This commit is contained in:
John Gatward committed 2026-10-04 15:24:17 +01:00
1 parent d0f27f276b
commit d6f54d4ec2
103 files changed
+3663 -3779

No files matched your search

+26 -27
View File
@@ -10,7 +10,7 @@
**Asymmetric**
>“Methods which use separate, but related, private and public keys.”
> “Methods which use separate, but related, private and public keys.”
**Protocols**
@@ -20,7 +20,7 @@
> “The science and art of breaking cryptosystems.”
### Modern Cyptography (1970-)
### Modern Cryptography (1970-)
**Fundamentally different** - a scientific and mathematical discipline
@@ -46,13 +46,12 @@
- Modular arithmetic is a system of arithmetic for finite sets of integers
- Common sets include
- $\mathbb{N} = \{1,2,3,...\}$
- $\mathbb{Z} = \{..., -3, -2, -1, 0,1,2,3,...\}$
- Also $\mathbb{Q}, \mathbb{R}, \mathbb{C}$
- $\mathbb{N} = \{1,2,3,...\}$
- $\mathbb{Z} = \{..., -3, -2, -1, 0,1,2,3,...\}$
- Also $\mathbb{Q}, \mathbb{R}, \mathbb{C}$
- Cryptography is almost always interested in finite sets
- This is useful as it avoids overflow errors
- When we add or multiply two 1 byte binary digits, the result will always be 1 byte
- When we add or multiply two 1 byte binary digits, the result will always be 1 byte
###### Congruence
@@ -73,7 +72,7 @@ This can be rewritten as: $a = q\cdot m+r$
###### Equivalence Classes
- The sets of all integers **mod 5** form a series of equivalence classes
- All these numbers act the same in any modluo sum
- All these numbers act the same in any modulo sum
For example
@@ -99,25 +98,25 @@ The integer ring $\mathbb{Z}_m$ consists of:
1. The set $\mathbb{Z}_m = \{0, 1,\ldots m-1\}$
2. Two operations $+$ and $\cdot$ for all $a, b \in \mathbb{Z}_m$ such that:
1. $a+b \equiv c \space (mod\space m), (c\in \mathbb{Z})$
2. $a\cdot b \equiv d \space (mod\space m), (d\in \mathbb{Z})$
1. $a+b \equiv c \space (mod\space m), (c\in \mathbb{Z})$
2. $a\cdot b \equiv d \space (mod\space m), (d\in \mathbb{Z})$
Any time you add or multiply any two numbers in the set, the result is always in the set. We use $\equiv$ instead of $=$ as it could be an intermediatary number e.g. 12 instead of 2.
Any time you add or multiply any two numbers in the set, the result is always in the set. We use $\equiv$ instead of $=$ as it could be an intermediate number, e.g. 12 instead of 2.
##### Properties of Rings
- We can add or multiply any two numbers in the ring, and the result is in the ring
- It is closed
- It is closed
- Addition and multiplication are associative
- (a+b)+c = a + (b+c)
- (a+b)+c = a + (b+c)
- There is a neutral element 0 for addition
- $a + 0 \equiv a\space mod \space m$
- $a + 0 \equiv a\space mod \space m$
- The additive inverse always exists
- $a + (-a) = 0\space mod \space m$
- $a + (-a) = 0\space mod \space m$
- There is a neutral element for multiplication
- $a\cdot 1 \equiv a\space mod\space m$
- $a\cdot 1 \equiv a\space mod\space m$
- The multiplicative inverse exists for some but not all elements
- $a\cdot a^{-1} \equiv 1 \space mod \space m$
- $a\cdot a^{-1} \equiv 1 \space mod \space m$
#### Modular Inversion
@@ -158,7 +157,7 @@ $$
##### Frequency Analysis
- The frequency of occurrences of each character are very consistent
- The frequency of occurrences of each character is very consistent
- The longer a cipher text is, the easier this becomes
#### Affine Cipher
@@ -174,23 +173,23 @@ $$
where $k=(a,b)$ and $gcd(a,26)=1$
This is a multiplication and a addition analagous to $y=mx+c$
This is a multiplication and an addition analogous to $y=mx+c$
In a Affine cipher, letters can be themselves
In an Affine cipher, letters can be themselves
- The keyspace of an affine cipher
- a can be 0-25
- b can be 0-12
- 25*12=300
- More secure than a caesar cipher
- a can be 0-25
- b can be 0-12
- 25*12=300
- More secure than a Caesar cipher
Frequency analysis can still be used, in this case the columns will not only be shifted, but jumbled aswell.
Frequency analysis can still be used; in this case the columns will not only be shifted, but jumbled as well.
- This is not hard to crack
#### The Vigenere Cipher
- An early stream cipher, the Vigenere cipher is a shift cipher with a running key
- Unlike caesar cipher, the key is repeated for as long as required.
- Unlike the Caesar cipher, the key is repeated for as long as required.
- It is the equivalent to multiple interleaved Caesar ciphers
- Spreads outs occurrances of characters making frequency analysis hard.
- Spreads out occurrences of characters, making frequency analysis hard.
+16 -18
View File
@@ -20,9 +20,7 @@ d_{s_i} (y_i) \equiv (x_i + 0\cdot s_i \space (mod\space 2) \\
d_{s_i} (y_i) \equiv x_i
$$
Note: 2 % 2 is 0, its like **xor**-ing twice.
Note: 2 % 2 is 0; it's like **xor**-ing twice.
#### Security of XOR
@@ -44,12 +42,12 @@ The security of a stream cipher depends entirely on the nature of the key stream
##### True Randomness
- True randomness is impossible to recreate except by chance
- coin flips
- coin flips
- Computer systems often use hardware sources for randomness
- Thermal or other noise
- Radioactive decay
- Clock drift
- Random timings of interrupts
- Thermal or other noise
- Radioactive decay
- Clock drift
- Random timings of interrupts
##### Pseudo Randomness
@@ -58,7 +56,7 @@ The security of a stream cipher depends entirely on the nature of the key stream
###### Linear Congruential Generator
Cs `rand()` function, this is a PRNG
C's `rand()` function is a PRNG
$$
s_0 = 12345 \\
@@ -76,7 +74,7 @@ $$
#### Unconditional Security
A crypto-system is **unconditional security** is unconditionally or information-theoretically secure if it cannot be broken, even with infinite computational resources.
A cryptosystem has **unconditional security**: it is unconditionally or information-theoretically secure if it cannot be broken, even with infinite computational resources.
**Perfect Secrecy**: The cipher-text should reveal no information about the plain text
@@ -84,7 +82,7 @@ $\forall_{m_0, m_1} \in M$ where $|m_0| = |m_1|$ and $\forall_c \in C$
$Pr[E(k,m_0) = c] = Pr[E(k,m_1) = c]$
The probability that $m_0$ encrypts to $c$ is the same as the probability of $m_1$ also encrypted to $c$
The probability that $m_0$ encrypts to $c$ is the same as the probability of $m_1$ also being encrypted to $c$
## One Time Pad
@@ -134,7 +132,7 @@ $$
#### Crib Dragging
This involves guessing $M_1$, this can be a common message such as `HTTP` request.
This involves guessing $M_1$; this can be a common message such as an `HTTP` request.
This can be automated by checking $M_1$ over different parts of $M_2$.
@@ -145,14 +143,14 @@ This can be automated by checking $M_1$ over different parts of $M_2$.
