CMP426 Network and Cyber Security

Network and Cyber SecurityUnit 29 min read

Classical & Symmetric Cryptography: Ciphers, AES, DES, Block vs Stream Modes

Unit 2 of Network and Cyber Security explores the foundations of cryptography—classical ciphers (Caesar, Vigenère, Playfair) and modern symmetric encryption (AES, DES, 3DES)—how they transform plaintext into ciphertext, their mathematical underpinnings, and real-world trade-offs between security and performance.

Core Concepts: What Is Cryptography?

Cryptography is the science of securing information by transforming it into an unreadable format (ciphertext) using mathematical algorithms. Symmetric cryptography uses a single shared key for both encryption and decryption, making it fast but vulnerable if the key is compromised.

Classical Ciphers: The Birth of Cryptography

Classical ciphers are manual substitution/transposition techniques used before computers. They rely on human effort to break, not computational power.

1. Substitution Ciphers

Replace each plaintext character with another (e.g., A→D, B→E).

  • Caesar Cipher: Shifts letters by a fixed number (e.g., shift=3: A→D, B→E).
    flowchart TD
      A["Plaintext: ATTACKATDAWN"] --> B["Shift +3: DWWDFNDWDZQ"]
      B --> C["Key: 3"]
  • Vigenère Cipher: Uses a keyword to vary the shift per character.
    • Example: Key = "KEY", Plaintext = "ATTACK":
      A T T A C K
      K E Y K E Y
      D W W D F N
      
    • Why it’s stronger: Resists frequency analysis better than Caesar.

2. Transposition Ciphers

Reorder characters without substitution (e.g., rail fence cipher).

  • Example: Plaintext = "HELLO", Key = 2 rails:
    H   E   L   L   O
    E L L O H
    → "HELLO" → "HELLO" (reordered: HELLO → HELO L)
    

3. Playfair Cipher

Encrypts digraphs (2-letter pairs) using a 5×5 matrix.

  • Example: Key = "MONARCHY", Plaintext = "HELLO":
    M O N A R
    C H Y B D
    E L L O → "BM OD" (substituted pairs)
    

Caesar cipher wheel**A physical device used to encode/decode Caesar shifts by rotating letters. (Image: Armchair, CC BY-SA 4.0, via Wikimedia Commons)


Modern Symmetric Cryptography: AES, DES, and Beyond

Classical ciphers are broken by computers—modern symmetric encryption uses algorithms (AES, DES) and modes of operation (ECB, CBC, CFB).

1. Block Ciphers: AES and DES

Block ciphers split plaintext into fixed-size blocks (e.g., 64-bit for DES, 128-bit for AES) and encrypt each block.

AES (Advanced Encryption Standard)

  • Block size: 128 bits.
  • Key sizes: 128, 192, or 256 bits.
  • Rounds: 10 (128-bit key), 12 (192-bit), or 14 (256-bit).
  • Operations per round:
    • SubBytes (non-linear substitution)
    • ShiftRows (permutation)
    • MixColumns (linear mixing)
    • AddRoundKey (XOR with key)

DES (Data Encryption Standard)

  • Block size: 64 bits (but only 56 bits are key bits).
  • Key size: 56 bits (now obsolete due to brute-force attacks).
  • Rounds: 16 (Feistel network structure).

Comparison Table: AES vs. DES

Feature AES DES
Block size 128 bits 64 bits
Key size 128/192/256 bits 56 bits (weak)
Security Resistant to brute force Broken by 2005 (EFF)
Speed Faster on modern CPUs Slower (legacy hardware)
Use case Modern encryption (WPA2, TLS) Legacy systems (rare today)

2. Modes of Operation: How Blocks Are Encrypted

Modes define how block ciphers handle multiple blocks and errors.

ECB (Electronic Codebook)

  • Encrypts each block independently.
  • Problem: Identical plaintext blocks → identical ciphertext (visible patterns).
    flowchart TD
      P1["Block 1"] --> E1["ECB Encrypt"]
      P2["Block 2"] --> E2["ECB Encrypt"]
      E1 --> C1["Ciphertext 1"]
      E2 --> C2["Ciphertext 2"]

CBC (Cipher Block Chaining)

  • XORs each plaintext block with the previous ciphertext block before encryption.
  • Requires: Initialization Vector (IV) for the first block.
  • Advantage: Hides patterns (avalanche effect).
    flowchart TD
      IV["IV"] --> XOR1["XOR P1"]
      XOR1 --> E1["Encrypt"]
      E1 --> C1["Ciphertext 1"]
      C1 --> XOR2["XOR P2"]
      XOR2 --> E2["Encrypt"]
      E2 --> C2["Ciphertext 2"]

CFB (Cipher Feedback) and OFB (Output Feedback)

  • Treat block cipher as a stream cipher (good for real-time data like video).
  • CFB: Encrypts previous ciphertext block, XORs with plaintext.
  • OFB: Generates a keystream independently (better error resilience).

