secrecy.

2. Meet-in-the-Middle Attack on Symmetric Ciphers

Scenario: Attacker precomputes possible keys to crack a double-encrypted message (e.g., Playfair cipher with two passes). Example:

  • Message: "INFORMATION" encrypted twice with keyword "SECURITY".
  • Attack: Precompute all possible first-key encryptions, then decrypt with second key.

Countermeasure: Use stronger ciphers (AES-256) or salting.


Message Authentication Codes (MACs) and Hash Functions

MACs and hashes verify data integrity and authenticate senders.

MACs in Action

  • HMAC-SHA256 is used in IPSec (AH) and TLS to ensure packets/messages aren’t tampered with.
  • Example: eSewa uses HMAC to sign transaction IDs before sending to banks.

Hash Functions: MD4 vs. MD5 vs. SHA-256

Algorithm Output Size Collision Resistance Use Case
MD4 128-bit Broken (easy collisions) Legacy systems (avoid!)
MD5 128-bit Broken (e.g., MD5 hash collisions) Avoid in security!
SHA-256 256-bit Strong TLS, Bitcoin, NEPSE trades

Worked Example: Computing MD4 digest for "NEPSE":

  1. Pad input to 512-bit blocks.
  2. Process in three passes (rounds of bitwise ops + constants).
  3. Final hash: 5d41402abc4b2a76b9719d911017c592 (truncated for brevity).

In the Real World

  1. eSewa:

    • Protocol: TLS 1.3 (for HTTPS) + HMAC-SHA256 (for transaction signing).
    • How: When you pay a bill, eSewa encrypts your bank details with AES-256 and signs the transaction with a private key (only eSewa knows). The bank verifies the MAC to ensure no tampering.
  2. WhatsApp:

    • Protocol: Signal Protocol (X3DH key exchange) + AES-256 for messages.
    • How: When you send a message to a friend, WhatsApp generates a one-time key pair, exchanges it securely, and encrypts the message. Even if Ncell intercepts the traffic, they can’t decrypt it (forward secrecy).
  3. NEPSE (Nepal Stock Exchange):

    • Protocol: Blockchain-like digests (SHA-256) + digital signatures.
    • How: Every trade is hashed and signed by the exchange. If someone tries to alter a trade record, the hash mismatches, exposing fraud.
  4. Ncell’s Network:

    • Protocol: IPSec (ESP mode) between towers + Kerberos for internal auth.
    • How: Data from your phone to Ncell’s server is encrypted with AES-256 (ESP). Only authorized staff can access the billing system via Kerberos tickets.

Exam Tip

  1. CIA Triad: Always define all three components (Confidentiality, Integrity, Availability) with one example each (e.g., "AES for confidentiality, HMAC for integrity, load balancers for availability").
  2. Protocols:
    • IPSec: Draw the AH vs. ESP table and explain IKE phases.
    • TLS: Sketch the handshake diagram and mention forward secrecy (ECDHE).
    • Kerberos: Explain TGT vs. Service Ticket and why it’s replay-resistant.
  3. Attacks:
    • MITM on DH: Show the sequence diagram with Mallory intercepting.
    • Meet-in-the-middle: Relate to double encryption (e.g., Playfair cipher).
  4. MACs/Hashes:
    • Compare MD5 (broken) vs. SHA-256 (secure).
    • For MD4 passes, mention three rounds (but don’t derive full hash—examiners want the process, not the output).
  5. Real-World Links:
    • eSewa → TLS + HMAC.
    • WhatsApp → Signal Protocol + AES.
    • NEPSE → SHA-256 digests.
    • Ncell → IPSec + Kerberos.

Avoid:

  • Describing RSA encryption (Unit 5 topic).
  • Going into AES internals (Unit 4).
  • Forgetting layer numbers (e.g., TLS is Layer 5–7, IPSec is Layer 3).

Based on the TU BSc CSIT syllabus for Cryptography (CSC316), unit 8.

Discussion

Loading…