- Numbers used once or *nonces* are vital for stream cipher security
- Instead of always using a unique key, the security requirement is you always use a unique (key + nonce) pair
- Nonces are not secret, they are public random seed for a key stream
- Nonces are not secret; they are public random seeds for a key stream
### Could we use a LCG?
### Could we use an LCG?
- LCG - Linear congruential generators
- Seed using some key, then
- $s_{i+1} \equiv A \cdot s_i + B \space (mod \space 2)$
- $s_i, A, B$ are $log_2m$ bits long
- $s_{i+1} \equiv A \cdot s_i + B \space (mod \space 2)$
- $s_i, A, B$ are $log_2m$ bits long
- This is trivial to break
- Given known plaintext $x_1, x_2, x_3$
- Calculate corresponding key $s_1, s_2, s_3$
- Given known plaintext $x_1, x_2, x_3$
- Calculate corresponding key $s_1, s_2, s_3$
+19 -19
View File
@@ -2,23 +2,23 @@
### Pseudo-randomness
- TRNGs - true Random Number Generator
- Not feasible at scale
- PRNGs - Pseudo Random Number Generator
- CSPRNGs - Cryptographically Secure Pseudo Random Number Generator
- TRNGs - True Random Number Generators
- Not feasible at scale
- PRNGs - Pseudo-random Number Generators
- CSPRNGs - Cryptographically Secure Pseudo-random Number Generators
#### LFSRs
- A Linear-feedback Shift Register us a register if buts whose positions shift to the right
- A linear-feedback shift register is a register of bits whose positions shift to the right
- Usually comprised of flip-flops, the last bit represents the output
(Where the squares at the bottom are flip-flops)
- If initialised to `000`, nothing happens as $0\oplus0 = 0$.
- Therefore, we have $2^n-1$ states
- Statistical randomness
- Therefore, we have $2^n-1$ states
- Statistical randomness
- To add more randomness to the setup, we can add another (more) `xor` gate
- However, we have fewer states
- However, we have fewer states
$$
s_m \equiv s_{m-1}p_{m-1} + ... + s_1p_1 + s_0p_0\space (mod \space 2)\\
@@ -27,11 +27,11 @@ $$
- We usually represent m-bit LFSRs using polynomials of degree m.
- In general $P(x)=x^m + p_{m-1}x^{m-1} + ... + p_1x + p_0$
- LFSRs that have primitive polynoimials produce sequences of maximum length
- There are many and are easily computed
- $x^5 + x^2 + 1$ has 31 states
- $x^{10} + x^3 + 1$ has 1023
- $x^{85}+x^8+x^2+x+1$ has $10^{26}$ states
- LFSRs that have primitive polynomials produce sequences of maximum length
- There are many, and they are easily computed
- $x^5 + x^2 + 1$ has 31 states
- $x^{10} + x^3 + 1$ has 1023
- $x^{85}+x^8+x^2+x+1$ has $10^{26}$ states
##### Attacking LFSRs
@@ -55,31 +55,31 @@ $s_{2m+1} \equiv s_{2m-1}p_{m} + ... + s_mp_1 + s_{m-1}p_0$
- LFSRs are much more cryptographically secure if we combine more than one together in a non-linear way.
Trivium is 3 LFSR in a row
Trivium is 3 LFSRs in a row
- Feedback between each with non-linear AND gates
- Initialises the LFSR with an 80-bit key and 80-bit random value
### ChaCha20
- ChaCha is a stream cipher written by Daniel Berstein
- ChaCha is a stream cipher written by Daniel Bernstein
- A modification of a previous cipher, Salsa
- Very lightweight, using only `add`, `xor` and rotate operations
- One of two ciphers in `TLS 1.3`
- Dashes represent bit length
- Constants are not secret
- The block number can skip to anywhere
- Suppose someone skips ahead on a video stream, the cipher can skip unlike other synchronous stream ciphers
- Suppose someone skips ahead on a video stream, the cipher can skip unlike other synchronous stream ciphers
- Works well on low power devices, due to simplicity of encryption
- Once the input and the mixed words are added together it is hard to know what the starting thing was
- e.g. what two numbers have i added to make 100
- e.g. what two numbers have I added to make 100
ChaCha performs **20** rounds
- Alternates column and diagonal rounds
- Each round is 4 quarter rounds
- Each round is 4 quarter rounds
#### Vulnerabilities
- Stream ciphers like ChaCha give us *confidentiality*, but *not integrity*
- Running a stream cipher by itself is not sufficient
- Running a stream cipher by itself is not sufficient
@@ -4,35 +4,35 @@
- A pseudorandom permutation is a function that cannot be distinguished from a random permutation
- Maps a set of values $\{0,1\}^n \times \{0,1\}^s \rightarrow \{0,1\}^n$ such that:
- For any key, the function F is a *bijection* (1:1)
- The key just changes the mapping
- There is an *efficient algorithm* to calculate $F(x)$ for all keys and all messages
- For any key, the function F is a *bijection* (1:1)
- The key just changes the mapping
- There is an *efficient algorithm* to calculate $F(x)$ for all keys and all messages
![1645042514.png](img/1645042514.png)
**Confusion**: Obscure the relationship between plaintext, key and ciphertext
- Often achieved through substitution operations
- Using lookup tables
- Using lookup tables
**Diffusion**: Influence of each plaintext and key bit is distributed throughout the ciphertext
- Achieved via permutation
- Swapping or otherwise mixing bits/bytes
- Swapping or otherwise mixing bits/bytes
Shannon called a cipher like this a **product cipher**
### Feistal Network
### Feistel Network
- A Feistal Network is one mechanism used to create block ciphers
- Developed by Horst Feistal while he worked at IBM
- A Feistel network is one mechanism used to create block ciphers
- Developed by Horst Feistel while he worked at IBM
- Underpins DES, GOST, Blowfish, Twofish and numerous others.
![1645042957.png](img/1645042957.png)
- To decrypt, we run the encrypted bits through the network again
##### A Single Feistal Round
##### A Single Feistel Round
- During each round, only half of the block is encrypted
@@ -58,17 +58,17 @@ Note - the last round does a final swap so the left and right are in the correct
Basically the `xor`s cancel themselves out, the most important part is choosing a good function $f$
#### About Feistal Networks
#### About Feistel Networks
- 1 or 2 rounds is not sufficient
- 1 or 2 rounds are not sufficient
- Luby and Rackoff show that if $f$ is a cryptographically secure pseudorandom function then:
- 3 rounds are sufficient to make a pseudorandom permutation
- 4 rounds are sufficient to make a strong pseudorandom permutation
- Balanced Feistal networks
- L and R are equal sizes
- Unbalanced feistal networks
- L and R can be different sizes
- e.g. `skipjack`, `OAEP`
- 3 rounds are sufficient to make a pseudorandom permutation
- 4 rounds are sufficient to make a strong pseudorandom permutation
- Balanced Feistel networks
- L and R are equal sizes
- Unbalanced Feistel networks
- L and R can be different sizes
- e.g. `skipjack`, `OAEP`
### DES
@@ -78,10 +78,10 @@ Basically the `xor`s cancel themselves out, the most important part is choosing
1976: NIST accepts an altered version of DES following consultation with NSA
- Feistal network with 64-bit block size
- Feistel network with 64-bit block size
- 56-bit key
- The most studied cipher in history
- Hasn’t been broken for over 46 years
- Hasn’t been broken for over 46 years
![1645044034.png](img/1645044034.png)
@@ -93,7 +93,7 @@ This speeds up loading bits into registers
![1645044186.png](img/1645044186.png)
$S_1, S_2....$ are called s-boxes. These substitute 6 bits input to 4 bits output based on lookup tables. The lookup tables for each s-box is different.
$S_1, S_2....$ are called s-boxes. These substitute 6-bit inputs with 4-bit outputs based on lookup tables. The lookup tables for each s-box are different.
##### Expansion
@@ -107,7 +107,7 @@ $S_1, S_2....$ are called s-boxes. These substitute 6 bits input to 4 bits outpu
##### Substitution Boxes
- Add confusion
- The s-boxes map 6 bit inputs to 4-bit outputs
- The s-boxes map 6-bit inputs to 4-bit outputs
- There are 8 s-boxes in total, each is different
![1645044443.png](img/1645044443.png)
@@ -115,19 +115,19 @@ $S_1, S_2....$ are called s-boxes. These substitute 6 bits input to 4 bits outpu
- This s-box is not random, very carefully designed
- s-boxes need to be highly **non-linear**: $S(a) \oplus S(b) \neq S(a\oplus b)$
- This prevents simple systems of linear equations such as we saw in LFSRs.
