Network and Cyber SecurityUnit 29 min read
Classical & Symmetric Cryptography: Ciphers, AES, DES, Block vs Stream Modes
Unit 2 of Network and Cyber Security explores the foundations of cryptography—classical ciphers (Caesar, Vigenère, Playfair) and modern symmetric encryption (AES, DES, 3DES)—how they transform plaintext into ciphertext, their mathematical underpinnings, and real-world trade-offs between security and performance.
Core Concepts: What Is Cryptography?
Cryptography is the science of securing information by transforming it into an unreadable format (ciphertext) using mathematical algorithms. Symmetric cryptography uses a single shared key for both encryption and decryption, making it fast but vulnerable if the key is compromised.
Classical Ciphers: The Birth of Cryptography
Classical ciphers are manual substitution/transposition techniques used before computers. They rely on human effort to break, not computational power.
1. Substitution Ciphers
Replace each plaintext character with another (e.g., A→D, B→E).
- Caesar Cipher: Shifts letters by a fixed number (e.g., shift=3:
A→D,B→E).flowchart TD A["Plaintext: ATTACKATDAWN"] --> B["Shift +3: DWWDFNDWDZQ"] B --> C["Key: 3"]
- Vigenère Cipher: Uses a keyword to vary the shift per character.
- Example: Key = "KEY", Plaintext = "ATTACK":
A T T A C K K E Y K E Y D W W D F N - Why it’s stronger: Resists frequency analysis better than Caesar.
- Example: Key = "KEY", Plaintext = "ATTACK":
2. Transposition Ciphers
Reorder characters without substitution (e.g., rail fence cipher).
- Example: Plaintext = "HELLO", Key = 2 rails:
H E L L O E L L O H → "HELLO" → "HELLO" (reordered: HELLO → HELO L)
3. Playfair Cipher
Encrypts digraphs (2-letter pairs) using a 5×5 matrix.
- Example: Key = "MONARCHY", Plaintext = "HELLO":
M O N A R C H Y B D E L L O → "BM OD" (substituted pairs)
A physical device used to encode/decode Caesar shifts by rotating letters. (Image: Armchair, CC BY-SA 4.0, via Wikimedia Commons)
Modern Symmetric Cryptography: AES, DES, and Beyond
Classical ciphers are broken by computers—modern symmetric encryption uses algorithms (AES, DES) and modes of operation (ECB, CBC, CFB).
1. Block Ciphers: AES and DES
Block ciphers split plaintext into fixed-size blocks (e.g., 64-bit for DES, 128-bit for AES) and encrypt each block.
AES (Advanced Encryption Standard)
- Block size: 128 bits.
- Key sizes: 128, 192, or 256 bits.
- Rounds: 10 (128-bit key), 12 (192-bit), or 14 (256-bit).
- Operations per round:
- SubBytes (non-linear substitution)
- ShiftRows (permutation)
- MixColumns (linear mixing)
- AddRoundKey (XOR with key)
DES (Data Encryption Standard)
- Block size: 64 bits (but only 56 bits are key bits).
- Key size: 56 bits (now obsolete due to brute-force attacks).
- Rounds: 16 (Feistel network structure).
Comparison Table: AES vs. DES
| Feature | AES | DES |
|---|---|---|
| Block size | 128 bits | 64 bits |
| Key size | 128/192/256 bits | 56 bits (weak) |
| Security | Resistant to brute force | Broken by 2005 (EFF) |
| Speed | Faster on modern CPUs | Slower (legacy hardware) |
| Use case | Modern encryption (WPA2, TLS) | Legacy systems (rare today) |
2. Modes of Operation: How Blocks Are Encrypted
Modes define how block ciphers handle multiple blocks and errors.
ECB (Electronic Codebook)
- Encrypts each block independently.
- Problem: Identical plaintext blocks → identical ciphertext (visible patterns).
flowchart TD P1["Block 1"] --> E1["ECB Encrypt"] P2["Block 2"] --> E2["ECB Encrypt"] E1 --> C1["Ciphertext 1"] E2 --> C2["Ciphertext 2"]
CBC (Cipher Block Chaining)
- XORs each plaintext block with the previous ciphertext block before encryption.
- Requires: Initialization Vector (IV) for the first block.
- Advantage: Hides patterns (avalanche effect).
flowchart TD IV["IV"] --> XOR1["XOR P1"] XOR1 --> E1["Encrypt"] E1 --> C1["Ciphertext 1"] C1 --> XOR2["XOR P2"] XOR2 --> E2["Encrypt"] E2 --> C2["Ciphertext 2"]
CFB (Cipher Feedback) and OFB (Output Feedback)
- Treat block cipher as a stream cipher (good for real-time data like video).
- CFB: Encrypts previous ciphertext block, XORs with plaintext.
- OFB: Generates a keystream independently (better error resilience).
