CMP426 Network and Cyber Security

Network and Cyber SecurityUnit 49 min read

Hash Functions & Digital Signatures: How Data Integrity & Authenticity Work

Unit 4 of Network and Cyber Security explores hash functions (how data is condensed into fixed-size fingerprints) and digital signatures (how to prove authenticity and non-repudiation), including their cryptographic principles, attacks, and real-world applications in security protocols like TLS and blockchain.

TAKEAWAYS:

  • Hash functions convert any input into a fixed-length hash (e.g., SHA-256), ensuring data integrity and collision resistance.
  • Digital signatures use asymmetric cryptography (RSA/ECDSA) to sign data, proving authenticity and non-repudiation.
  • Common attacks (collision, preimage, birthday) exploit weaknesses in weak hash functions (e.g., MD5, SHA-1).
  • Real-world uses: Password storage (bcrypt), blockchain (Bitcoin), and secure file verification (PGP).
  • TLS/SSL uses hashes (HMAC) and signatures to secure web traffic (HTTPS).
  • Exam focus: Compare hash functions, explain RSA signing, and trace a digital signature verification process.

1. Hash Functions: The Digital Fingerprint

A hash function takes any input (file, message, password) and produces a fixed-length hash value (e.g., 256-bit for SHA-256). Key properties:

  • Deterministic: Same input → same hash.
  • Fixed-length: Output is always the same size (e.g., 256 bits).
  • Preimage resistance: Hard to reverse (given hash, find input).
  • Collision resistance: Hard to find two different inputs with the same hash.

How Hash Functions Work

Input Data (e.g., 'hello')Hash Function (SHA-256)Fixed-Length Hash (e.g.,'2cf24dba5fb0a30e26e83b2ac5b9e29e1Stored/Verifiedone-way, irreversible
Hash function process: Input → Hash → Output (fixed-length)

Example: Storing passwords securely.

  • Bad practice: Store plaintext passwords (e.g., password123).
  • Good practice: Store hashes (e.g., 5f4dcc3b5aa765d61d8327deb882cf99 for SHA-256 of password).
  • Even better: Use salted hashes (add random data to prevent rainbow table attacks).

Common Hash Functions

Algorithm Output Size Security Level Use Cases
MD5 128-bit Broken Legacy systems (avoid)
SHA-1 160-bit Weak Deprecated (collision attacks)
SHA-256 256-bit Secure Bitcoin, TLS, file verification
bcrypt Variable Secure Password storage (slow hashing)
064128192256MD5128SHA-1160SHA-256256SHA-3256
Bit-length of common hash functions (MD5/SHA-1 are now considered insecure)

Hash Function Attacks

  1. Preimage Attack: Given H(x), find x (e.g., cracking MD5 hashes).
  2. Second Preimage Attack: Find x' such that H(x) = H(x').
  3. Collision Attack: Find any two inputs x ≠ y with H(x) = H(y).

Worked Example: Detecting File Tampering

  • Scenario: You download a software file (app.exe) from a website. How do you verify it’s not corrupted?
  • Solution:
    1. Website provides a SHA-256 hash of the original file: a1b2c3....
    2. You download app.exe and compute its hash locally.
    3. If your hash ≠ website’s hash → file is tampered with.

2. Digital Signatures: Proving Authenticity

A digital signature uses asymmetric cryptography (public/private keys) to:

  • Sign data (prove you created it).
  • Verify signatures (prove sender’s identity).
  • Ensure non-repudiation (sender can’t deny sending).

How Digital Signatures Work (RSA Example)

sequenceDiagram
    participant Alice as Alice (Sender)
    participant Bob as Bob (Receiver)
    participant Hash as Hash Function
    participant RSA as RSA Algorithm

    Alice->>Hash: Compute H(M) (hash of message M)
    Alice->>RSA: Encrypt H(M) with private key → Signature (S)
    Alice->>Bob: Send (M, S)
    Bob->>RSA: Decrypt S with Alice's public key → H'(M)
    Bob->>Hash: Compute H(M) (hash of received M)
    Bob->>Bob: Compare H(M) == H'(M) → Verify

Steps:

  1. Signing:
    • Alice hashes the message (H(M)).
    • Encrypts the hash with her private key → signature (S).
    • Sends (M, S) to Bob.
  2. Verification:
    • Bob decrypts S with Alice’s public key → H'(M).
    • Bob hashes M → H(M).
    • If H(M) == H'(M) → signature is valid.