- The formula needed to represent DES is too complicated
- The formula needed to represent DES is too complicated
- Key design principles
1. No output bit should be too close to a linear combination of input bits
2. 1-bit change input should lead to at least 2-bits output
3. If you only change the 4 middle bits, each output must occur exactly once
4. If the first two bits are different but the last two are identical, the output must differ
5. For any non-zero difference in input, no more than 8 of the 32 inputs exhibiting this difference should share the same output difference
- We want to limit the number of predictable swaps
6. A collision (zero difference) is only possible for 3 adjacent s-boxes
1. No output bit should be too close to a linear combination of input bits
2. 1-bit change input should lead to at least 2-bits output
3. If you only change the 4 middle bits, each output must occur exactly once
4. If the first two bits are different but the last two are identical, the output must differ
5. For any non-zero difference in input, no more than 8 of the 32 inputs exhibiting this difference should share the same output difference
- We want to limit the number of predictable swaps
6. A collision (zero difference) is only possible for 3 adjacent s-boxes
##### Permutation
- At the end of $f()$ is a permuatation
- At the end of $f()$ is a permutation
- This moves bits between s-boxes on the next round
![1645044919.png](img/1645044919.png)
@@ -138,11 +138,11 @@ $S_1, S_2....$ are called s-boxes. These substitute 6 bits input to 4 bits outpu
If you input all 0s, we will see a random cipher text
However if we change one 0 to a 1, how does this effect the result.
However, if we change one 0 to a 1, how does this affect the result?
- On average, if you change one (first) bit in $R$, one bit will change in the expansion
- Due to the way the s-boxes are setup, at least 2 of the 4 bits in the output will be different
- Due to the way the s-boxes are set up, at least 2 of the 4 bits in the output will be different
- Now when the permutation happens, these two changes are spread to other s-boxes
- Now next round we’ll get 4 changes, then 8, then 16 …
For DES the worst case scenario when one bit is changed (with 5 rounds) is there will be an effect on every bit on the output.
For DES the worst case scenario when one bit is changed (with 5 rounds) is there will be an effect on every bit on the output.
+33 -33
View File
@@ -3,11 +3,11 @@
#### Key Schedule
- The **DES** key schedule simply returns various permutations of $k$ as sub-keys
- $k_1, ... k_{16}$
- $k_1, ... k_{16}$
##### PC-1
- Permutated Choice 1 (PC-1) selects 56 of the 64 bits
- Permuted Choice 1 (PC-1) selects 56 of the 64 bits
- The other ‘parity’ bits are discarded: DES only uses a 56-bit key
- Key bits are spread throughout the initial state of the key schedule
- Key bits 8, 16, 24,…64 are not used
@@ -16,14 +16,14 @@
#### Left Rotation
- Left rotations (often written as `<<<`) represent a lift shift where the left most numbers wrap around to the right hand side
- Left rotations (often written as `<<<`) represent a left shift where the leftmost numbers wrap around to the right-hand side
- In DES, each 28-bit block is rotated left by `<<<1` for rounds 1,2,9,16 and `<<<2` otherwise
- The total rotation is $4\cdot 1 + 12\cdot 2 = 28$ which means $C_0 = C_{16}$ and $D_0 = D_{16}$
- NOTE: $C_0$ or $D_0$ is not used
- NOTE: $C_0$ or $D_0$ is not used
##### PC-2
- Permuted Choice 2 select 48 of the 56 bits to be used as a round key
- Permuted Choice 2 selects 48 of the 56 bits to be used as a round key
![1645476385.png](img/1645476385.png)
@@ -31,8 +31,8 @@
- Is entirely permutation based
- Doesn’t use `xor`, addition or any other mixing operation
- Because $C_0 = C_{16}$ and $D_0 = D_{16}$ we don’t need to write seperate encrpt and decrypt functions
- Usful for writing implementations on low memory devices (smart cards)
- Because $C_0 = C_{16}$ and $D_0 = D_{16}$ we don’t need to write separate encrypt and decrypt functions
- Useful for writing implementations on low-memory devices (smart cards)
### Breaking DES
@@ -47,10 +47,10 @@ NOTE: $2^{56}-1$ is a very large number
#### Key Collisions
- For a 56-bit key but a 64-bit block is possible (though unlikely) a different key would work
- For a 56-bit key but a 64-bit block, it is possible (though unlikely) that a different key would work
- How likely is this to happen for a 1 bit key and an $n$ bit block cipher
- $\frac{2^l}{2^n}$ where $l$ is the length of the block and $n$ is the key length
- $\frac{2^{64}}{2^{56}} = 2^8$
- $\frac{2^l}{2^n}$ where $l$ is the length of the block and $n$ is the key length
- $\frac{2^{64}}{2^{56}} = 2^8$
![1645477137.png](img/1645477137.png)
@@ -64,15 +64,15 @@ NOTE: $2^{56}-1$ is a very large number
![1645477338.png](img/1645477338.png)
- Naive brute fource suggests $2^{56}\cdot 2^{56} = 2^{112}$ keyspace
- However using a meet-in-the middle attack this becomes trival.
- Step 1: Calculate encryptions of $x_1$ for all $k_{1...,i}$ and store intermediate values $Z_{1..,i}$
- Step 2: Calculate all decryptions of $y_1$ for all $k_{R, j}$ to find $Z_{R,i}$
- Step 3: Find any value of $Z_{R,j}$ matching existing $Z_L,i$
- Naive brute force suggests $2^{56}\cdot 2^{56} = 2^{112}$ keyspace
- However, using a meet-in-the-middle attack, this becomes trivial.
- Step 1: Calculate encryptions of $x_1$ for all $k_{1...,i}$ and store intermediate values $Z_{1..,i}$
- Step 2: Calculate all decryptions of $y_1$ for all $k_{R, j}$ to find $Z_{R,i}$
- Step 3: Find any value of $Z_{R,j}$ matching existing $Z_L,i$
![1645477760.png](img/1645477760.png)
Meet-in-the-middle requires $2^{k+1}$ attemps rather than $2^{k\cdot 2}$
Meet-in-the-middle requires $2^{k+1}$ attempts rather than $2^{k\cdot 2}$
- This is much better than brute force, but doesn’t make it easy
- Trades off computation for storage - Petabytes for DES
@@ -81,7 +81,7 @@ Meet-in-the-middle requires $2^{k+1}$ attemps rather than $2^{k\cdot 2}$
## 3DES
- Triple DES uses three different keys
- Either `enc -> enc -> enc` or `enc -> dec -> enc`
- Either `enc -> enc -> enc` or `enc -> dec -> enc`
- Often used in banking, smart cards and other payment systems
![1645478048.png](img/1645478048.png)
@@ -100,34 +100,34 @@ This is why banking systems use 3DES as they already have the infrastructure for
![1645478296.png](img/1645478296.png)
- Theoretically this provides a seach space of $2^{k+2n}$ but meet-in-the-middle can be used here, as well as other more advanced attacks
- In practive securtity is $2^{k+n-m}$ where an attack has $2^m$ known plain texts
- Theoretically this provides a search space of $2^{k+2n}$ but meet-in-the-middle can be used here, as well as other more advanced attacks
- In practice, security is $2^{k+n-m}$ where an attack has $2^m$ known plain texts
# Cryptanalysis
#### What is a break?
- In modern cryptography, a cipher is declared broken by essentially any attack that is more efficient than brute force
- For example, *differential cryptanalysis* requires $2^{47}$ operations on DES rather than $2^{56}$
- For example, *differential cryptanalysis* requires $2^{47}$ operations on DES rather than $2^{56}$
- These are often academic breaks, rather than a practical security concern
- For example there is a *related key* attack on AES of $2^{99.5}$, compared to brute force of $2^{128}$
- Remember that a $2^{n-1}$ takes half the time $2^n$ does
- For example there is a *related key* attack on AES of $2^{99.5}$, compared to brute force of $2^{128}$
- Remember that a $2^{n-1}$ takes half the time $2^n$ does
##### Analytical Attacks
- Exploit some underlying structureal or mathematical weakness in a cipher
- e.g. meet in the middle attack
- Derivation of taps in LFSRs
- Exploit some underlying structural or mathematical weakness in a cipher
- e.g. meet in the middle attack
- Derivation of taps in LFSRs
##### Statistical Attacks
- Capture statistical patterns between input and output to recover key bits
- Differential cryptanalysis
- Linear cryptanalysis
- Differential cryptanalysis
- Linear cryptanalysis
###### Differential Cryptanalysis
- Different cryptanalysis is prehaps now the most important modern method for breaking block ciphers
- Differential cryptanalysis is perhaps now the most important modern method for breaking block ciphers
- It is a **chosen plaintext** attack
- We aim to find predictable changes in output bits caused by known changes in the input bits
@@ -141,15 +141,15 @@ This is why banking systems use 3DES as they already have the infrastructure for
![1645479256.png](img/1645479256.png)
- Tracing differentials through a cipher provides us with **differential characteristics** e.g.