Real-World Applications

1. eSewa and Khalti (Nepal)

  • What they use: AES-256 in CBC mode to encrypt payment data (card numbers, OTPs).
  • How it works:
    • When you pay via Khalti, your card details are split into 128-bit blocks, encrypted with AES, and sent to the bank’s server.
    • The bank’s server decrypts using the same shared key (symmetric).
  • Why symmetric? Speed: AES is 1000x faster than public-key crypto for bulk data.

2. WhatsApp End-to-End Encryption

  • What they use: AES-256 in CFB mode for message encryption.
  • How it works:
    • Your phone generates a one-time key, encrypts the message with AES-CFB, and sends it.
    • The recipient’s phone uses the same key to decrypt.
    • Key exchange: Uses Signal Protocol (public-key crypto) to securely share the AES key.

3. Bank ATMs and Loan Interest Calculations

  • What they use: 3DES (Triple DES) for PIN encryption (legacy systems).
  • How it works:
    • When you enter a PIN, it’s encrypted with 3DES (DES applied 3× with different keys) and sent to the bank.
    • Worked Example: If your loan interest is calculated monthly with compounding, the bank’s server uses AES to encrypt your transaction logs to prevent tampering.
    • Formula:
      • Here, P (principal) and r (rate) are stored encrypted with AES-128.

Strengths and Weaknesses

Advantage Disadvantage
Fast (AES: ~1 Gbps) Key distribution problem
Low computational cost Single key vulnerability
Proven security (AES) Not suitable for key exchange

Key Distribution Problem:

  • If Alice and Bob share a key via email, an attacker (Eve) can intercept it.
  • Solution: Use asymmetric crypto (Unit 3) to exchange the symmetric key securely.

Worked Example: Encrypting "HELLO" with AES-128 in ECB Mode

  1. Plaintext: H E L L O → Convert to binary:
    H: 01001000, E: 01000101, L: 01001100, L: 01001100, O: 01001111
    
  2. Pad to 128 bits: Add null bytes (PKCS#7 padding):
    01001000 01000101 01001100 01001100 01001111 00000000 00000000 00000000
    
  3. Encrypt with AES-128:
    • Apply 10 rounds of SubBytes, ShiftRows, MixColumns, AddRoundKey.
    • Output (example ciphertext):
      3AD77BB40D7A3660A89BCF8FFAAF3692
      
  4. Decrypt: Reverse the process with the same key.

Common Attacks on Symmetric Crypto

Attack How It Works Prevention
Brute Force Try all possible keys (2^128 for AES-128) Use 128+ bit keys
Known-Plaintext Attacker knows plaintext → deduces key Avoid repeating patterns (use CBC)
Side-Channel Measures power/EM leaks to guess key Constant-time implementations
Meet-in-the-Middle Splits key search (e.g., DES 56-bit) Use AES (no practical splits)

Exam Tip: How This Unit Is Tested

  1. Definitions (5 marks):

    • Explain substitution vs. transposition ciphers.
    • Define block cipher, mode of operation, and Feistel network.
  2. Worked Examples (10 marks):

    • Encrypt/decrypt a short message using Caesar, Vigenère, or Playfair.
    • Trace one round of AES (show SubBytes, ShiftRows).
    • Calculate padding for AES (PKCS#7).
  3. Comparisons (5 marks):

    • Compare AES vs. DES (block size, key size, security).
    • Compare ECB vs. CBC (patterns, IV usage).
  4. Real-World Applications (5 marks):

    • Explain how Khalti uses AES for payments.
    • Describe WhatsApp’s use of CFB mode.
  5. Attacks (5 marks):

    • Explain frequency analysis (classical ciphers).
    • Describe brute-force limits for AES-128.

Pro Tip:

  • Memorize AES rounds: SubBytes → ShiftRows → MixColumns → AddRoundKey.
  • Draw diagrams: Always sketch CBC chaining or AES rounds in exams.
  • Link to real systems: Mention TLS (Unit 6) uses AES for encrypting web traffic.

mindmap
  root((Symmetric Cryptography))
    Classical Ciphers
      Caesar["Caesar: Shift by N"]
      Vigenère["Vigenère: Keyword-based shift"]
      Playfair["Playfair: 5×5 matrix digraphs"]
    Modern Block Ciphers
      DES["DES: 56-bit, 16 rounds"]
      AES["AES: 128/192/256-bit, SubBytes+ShiftRows"]
    Modes of Operation
      ECB["ECB: Independent blocks (insecure)"]
      CBC["CBC: Chaining with IV"]
      CFB["CFB: Stream-like feedback"]
    Attacks
      BruteForce["Brute force: 2^128 for AES"]
      KnownPlaintext["Known plaintext → key deduction"]
    Real-World
      Khalti["AES-256 for payments"]
      WhatsApp["CFB mode for messages"]

Based on the PU BE Computer (PU) syllabus for Network and Cyber Security (CMP426), unit 2.

Discussion

Loading…