Real-World Example: Bitcoin Transactions

  • Problem: How does Bitcoin ensure transactions are authentic?
  • Solution:
    1. A transaction is hashed (e.g., SHA-256).
    2. The sender signs the hash with their private key.
    3. The signature is broadcast to the network.
    4. Nodes verify the signature using the sender’s public key (stored in the blockchain).
    • Why it matters: Prevents double-spending and fraud.

Digital Signature Algorithms (DSAs)

Algorithm Key Size Use Case
RSA 2048–4096 TLS, code signing
ECDSA 256–521 Bitcoin, lightweight apps
DSA 1024–3072 Legacy systems
RSA (asymmetric)DSA (asymmetric)ECDSA (elliptic curve)EdDSA (Edwards curve)Digital Signature Algorithms
Major digital signature algorithms (asymmetric only)

Advantages:

  • Authenticity: Only the private key holder can sign.
  • Integrity: Any tampering breaks the signature.
  • Non-repudiation: Sender can’t deny sending.

Disadvantages:

  • Computationally heavy (slower than symmetric encryption).
  • Key management is critical (lose private key → lose access).

3. Hash Functions vs. Digital Signatures

Feature Hash Functions Digital Signatures
Purpose Data integrity, checksums Authenticity, non-repudiation
Input Any data (file, message) Hash of data + private key
Output Fixed-length hash Encrypted hash (signature)
Verification Compare hashes Decrypt signature with public key
Security Preimage/collision resistance Asymmetric cryptography
Example Use Password storage, file checks Code signing, TLS, blockchain

4. Applications in Real World

In Nepal

  1. eSewa & Khalti Payments

    • Hashing: Transactions are hashed to ensure no tampering.
    • Digital Signatures: Merchants sign transactions with private keys; eSewa verifies with public keys.
    • Why it matters: Prevents fraud in online payments.
  2. Nepal Rastra Bank (NRB) Digital Transactions

    • Digital signatures are used in NEFT/RTGS transfers to authenticate senders.
    • Example: When you transfer money via an app, the bank verifies your signature to confirm the transaction is from you.
  3. NEPSE (Nepal Stock Exchange)

    • Hashing: Used to verify trade orders (e.g., SHA-256 for order books).
    • Digital signatures: Brokers sign trades to prevent forgery.

Globally

  1. WhatsApp End-to-End Encryption

    • Hashing: Used to verify message integrity.
    • Digital signatures: Used in Signal Protocol to authenticate users.
    • Example: When you send a message, WhatsApp signs it with your private key; the recipient verifies it with your public key.
  2. Git Version Control

    • Hashing: Every commit is assigned a SHA-1 hash (e.g., a1b2c3...).
    • Why it matters: Ensures no one alters the code history.
  3. YouTube Video Authenticity

    • Digital signatures: Used to verify video uploads (prevent deepfake spoofing).

5. Exam Tip: How to Score Full Marks

  1. Define Clearly:

    • "A hash function is a deterministic, fixed-length function that maps input to a hash value with preimage/collision resistance."
    • "A digital signature is a mathematical scheme for verifying authenticity using asymmetric cryptography."
  2. Compare Hash Functions:

    • Always mention MD5/SHA-1 (broken) vs. SHA-256/SHA-3 (secure) in exams.
    • Example answer:

      "MD5 is vulnerable to collision attacks, while SHA-256 is collision-resistant and used in Bitcoin. SHA-1 is deprecated due to practical collision attacks in 2017."

  3. Trace a Digital Signature Process:

    • Signing: Hash → Encrypt with private key.
    • Verification: Decrypt with public key → Compare hashes.
    • Example:

      "Alice signs a contract by hashing it (SHA-256) and encrypting the hash with her RSA private key. Bob verifies by decrypting with Alice’s public key and comparing hashes. If they match, the signature is valid."

  4. Real-World Applications:

    • Link to eSewa (payments), Bitcoin (transactions), or TLS (HTTPS).
    • Example:

      "In TLS, digital signatures ensure a website’s certificate is authentic. The browser verifies the signature using the CA’s public key."

  5. Attack Scenarios:

    • Weak hash: "MD5 is broken; use SHA-256 for passwords."
    • Collision attack: "SHA-1 collisions can forge certificates (e.g., 2017 Shattered attack)."
  6. Diagrams:

    • Draw a hash function process (input → hash → verification).
    • Draw a digital signature sequence diagram (signing → verification).

Final Note: Hash functions and digital signatures are the backbone of secure communications. Master their definitions, processes, and real-world uses to ace the exam!

Based on the PU BE Computer (PU) syllabus for Network and Cyber Security (CMP426), unit 4.

Discussion

Loading…