- $(\Delta x, \Delta y) =$ (0x80, 0xA0) where $p \geq 2^{-3} = 1/8$
- $(\Delta x, \Delta y) =$ (0x80, 0xA0) where $p \geq 2^{-3} = 1/8$
- These can be calculated by hand or using automated tools
- The attack then looks for these expected differentials as you manipulate sub-key bits
###### Resisting differential cryptanalysis
- S-boxes must be designed such that the probability of any pair $(\Delta x, \Delta y)$ is as low as possible
- AES has a maximum likelihood of a differential per s-box of $2^{-6}$
- This is because AES has such good diffusion
- AES has a maximum likelihood of a differential per s-box of $2^{-6}$
- This is because AES has such good diffusion
- More rounds make differentials even less likely
- Good permuation to involve more s-boxes is vital
- DES was specifically designed to resist this kind of attack
- Good permutation to involve more s-boxes is vital
- DES was specifically designed to resist this kind of attack
+17 -17
View File
@@ -1,12 +1,12 @@
# Finite Field Arithmetic
- A **finite field** is a set containing a finite number of elements
- This is sometimes called a *Galois Field*
- This is sometimes called a *Galois Field*
- In a Galois field you can:
- Add
- Subtract
- Multiply
- Invert (divide)
- Add
- Subtract
- Multiply
- Invert (divide)
- Fields are an extension of *groups* and related to *rings*
### Groups
@@ -14,9 +14,9 @@
A group is a set of elements $G$ together with an operation $\circ$ that combines two elements of $G$
> 1. The operation $\circ$ is **closed**
> - i.e. for all $a,b \in G$ then $a\circ b=c\in G$
> - i.e. for all $a,b \in G$ then $a\circ b=c\in G$
> 2. The operation is associative
> - i.e. $a\circ(b\circ c) = (a\circ b)\circ c$ for all $a,b,c \in G$
> - i.e. $a\circ(b\circ c) = (a\circ b)\circ c$ for all $a,b,c \in G$
> 3. There is an element $1\in G$ called a **neutral element** such that $a\circ 1 = 1\circ a = a$ for all $a\in G$
> 4. For each $a \in G$ there exists an element $a^{-1}\in G$ called the **inverse** of $a$ such that $a\circ a^{-1} = a^{-1}\circ a = 1$
> 5. A group $G$ is **abelian** (commutative) if $a\circ b = b \circ a$ for all $a,b\in G$
@@ -26,7 +26,7 @@ A group is a set of elements $G$ together with an operation $\circ$ that combine
- The set of integers $\mathbb{Z}_m = \{0,1,...m-1\}$ with the operation addition modulo m form a group with the neutral element 0
- Every element would have an inverse where $a + (-a) = 0$ mod m
- This group would not form a group with multiplication, as not all elements would have an inverse
- We wouldn’t have an inverse, we would need $5\times \frac15=1$ however $\frac15 \notin \mathbb{Z}$
- We wouldn’t have an inverse; we would need $5\times \frac15=1$, but $\frac15 \notin \mathbb{Z}$
### Fields
@@ -35,12 +35,12 @@ A field $F$ is a set of elements with the following properties
> 1. All elements of $F$ form an **additive group** with the group operation $+$ and the neutral element 0
> 2. All elements of $F$ except 0 form a multiplicative group with the group operation $\times$ and the neutral element 1
> 3. When the two group operations are mixed, the distributivity law holds.
> - i.e. for all $a,b,c \in F, a\cdot(b+c) = (a\cdot b) + (a\cdot c)$
> - i.e. for all $a,b,c \in F, a\cdot(b+c) = (a\cdot b) + (a\cdot c)$
##### Example Field
- The set of real numbers $\mathbb{R}$ is a field with neutral element 0 for addition and 1 for multiplication
- Every real number $a$ has a additive inverse $-a$
- Every real number $a$ has an additive inverse $-a$
- Every non-zero number $a$ has a multiplicative inverse $\frac{1}{a}$
![1646405235.png](img/1646405235.png)
@@ -80,7 +80,7 @@ $a \cdot a^{-1} \equiv 1 \space (mod \space p)$
- A modular inverse exists when $gcd(a,p) = 1$
- Because $p$ is prime, every number has a multiplicative inverse
- $gcd(a,p) = 1, \forall a \neq0 \in GF(p)$
- $gcd(a,p) = 1, \forall a \neq0 \in GF(p)$
- $a^{-1}$ can be calculated using the **extended Euclidean algorithm**
#### Extension Fields
@@ -97,16 +97,16 @@ The coefficients of the polynomial are elements in $GF(2)$ the **sub-field**
##### Example $GF(2^3)$
- The field $GF(2^3)$, sometimes called $GF(8)$ is an extension field containing elements of the form: $A(x) = a_2 x^2 + a_1x^1 + a_0$
- Its often easier to simply write the coefficients $(a_2, a_1, a_0)$ e.g. 001 or 101
- It's often easier to simply write the coefficients $(a_2, a_1, a_0)$ e.g. 001 or 101
- $GF(2^3) = \{0, 1, x, x+1, x^2, x^2+1, x^2 + x, x^2 + x + 1\}$
- $|GF(2^3)| = 8$
- $|GF(2^3)| = 8$
#### Arithmetic in $GF(2^3)$
- Adding or subtracting two polynomials happens as expected, but adding the coefficients
- $A(x) = x^2 + x + 1$
- $B(x) = x^2 + 1$
- $A(x) + B(x) = (1+1)x^2 + (1)x + (1+1) = x$
- $A(x) = x^2 + x + 1$
- $B(x) = x^2 + 1$
- $A(x) + B(x) = (1+1)x^2 + (1)x + (1+1) = x$
- mod 2 is simply `xor`
- Addition and subtraction are identical
@@ -130,7 +130,7 @@ $$
- Inversion is performed in a similar way to prime fields, we find:
- $A(x) \cdot A^{-1}(x) \equiv 1 \space (mod \space P(x))$
- $A^{-1}(x)$ is calculated using the extended euclidean algorithm
- $A^{-1}(x)$ is calculated using the extended Euclidean algorithm
### AES’ Finite Field
+44 -38
View File
@@ -2,7 +2,7 @@
- AES superseded DES as a standard in 2002
![1646490755.png](img/1646490755.png)
![1646490755.png](img/1646490755.png)
- Uses rounds of 4 layers and a final round of 3
- Bytes are represented as a 4x4 block called the *state*
@@ -19,12 +19,12 @@ First row doesn’t move, second row is shifted to the left by 1, the third row
Then, when the columns are mixed, this means the overall diffusion is extremely good
The last round doesn’t have a **mix column** step as its reversible and wouldn’t add additional security.
The last round doesn’t have a **mix column** step as it's reversible and wouldn’t add additional security.
