CMP426 Network and Cyber Security

Network and Cyber SecurityUnit 36 min read

Public Key Cryptography: RSA, ECC, Diffie-Hellman, Digital Signatures

Unit 3 of Network and Cyber Security explores asymmetric cryptography, covering RSA, ECC, Diffie-Hellman key exchange, and digital signatures, with real-world applications in secure communications, authentication, and blockchain.

Key Concepts and Definitions

What is Public Key Cryptography?

Public key cryptography (asymmetric cryptography) uses a pair of keys: a public key (shared openly) and a private key (kept secret). Data encrypted with the public key can only be decrypted with the private key, and vice versa. This solves the key distribution problem inherent in symmetric cryptography.

stateDiagram-v2
    [*] --> PublicKey: Shared openly
    [*] --> PrivateKey: Kept secret
    PublicKey --> Encrypt: Data
    PrivateKey --> Decrypt: Data
    PrivateKey --> Sign: Data
    PublicKey --> Verify: Signature

Why Use Public Key Cryptography?

  • Key Distribution: No need to securely share a single key.
  • Authentication: Digital signatures prove identity.
  • Non-repudiation: The sender cannot deny sending a message.
  • Confidentiality: Secure communication without pre-shared secrets.

RSA Algorithm: The Workhorse of Asymmetric Cryptography

How RSA Works

RSA relies on the mathematical difficulty of factoring large prime numbers. The steps are:

  1. Key Generation:
    • Choose two large primes and .
    • Compute (modulus).
    • Compute Euler’s totient function .
    • Choose an integer (public exponent) such that and .
    • Compute (private exponent) as the modular inverse of modulo .
  2. Encryption: .
  3. Decryption: .

Worked Example: RSA Encryption

Let’s encrypt the message using:

  • , , so .
  • .
  • Choose (since ).
  • Compute (since ).

Encryption: .

Decryption: .


Elliptic Curve Cryptography (ECC): Efficiency in Smaller Keys

Why ECC?

ECC provides equivalent security to RSA but with smaller key sizes. For example, a 256-bit ECC key offers security comparable to a 3072-bit RSA key. This makes ECC faster and more efficient for resource-constrained devices (e.g., smartphones, IoT).

How ECC Works

ECC relies on the algebraic structure of elliptic curves over finite fields. The security is based on the Elliptic Curve Discrete Logarithm Problem (ECDLP), which is computationally hard.

classDiagram
    class EllipticCurve {
        +Equation: y² = x³ + ax + b
        +PointAddition: P + Q = R
    }
    class ECC {
        +KeyGeneration: PrivateKey + BasePoint
        +Encryption: PublicKey + Plaintext
        +Decryption: PrivateKey + Ciphertext
    }
    EllipticCurve <|-- ECC

Comparison: RSA vs. ECC

Feature RSA ECC
Key Size Large (e.g., 2048-bit) Small (e.g., 256-bit)
Security Factoring large primes ECDLP
Speed Slower Faster
Use Case General-purpose encryption Mobile, IoT, blockchain

Diffie-Hellman Key Exchange: Secure Key Agreement

Problem Solved

How can two parties securely agree on a shared secret over an insecure channel? Diffie-Hellman (DH) solves this using exponential modular arithmetic.

How DH Works

  1. Both parties agree on a public prime and a generator .
  2. Alice picks a private key , computes , and sends to Bob.
  3. Bob picks a private key , computes , and sends to Alice.
  4. Alice computes the shared secret .
  5. Bob computes the shared secret .

Worked Example: DH Key Exchange

Let , .

  • Alice picks , computes .
  • Bob picks , computes .
  • Shared secret:
    • Alice: .
    • Bob: .

Digital Signatures: Proving Authenticity

How Digital Signatures Work

  1. The sender signs a message using their private key.
  2. The recipient verifies the signature using the sender’s public key.
  3. Common algorithms: RSA, ECC, DSA (Digital Signature Algorithm).

Worked Example: RSA Digital Signature

  1. Alice hashes the message to get .
  2. She signs with her private key : .
  3. Bob verifies by computing and checking if it matches the hash of the received message.

In the Real World

  1. eSewa and Khalti (Nepal):

    • Use ECC or RSA for secure transactions. When you pay via Khalti, your card details are encrypted with the merchant’s public key, ensuring confidentiality. The digital signature on the transaction proves you authorized it (non-repudiation).
  2. WhatsApp End-to-End Encryption:

    • Uses the Signal Protocol, which combines Diffie-Hellman for key exchange and AES (symmetric) for message encryption. Your private key never leaves your device, and even WhatsApp cannot read your messages.
  3. Nepal Stock Exchange (NEPSE):

    • Trades are authenticated using digital signatures (likely RSA or ECC) to prevent fraud. When you place an order, the exchange verifies your signature with your public key to confirm you are authorized.
  4. Pathao Driver-Passenger Matching:

    • When a driver accepts a ride request, Diffie-Hellman is used to establish a secure session key for real-time location sharing and payment processing. This ensures no third party can intercept or alter the data.

Exam Tip

  1. Understand the Math: Focus on the modular arithmetic in RSA and DH. Be able to compute small examples manually (e.g., ).
  2. Key Differences: Memorize the trade-offs between RSA, ECC, and DH (key size, speed, use cases).
  3. Digital Signatures: Know how hashing + private key signing + public key verification works. Practice a full trace.
  4. Real-World Applications: Link algorithms to systems like TLS (uses RSA/ECC for key exchange), Bitcoin (ECDSA for signatures), and VPNs (IKE uses DH).
  5. Security Assumptions: RSA relies on factoring hardness; ECC on ECDLP; DH on discrete log hardness. Examiners may ask which problem each algorithm resists.
  6. Diagrams: Draw the RSA/ECC/DH workflows in exams. A well-labeled sequence diagram for DH or a state diagram for signature verification can earn easy marks.

digital signature verification processHow a recipient verifies an RSA digital signature. (Image: FlippyFlink, CC BY-SA 4.0, via Wikimedia Commons)

Based on the PU BE Computer (PU) syllabus for Network and Cyber Security (CMP426), unit 3.

Discussion

Loading…