Real-World Applications
1. eSewa and Khalti (Nepal)
- What they use: AES-256 in CBC mode to encrypt payment data (card numbers, OTPs).
- How it works:
- When you pay via Khalti, your card details are split into 128-bit blocks, encrypted with AES, and sent to the bank’s server.
- The bank’s server decrypts using the same shared key (symmetric).
- Why symmetric? Speed: AES is 1000x faster than public-key crypto for bulk data.
2. WhatsApp End-to-End Encryption
- What they use: AES-256 in CFB mode for message encryption.
- How it works:
- Your phone generates a one-time key, encrypts the message with AES-CFB, and sends it.
- The recipient’s phone uses the same key to decrypt.
- Key exchange: Uses Signal Protocol (public-key crypto) to securely share the AES key.
3. Bank ATMs and Loan Interest Calculations
- What they use: 3DES (Triple DES) for PIN encryption (legacy systems).
- How it works:
- When you enter a PIN, it’s encrypted with 3DES (DES applied 3× with different keys) and sent to the bank.
- Worked Example: If your loan interest is calculated monthly with compounding, the bank’s server uses AES to encrypt your transaction logs to prevent tampering.
- Formula:
- Here,
P(principal) andr(rate) are stored encrypted with AES-128.
- Here,
Strengths and Weaknesses
| Advantage | Disadvantage |
|---|---|
| Fast (AES: ~1 Gbps) | Key distribution problem |
| Low computational cost | Single key vulnerability |
| Proven security (AES) | Not suitable for key exchange |
Key Distribution Problem:
- If Alice and Bob share a key via email, an attacker (Eve) can intercept it.
- Solution: Use asymmetric crypto (Unit 3) to exchange the symmetric key securely.
Worked Example: Encrypting "HELLO" with AES-128 in ECB Mode
- Plaintext:
H E L L O→ Convert to binary:H: 01001000, E: 01000101, L: 01001100, L: 01001100, O: 01001111 - Pad to 128 bits: Add null bytes (PKCS#7 padding):
01001000 01000101 01001100 01001100 01001111 00000000 00000000 00000000 - Encrypt with AES-128:
- Apply 10 rounds of SubBytes, ShiftRows, MixColumns, AddRoundKey.
- Output (example ciphertext):
3AD77BB40D7A3660A89BCF8FFAAF3692
- Decrypt: Reverse the process with the same key.
Common Attacks on Symmetric Crypto
| Attack | How It Works | Prevention |
|---|---|---|
| Brute Force | Try all possible keys (2^128 for AES-128) | Use 128+ bit keys |
| Known-Plaintext | Attacker knows plaintext → deduces key | Avoid repeating patterns (use CBC) |
| Side-Channel | Measures power/EM leaks to guess key | Constant-time implementations |
| Meet-in-the-Middle | Splits key search (e.g., DES 56-bit) | Use AES (no practical splits) |
Exam Tip: How This Unit Is Tested
Definitions (5 marks):
- Explain substitution vs. transposition ciphers.
- Define block cipher, mode of operation, and Feistel network.
Worked Examples (10 marks):
- Encrypt/decrypt a short message using Caesar, Vigenère, or Playfair.
- Trace one round of AES (show SubBytes, ShiftRows).
- Calculate padding for AES (PKCS#7).
Comparisons (5 marks):
- Compare AES vs. DES (block size, key size, security).
- Compare ECB vs. CBC (patterns, IV usage).
Real-World Applications (5 marks):
- Explain how Khalti uses AES for payments.
- Describe WhatsApp’s use of CFB mode.
Attacks (5 marks):
- Explain frequency analysis (classical ciphers).
- Describe brute-force limits for AES-128.
Pro Tip:
- Memorize AES rounds: SubBytes → ShiftRows → MixColumns → AddRoundKey.
- Draw diagrams: Always sketch CBC chaining or AES rounds in exams.
- Link to real systems: Mention TLS (Unit 6) uses AES for encrypting web traffic.
mindmap
root((Symmetric Cryptography))
Classical Ciphers
Caesar["Caesar: Shift by N"]
Vigenère["Vigenère: Keyword-based shift"]
Playfair["Playfair: 5×5 matrix digraphs"]
Modern Block Ciphers
DES["DES: 56-bit, 16 rounds"]
AES["AES: 128/192/256-bit, SubBytes+ShiftRows"]
Modes of Operation
ECB["ECB: Independent blocks (insecure)"]
CBC["CBC: Chaining with IV"]
CFB["CFB: Stream-like feedback"]
Attacks
BruteForce["Brute force: 2^128 for AES"]
KnownPlaintext["Known plaintext → key deduction"]
Real-World
Khalti["AES-256 for payments"]
WhatsApp["CFB mode for messages"]Based on the PU BE Computer (PU) syllabus for Network and Cyber Security (CMP426), unit 2.
Discussion
Loading…