#### S-Box
- The AES s-box is based around the multiplicative inverse of 8-bit values in $GF(2^8)$
- This is strongly *non-linear* mapping
- This is a strongly *non-linear* mapping
$$
A_i \cdot A_i^{-1} \equiv 1 \space (mod \space P(x)) \\
@@ -37,7 +37,7 @@ $$
![1646491900.png](img/1646491900.png)
- Note: 0 maps to 0
- The inverses $B'_i$ then undergo an **affine transformation** to produce the final s-box
- The inverses $B'_i$ then undergo an **affine transformation** to produce the final s-box
- This destroys any remaining mathematical structure
![1646491995.png](img/1646491995.png)
@@ -46,15 +46,15 @@ Remember an affine transformation is a multiplication and addition by two consta
##### S-box Properties
- The s-box simply described, and is bijective, an invertible 1:1 mapping
- The s-box is simply described, and is bijective, an invertible 1:1 mapping
- It has no fixed points
- i.e. no $A_i$ for which $S(A_i) = A_i$
- i.e. no $A_i$ for which $S(A_i) = A_i$
- No inverse fixed points
- i.e. no $A_i$ for which $S(A_i) \oplus A_i = FF$
- i.e. no $A_i$ for which $S(A_i) \oplus A_i = FF$
- Minimisation of the largest non-trivial correlation between linear combinations of input bits and linear combinations of output bits
- 0 is a non-trivial combination
- 0 is a non-trivial combination
- Minimisation of the largest non-trivial value in the `EXOR` table
- This stops differential cryptanalysis
- This stops differential cryptanalysis
#### AES Diffusion
@@ -86,48 +86,54 @@ When multiplying by $x$, there’s a shortcut we can implement. We can set the e
- The first round key used is just the key
- We then take $W[3]$ and put it through the $g$ function which just permutes it
- $g$ takes the word, shifts it one to the right and then passes it through the s-boxes
- We then `xor` it with $RC[i]$ which is just a constant value to ensure *something* changes
- Like for example if we had a bit stream of all 0s
- $g$ takes the word, shifts it one to the right and then passes it through the s-boxes
- We then `xor` it with $RC[i]$ which is just a constant value to ensure *something* changes
- Like for example if we had a bit stream of all 0s
### Implementation
1. All addition and subtractions are `xor`
1. All additions and subtractions are `xor`
2. Multiply by `01` has no effect
2. Multiplying by `01` has no effect
3. Multiplying by `02` (which is $x$) is simply a left shift followed by modular reduction
- Left shift multiplies by $x$
- Left shift multiplies by $x$
- If the original $x^7$ bit was set, then we must `xor` with `0x1B`
- If the original $x^7$ bit was set, then we must `xor` with `0x1B`
- ```java
// xtime
if ((a & 0x80) > 0) {
a = (a << 1) ^ 0x1b;
} else {
a <<= 1;
}
```
- Example:
4. Multiply by `03` ($x+1$) is simply `xtime(a) ^ a`
```java
// xtime
if ((a & 0x80) > 0) {
a = (a << 1) ^ 0x1b;
} else {
a <<= 1;
}
```
- Inverse multiplications are by `09`, `11`, `13`, `14`. these require either a more general function or lookup tables
4. Multiplying by `03` ($x+1$) is simply `xtime(a) ^ a`
- Inverse multiplications are by `09`, `11`, `13`, `14`. These require either a more general function or lookup tables
- Consider the sum:
- $$
a = x^6 + x^4 + x^2 + 1 \\
b = x^7 + x^4 + x^2 + x \\
\therefore a\cdot b = a\cdot x^7 + a\cdot x^4 + a\cdot x^2 + a\cdot x
$$
- Product:
- $$
a\curvearrowright a\cdot x \curvearrowright a\cdot x^2 \curvearrowright a\cdot x^3 \curvearrowright a\cdot x^4 \curvearrowright a\cdot x^5
$$
$$
a = x^6 + x^4 + x^2 + 1 \\
b = x^7 + x^4 + x^2 + x \\
\therefore a\cdot b = a\cdot x^7 + a\cdot x^4 + a\cdot x^2 + a\cdot x
$$
- Here in $a\cdot b$, $a$ is just being multiplied by various powers of $x$. This can be easily calculated by repeated multiplying $a$ by $x$.
- Repeated multiplication:
$$
a\curvearrowright a\cdot x \curvearrowright a\cdot x^2 \curvearrowright a\cdot x^3 \curvearrowright a\cdot x^4 \curvearrowright a\cdot x^5
$$
- Here in $a\cdot b$, $a$ is just being multiplied by various powers of $x$. This can be easily calculated by repeatedly multiplying $a$ by $x$.
- AES is very **fast in software** and pretty **fast in hardware**
@@ -135,11 +141,11 @@ When multiplying by $x$, there’s a shortcut we can implement. We can set the e
- Much of the algorithm can be converted into a series of lookup tables
- **Trade off** between **speed** and **space**
- **Trade-off** between **speed** and **space**
- There are numerous cache-timing and other attacks possible
- Implementation must be constant time
- CPU instructions help mitigate this
- Implementation must be constant time
- CPU instructions help mitigate this
- In general AES is much harder to implement safely than `ChaCha20`
@@ -5,23 +5,25 @@
- Most messages don’t come in convenient 128-bit block lengths
- We’ll need to run a block cipher repeatedly on consecutive blocks
- Why not use stream ciphers?
- Historically stream ciphgers have proven harder to implement
- Historically, stream ciphers have proven harder to implement
##### Padding
- ECB and some other modes require message length to be a multiple of the block size
- Public Key Cryptography Standards `PKCS7` is a common padding scheme:
1. Padding bytes are always added to the plaintext **before it is encrypted**
2. Each padding byte has a *value equal to the total number of padding bytes* that are added
3. The total number of padding bytes is **atleast one**
1. Padding bytes are always added to the plaintext **before it is encrypted**
2. Each padding byte has a *value equal to the total number of padding bytes* that are added
3. The total number of padding bytes is **at least one**
- ![1646749511.png](img/1646749511.png)
- Note in this example there are 7 `7`s and 16 `16`s
- Note the bottom left example there is 1 `1`. This could be interpreted as 1 bytes of padding or some plaintext. This is why every block must contain at least one padding byte
- Note that in the bottom-left example there is 1 `1`. This could be interpreted as 1 byte of padding or some plaintext. This is why every block must contain at least one padding byte
### Electronic Code Book Mode (ECB)
- Just encrypt each block one after another
- This is quick as can be easily parallelised
- This is quick as it can be easily parallelised
![1646749909.png](img/1646749909.png)
@@ -44,7 +46,7 @@
### Deterministic vs Probabilistic Encryption
- An encryption scheme is **deterministic** if some plaintext is mapped to a fixed ciphertext if the key is unchanged
- ECB is deterministic, but most modern modes of operation of **probabilistic**
- ECB is deterministic, but most modern modes of operation are **probabilistic**
- Probabilistic encryption schemes add randomness to the encryption process to achieve a non-deterministic generation of the ciphertext
![1646750428.png](img/1646750428.png)
@@ -55,9 +57,9 @@
- `XOR` the output of each cipher block with the next input
- $IV$ - **Initialisation Vector**
- The initial random seed that randomises the whole stream
- If you encrypted the same plaintext later it will be different
- An attacker will be unable to tell if $y_1$ and $y_2$ are the same message but with different $IV$ or different messages with different $IV$
- The initial random seed that randomises the whole stream
- If you encrypted the same plaintext later it will be different
- An attacker will be unable to tell if $y_1$ and $y_2$ are the same message but with different $IV$ or different messages with different $IV$
![1646750496.png](img/1646750496.png)
@@ -79,29 +81,31 @@ x_i = d_k(y_i) \oplus y_{i-1}
$$
- If we lost $y_1$ we would be unable to decrypt $y_2$
- We would be able to decrypt $y_3$ though
- We would be able to decrypt $y_3$ though
##### Weaknesses
- CBC was the primary method of encryption for many years
- Now it is less common
- CBC was the primary method of encryption for many years
- Now it is less common
- ![1646750960.png](img/1646750960.png)
- If you flip the first bit in $y_2$, the same bit is flipped for $x_3$
- Changing $y_2$ means $x_2$ no longer decrypts properly
- Changing $y_2$ means $x_2$ no longer decrypts properly
### Padding Oracles
- Here, an **oracle** is a system we can query and it will tell us if, once decrypt, some text has **valid padding**
- Here, an **oracle** is a system we can query and it will tell us if, once decrypted, some text has **valid padding**
- A system is unlikely to tell you directly, but it might give away some clue
- Image an example `api` that receives a CBC encrypted authorisation token
- Imagine an example `api` that receives a CBC-encrypted authorisation token
![1646751224.png](img/1646751224.png)
#### Padding Oracle Attacks
- Lets look at a single decryption block in CBC
- Let's look at a single decryption block in CBC
- The attack is essentially the same for multiple blocks, just one at a time
- You attack the last block, which contains the padding
- You attack the last block, which contains the padding
> The general strategy is to manipulate bits in the IV to find valid padding and recover $z_i$
@@ -116,22 +120,22 @@ $$
### Counter Mode (CTR)
- Encrypt a nonce + counter and use this to mask the plaintext with `XOR`
- This is very easily parallelised
- Each block is encrypted differently, avoiding the issues with ECB mode
- This is very easily parallelised
- Each block is encrypted differently, avoiding the issues with ECB mode
![1646751954.png](img/1646751954.png)
- We are now using our block cipher as a stream cipher
- The keystream generation (AES) is run through blocks
- The keystream generation (AES) is run through blocks
- Decrypting is super easy, just the reverse
### Galois Counter Mode
- Extends counter mode to add authenticity
- The sender definitely sent that message and it hasn’t been modified
- Very similar to ocunter mode, but **adds authentication tag**
- Uses multiplication in a Galois Finite field $GF(2^{128})$ modulo $x^{128} + x^7 + x^2 + x + 1$
- Extremely parallelsiable
- The sender definitely sent that message and it hasn’t been modified
- Very similar to counter mode, but **adds an authentication tag**
- Uses multiplication in a Galois Finite field $GF(2^{128})$ modulo $x^{128} + x^7 + x^2 + x + 1$
- Extremely parallelisable
- Robust to message modification
- Is now standard in `TLS1.3`
@@ -11,15 +11,15 @@ $$
#### Euclidean Algorithm
- The euclidean algorithm calculates the greatest common divisor of two numbers $gcd(r_0, r_1)$
- This is the largest number that divides both $r_0$ and $r_1$
- The Euclidean algorithm calculates the greatest common divisor of two numbers $gcd(r_0, r_1)$
- This is the largest number that divides both $r_0$ and $r_1$
- If $gcd(x,y)=1$ then $x$ and $y$ are **coprime** (sometimes called relatively prime)
- The Euclidean algorithm is based around the fact:
- $gcd(r_0, r_1) = gcd(r_1, r_0 - r_1)$
- $gcd(r_0, r_1) = gcd(r_1, r_0 - r_1)$
![1646755531.png](img/1646755531.png)
- Computing $(x-y)\cdot gcd(r_0, r_1)$ is easier as its a smaller number
- Computing $(x-y)\cdot gcd(r_0, r_1)$ is easier as it's a smaller number
- Doing this repeatedly is slow, we can use $gcd(r_0,r_1) = gcd(r_1, r_0\space mod \space r_1)$
![1646755650.png](img/1646755650.png)
@@ -37,16 +37,16 @@ $r_0=q\cdot r_1 + r_2 \\57=4\cdot 12 + 9\\ r_1=q\cdot r_2 + r_3 \\ 12=1\cdot 9 +
![1646756075.png](img/1646756075.png)
#### Bezout’s Identity
#### Bézout’s Identity
- Bezout’s identity tells us that the greatest common divisor of two numbers can be expressed as the sum of multiples of these numbers
- Bézout’s identity tells us that the greatest common divisor of two numbers can be expressed as the sum of multiples of these numbers
- $gcd(r_0,r_1) = s\cdot r_0 + t\cdot r_1$
- e.g. $gcd(99,20)=-1\cdot 99+5\cdot 20=1$
- $gcd(141,50)=11\cdot 141+-31\cdot 50=1$
- e.g. $gcd(99,20)=-1\cdot 99+5\cdot 20=1$
- $gcd(141,50)=11\cdot 141+-31\cdot 50=1$
##### Extended Euclidean Algorithm
- The extended euclidean algorithm calculates the $gcd(r_0,r_1)$ as normal, and in addition calculates $s$ and $t$.
- The extended Euclidean algorithm calculates the $gcd(r_0,r_1)$ as normal, and in addition calculates $s$ and $t$.
| Euclidean Algorithm | Extended Euclidean Algorithm |
| ---------------------------------- | ------------------------------------------------------------ |
@@ -81,4 +81,3 @@ $$
$$
Where $t$ is our multiplicative inverse
+36 -39
View File
@@ -21,19 +21,17 @@
### Euler Totient Function
- Integers $a$ and $m$ are *relatively prime* if they do not share a divisor (except 1)
- $gcd(a,m) = 1$
- $gcd(a,m) = 1$
- The **Euler totient** $\Phi$ is the number of integers in $\mathbb{Z}_m = \{0,1,...m-1\}$ for which $gcd(a,m)=1$
- For example $\Phi(9)=6$ as:
- $gcd(1,9)=1$ :white_check_mark:
- $gcd(2,9)=1$ :white_check_mark:
- $gcd(3,9)=3$ ❌
- $gcd(4,9)=1$ :white_check_mark:
- $gcd(5,9)=1$ :white_check_mark:
- $gcd(6,9)=3$ ❌
- $gcd(7,9)=1$ :white_check_mark:
- $gcd(8,9)=1$ :white_check_mark:
###
- For example $\Phi(9)=6$ as:
- $gcd(1,9)=1$ :white_check_mark:
- $gcd(2,9)=1$ :white_check_mark:
- $gcd(3,9)=3$ ❌
- $gcd(4,9)=1$ :white_check_mark:
- $gcd(5,9)=1$ :white_check_mark:
- $gcd(6,9)=3$ ❌
- $gcd(7,9)=1$ :white_check_mark:
- $gcd(8,9)=1$ :white_check_mark:
#### Integer Factorisation
@@ -64,19 +62,19 @@ $$
#### Fermat’s Little Theorem
- Fermat’s little theorem states that for some prime $p$, and any integer $a$:
- $a^{p-1} \equiv 1 \space (mod \space p)$
- Also note that $a^{p-1} = a\cdot a^{p-2} \equiv 1 \space (mod \space p)$
- Therefore $a^{p-2}$ is actually the inverse of $a\space (mod \space p)$
- It follows that $a^p \equiv p \space (mod \space p)$
- $a^{p-1} \equiv 1 \space (mod \space p)$
- Also note that $a^{p-1} = a\cdot a^{p-2} \equiv 1 \space (mod \space p)$
- Therefore $a^{p-2}$ is actually the inverse of $a\space (mod \space p)$
- It follows that $a^p \equiv p \space (mod \space p)$
#### Euler’s Theorem
- Generalisation of Fermat’s little theorem, not exclusive to primes
- $a^{\Phi(m)} \equiv 1 \space (mod \space m)$
- If $gcd(a,m)=1$
- $a^{\Phi(m)} \equiv 1 \space (mod \space m)$
- If $gcd(a,m)=1$
- This works for any integer ring $\mathbb{Z}_m$
- We can see that FLT is a special case of this
- $\Phi(p) = (p-1) \therefore a^{\Phi(p)} = a^{p-1} \equiv 1 \space (mod \space p)$
- We can see that FLT is a special case of this
- $\Phi(p) = (p-1) \therefore a^{\Phi(p)} = a^{p-1} \equiv 1 \space (mod \space p)$
## RSA Key Generation
@@ -86,7 +84,7 @@ $$
4. Choose a value $e\in \{2, ..., \Phi(n) -1\}$ where $gcd(\Phi(n),e)=1$
5. Compute $d$ where $d\cdot e \equiv 1 \space (mod \space \Phi(n))$
![1647285406.png](img/1647285406.png)
![1647285406.png](img/1647285406.png)
$d$ is very easy to calculate if you know $p$ and $q$
@@ -97,29 +95,29 @@ $d$ is very easy to calculate if you know $p$ and $q$
##### Encryption
- Now we have a public key $(3, 187)$ and private key $107$
- Encryption and decryption is performed by:
- $x^e \equiv y \space (mod \space n)$
- $y^d \equiv x \space (mod \space n)$
- Encryption and decryption are performed by:
- $x^e \equiv y \space (mod \space n)$
- $y^d \equiv x \space (mod \space n)$
![1647285650.png](img/1647285650.png)
#### Proof
- We want to show that $(x^e)^d = x^{ed} \equiv x \space (mod \space n)$
- Let’s assume $gcd(x,n)=1$ So Euler’s theorem applies
- $e\cdot d=1\space (mod \space \Phi(n))$
- $\therefore e\cdot d = 1 + k\cdot \Phi(n)$
- $x^{e\cdot d} = x^{1+k\cdot \Phi(n)} = x\cdot x^{k+\Phi(n)}$
- $x\cdot (x^{\Phi(n)})^k=x\cdot(1)^k=x$
- Let’s assume $gcd(x,n)=1$, so Euler’s theorem applies
- $e\cdot d=1\space (mod \space \Phi(n))$
- $\therefore e\cdot d = 1 + k\cdot \Phi(n)$
- $x^{e\cdot d} = x^{1+k\cdot \Phi(n)} = x\cdot x^{k+\Phi(n)}$
- $x\cdot (x^{\Phi(n)})^k=x\cdot(1)^k=x$
### Why is RSA Secure
- We’d like the message $x$ based on some ciphertext $y$, given the public key $e$:
- $y \equiv ?^d \space (mod \space n)$
- $x \equiv y^? \space (mod \space n)$
- $y \equiv ?^d \space (mod \space n)$
- $x \equiv y^? \space (mod \space n)$
- It can be fairly easy to calculate $d$:
- $e\cdot d \equiv q \space (mod \space \Phi(n))$
- $\Phi(n) = (p-1)(q-1)$
- $e\cdot d \equiv q \space (mod \space \Phi(n))$
- $\Phi(n) = (p-1)(q-1)$
- As an attacker we only have access to $e$ and $d$
### Exponentiation
@@ -129,7 +127,7 @@ x^4 = x^2 \cdot x^2 \\
x^8 = x^4 \cdot x^4
$$
When calculating a exponent raised to a power of two, we can use previously calculated values.
When calculating an exponent raised to a power of two, we can use previously calculated values.
##### Binary Exponentiation
@@ -158,8 +156,7 @@ $$
##### Computational Complexity
- What is the computational complexity of exponentiation?
- For a 2048 key:
- $X^{2^{2048}}$ - A ridiculously big number
- Where as using square and multiply
- $2048=T$ we need $\frac{3T}{2}$ calculations
- For a 2048 key:
- $X^{2^{2048}}$ - A ridiculously big number
- Whereas using square and multiply
- $2048=T$ we need $\frac{3T}{2}$ calculations
+24 -24
View File
@@ -2,7 +2,7 @@
- Two parties can jointly agree a *shared secret* over an *insecure channel*
- Mathematically, what we are doing is both calculating the same value, mod a prime $p$
- Remember $p$ is $\times 10^{600}$
- Remember $p$ is $\times 10^{600}$
- The parties separately compute the same key, rather than share it
### $\mathbb{Z}_n^*$
@@ -12,7 +12,7 @@
> This set forms an *abelian* group under multiplication modulo $n$. The identity element is 1
- In the majority of cases, we use a prime number as the modulus:
- $\mathbb{Z}_p^* = \{1,2,...,p-1\}$
- $\mathbb{Z}_p^* = \{1,2,...,p-1\}$
**Group Cardinality** - The number of elements in that group
@@ -21,11 +21,11 @@ $$
|\mathbb{Z}_m^*| = \Phi(n) \\
$$
- The security of ciphers often depend on the cardinality of the group
- The security of ciphers often depends on the cardinality of the group
#### Cyclic Groups
- Lets consider group $\mathbb{Z}_{11}^*$
- Let's consider group $\mathbb{Z}_{11}^*$
- Consider calculating powers of 3 in this group
$$
@@ -71,28 +71,30 @@ $$
- A group that contains an element $g$ of maximum order is called a cyclic group
- Any element of maximum order is called a primitive root, or a generator
- $2$ is a generator of $\mathbb{Z}_{11}^* \quad ord(2)=10$
- 3 is not a generator $\mathbb{Z}_{11}^* \quad ord(3)=5$
- $2$ is a generator of $\mathbb{Z}_{11}^* \quad ord(2)=10$
- 3 is not a generator $\mathbb{Z}_{11}^* \quad ord(3)=5$
##### Cyclic Subgroups
- For all primes, $(\mathbb{Z}_{11}^*, \cdot)$ is an *abelian finite cyclic group*
- Let $g \in G$ where $G$ is a cyclic group:
1. $g^{|G|}=1$
2. $ord(g)$ divides $|G|$
- These are called **cyclic subgroups**
- Let $g \in G$ where $G$ is a cyclic group:
1. $g^{|G|}=1$
2. $ord(g)$ divides $|G|$
- These are called **cyclic subgroups**
- Orders of $\mathbb{Z}_{11}^*$
- ![1647359471.png](img/1647359471.png)
- Note the neutral element generates an order of $1$
- ![1647359471.png](img/1647359471.png)
- Note the neutral element generates an order of $1$
## Diffie-Hellman
1. Alice and Bob agree on a large prime $p$, and a generator $g$ that is a primitive root of $p$
2. Alice and Bob choose private numbers $a$ and $b$ at random in $\mathbb{Z}_p^*$
- Where $a\in \{1,2,...,p-1\}$
- and $b\in \{1,2,...,p-1\}$
- Where $a\in \{1,2,...,p-1\}$
- and $b\in \{1,2,...,p-1\}$
3. Alice calculates $A=g^a\space mod \space p$ and sends $A$ publicly to Bob
4. Bob calculates $B=g^b\space mod \space p$ and sends $B$ pubicly to Alice
4. Bob calculates $B=g^b\space mod \space p$ and sends $B$ publicly to Alice
5. Alice computes $k_{ab}=B^a\space mod \space p$
6. Bob computes $k_{ab}=A^b\space mod \space p$
@@ -105,13 +107,13 @@ $$
- Why is Diffie-Hellman so hard to break
- Consider $\mathbb{Z}^*_{10000079},\space g=3$
- Alice calculates $A=3^a\space mod \space 10000079 = 4675535$
- What is $a$?
- Alice calculates $A=3^a\space mod \space 10000079 = 4675535$
- What is $a$?
- This is the discrete logarithm problem
**Brute Force** requires $O(|G|)$
**Shank’s Baby-Step Giant-Step** requires $O(\sqrt{|G|})$ and $\sim \sqrt{|G|}$ space
**Shanks’ Baby-Step Giant-Step** requires $O(\sqrt{|G|})$ and $\sim \sqrt{|G|}$ space
- Using 128 bits, this is $2^{64}$, which would need a cluster
@@ -121,15 +123,13 @@ $$
- The discrete log problem is solved mod each prime factor and the results combined using the Chinese remainder theorem
**Index calculus** directly attacks $\mathbb{Z}_p^*$ and is the reason Elliptic Curves is so much more efficient
**Index calculus** directly attacks $\mathbb{Z}_p^*$ and is the reason elliptic curves are so much more efficient
##### Choosing Primes
- To avoid any unexpected small subgroup attacks, commonly used DH primes are **safe primes**
- A safe prime is a prime $p$ where $\frac{(p-1)}{2}$ is also a prime
- Consider the order of $\mathbb{Z}_p^*$ for a safe prime
- This will have two subgroups of order $p-1$ and $2$
- By choosing a generator of the **subgroup of large prime order**, we avoid attacks on small factors of the group order
- Basically this ensures the prime factorisation has one massive prime in it
- This will have two subgroups of order $p-1$ and $2$
- By choosing a generator of the **subgroup of large prime order**, we avoid attacks on small factors of the group order
- Basically this ensures the prime factorisation has one massive prime in it
@@ -6,15 +6,15 @@ $$
ax^2+by^2=r^2
$$
- There are an infinite amount of solutions to this equation
- However if we restrict to only integers ($\mathbb{Z}$) and use mod, we have a finite set
- There are an infinite number of solutions to this equation
- However if we restrict to only integers ($\mathbb{Z}$) and use mod, we have a finite set
- We define an elliptic curve over points in $\mathbb{Z}_p, \space p>3$
- Set of all pairs where:
- $y^2 \equiv x^3 + ax + b \space (mod \space p)$
- $y^2 \equiv x^3 + ax + b \space (mod \space p)$
- The neutral element is 0
- One requirement is:
- $4a^3 + 27b^2 \neq 0 \space (mod \space p)$
- $4a^3 + 27b^2 \neq 0 \space (mod \space p)$
This is $y^2 \equiv x^3 -3x +3$ over $\mathbb{R}$
@@ -23,8 +23,8 @@ This is $y^2 \equiv x^3 -3x +3$ over $\mathbb{R}$
Notice the symmetry about the x axis, this is because we have a $y^2$ term meaning we have two solutions
- For a DLP problem, we need a cyclic group
- Elements within the group
- A group operation
- Elements within the group
- A group operation
- For ECs the elements are points on the curve
- The operation is point addition
@@ -47,23 +47,23 @@ In elliptic curves, to get $4P$, we can either do $P+3P$ or $2P+2P$
##### Group Properties
- Closed
- Any closed addition operation will end up somewhere on the curve
- Any closed addition operation will end up somewhere on the curve
- Associative
- The order of calculations doesn’t matter
- The order of calculations doesn’t matter
##### Point Addition Equations
- We can derive equations for this based on the equation for a line that intersects the curve in three places
- Given $y^3=x^3+ax+b$ and points:
- $P=(x_1,y_1)$
- $Q=(x_2, y_2)$
- line $y=s\cdot x + m$
- Given $y^3=x^3+ax+b$ and points:
- $P=(x_1,y_1)$
- $Q=(x_2, y_2)$
- line $y=s\cdot x + m$
- $(sx+m)^2 = x^3 + ax + b$
- $s^2x^2 + 2sxm + m^2 = x^3+ax+b$
- Plugging in $x_1, y_1, x_2, y_2$
- $P+Q=(x_3, y_3)$
- $x_3 = s^2 - x_1 - x_2$
- $y_3 = s(x_1 - x_3) - y_1$
- $P+Q=(x_3, y_3)$
- $x_3 = s^2 - x_1 - x_2$
- $y_3 = s(x_1 - x_3) - y_1$
$$
s = \cases{\frac{y_2-y_1}{x_2-x_1} \quad (mod\space p); P\neq Q\\{\frac{3x_1^2+a}{2y_1}}\quad (mod\space p); P=Q}
@@ -107,20 +107,20 @@ These are a pain as they don’t intersect the curve, we say they cross the curv
#### The Point $\mathcal O$ at Infinity
- The point at infinity is the neutral element on a elliptic curve
- $P+(-P)=\mathcal O$
- $P+\mathcal O=P$
- The point at infinity is the neutral element on an elliptic curve
- $P+(-P)=\mathcal O$
- $P+\mathcal O=P$
- In practice the point doesn’t have coordinates, and can’t be used within the normal formula
- $P=(x,y)$
- $-P=(x,-y)$
- $P=(x,y)$
- $-P=(x,-y)$
- When implementing, you have to detect when the x values are equal and y values are inverses $\mod p$
- e.g. $(7,6)+(7,11)$
- $\frac{y_2-y_1}{x_2-x_1}=\frac{-5}{0} = \mathcal O$
- e.g. $(7,6)+(7,11)$
- $\frac{y_2-y_1}{x_2-x_1}=\frac{-5}{0} = \mathcal O$
### Cyclic Groups
- The points on an elliptic curve including the neutral element $\mathcal O$ form a cyclic subgroup
- Under certain conditions all points for a cyclic group
- Under certain conditions all points form a cyclic group
![1647962887.png](img/1647962887.png)
@@ -136,48 +136,50 @@ $$
This is the graph modulus $p$
- Given a generator point, points on elliptic curves generate cyclic groups
- $y^2 \equiv x^3+2x+2 \mod 17$
- ![1648484059.png](img/1648484059.png)
- Here the next two points is the point at infinity ($\mathcal O$) and then it loops back round to $(5,1)$
- $y^2 \equiv x^3+2x+2 \mod 17$
- ![1648484059.png](img/1648484059.png)
- Here the next two points are the point at infinity ($\mathcal O$) and then it loops back round to $(5,1)$
- Each cyclic group includes the point at infinity
## Elliptic Curve Discrete Logarithm
- We can construct a DLP in a very similar way to the modular exponentiation equivalent
- $aP = \underbrace{P+P+...+P}_{a \space\textrm{ times}} = A$
- $aP = \underbrace{P+P+...+P}_{a \space\textrm{ times}} = A$
- Given points $P$ and $A$, find scalar value $a$
- Its important to remember the distinction between points on the curve, and integer values
- It's important to remember the distinction between points on the curve and integer values
- On elliptic curves, private keys such as $a$ are integers
- Generators and public keys are points
#### Group Cardinality
- The size of cyclic groups is very important to the security
- While easy to calculate for modular arithmetic, the number of points on a give elliptic curve is not so obvious
- While easy to calculate for modular arithmetic, the number of points on a given elliptic curve is not so obvious
- You might imagine that a curve would have $2p+1$ points, in reality it is fewer than this
- This is closer to $p$
- This is closer to $p$
- Hasse’s theorem states that for a curve $E$ over a field $\mathbb{Z}_p$, the number of elements $\#E$ is bounded by:
- $\#E=p+1+\epsilon$
- where $|\epsilon| \leq 2\sqrt{p}$
- $\#E=p+1+\epsilon$
- where $|\epsilon| \leq 2\sqrt{p}$
##### #E
- A large #E is very important to prevent various attacks on ECDLP
- Calculating it exactly is hard, it can be done with Shoof’s algorithm
- Calculating it exactly is hard; it can be done with Schoof’s algorithm
- Various properties of #E enable or restrict certain attacks
##### How Hard is ECDLP
- There are generic algorithms like **Polig-Hellman** that are applicable to any category of DLP
- Polig-Hellman requires $O(\sqrt{\#E})$ steps
- These are generic attacks mean curves and parameters should be chosen with care
- There are generic algorithms like **Pohlig-Hellman** that are applicable to any category of DLP
- Pohlig-Hellman requires $O(\sqrt{\#E})$ steps
- These generic attacks mean curves and parameters should be chosen with care
- The most powerful attack on modular arithmetic based DLP is **index calculus**
- It is this attack that forces modular arithmetic based crypto-systems to use >2000 bit keys
- Index calculus does not work on elliptic curves so they only need to remain secure against generic attacks
- It is this attack that forces modular arithmetic based crypto-systems to use >2000 bit keys
- Index calculus does not work on elliptic curves so they only need to remain secure against generic attacks
#### Efficient Computation
- There is no nautral way of calculating $a\cdot P$
- There is no natural way of calculating $a\cdot P$
- Think back to binary exponentiation, square and multiply `->` double and add
| Decimal | Binary |
@@ -199,13 +201,11 @@ E, \#E, G \\
\mathrm{Bob}: a\in \{1,2,...,\#E-1\} \\
$$
Alice takes point $G$ on the curve and add it to $a$: $A = a\cdot G$
Alice takes point $G$ on the curve and adds it to $a$: $A = a\cdot G$
Bob does the same: $B=b\cdot G$
Alice takes bob’s public key $k_{ab} = a\cdot B$
Alice takes Bob’s public key $k_{ab} = a\cdot B$
Bob does the same: $k_{ab}=b\cdot A$
@@ -227,7 +227,7 @@ Where each layer builds on the one beneath
- Since we know the formula for a given curve, we do not need to transport full $(x,y)$ coordinates
- Each point contains a unique $x$, and one or two $y$ where
- $y=\sqrt{x^3 + 2x + 2}\mod p$
- $y=\sqrt{x^3 + 2x + 2}\mod p$
- Most implementations will use the full $x$ value, and append a single bit representing a positive or negative y value
#### Projective Coordinates
@@ -244,11 +244,11 @@ Where each layer builds on the one beneath
- The choice of curve parameters influences both security and efficiency of crypto-systems based around ECs
- Never use a randomly generated curve!
- The chances are the number of points we generate will have a subgroup susecpible to Polig-Hellmen
- The chances are the number of points we generate will have a subgroup susceptible to Pohlig-Hellman
- Standard curves exist in various forms
- Varied equations
- Different implementation methods
- Different choices of prime
- Varied equations
- Different implementation methods
- Different choices of prime
##### P-256
@@ -259,8 +259,8 @@ Where each layer builds on the one beneath
![1648487070.png](img/1648487070.png)
- $h$ is the cofactor, the size of the subgroup in $G$
- Because its 1 it means all the points are being generated
- If it was 2, only half of the points are being generated
- Because it's 1 it means all the points are being generated
- If it was 2, only half of the points are being generated
##### secp256k1
@@ -289,5 +289,5 @@ Where each layer builds on the one beneath
#### Primary Applications
- Elliptic Curve Diffie Hellman
- DSA Signatures scheme, based on Elgamal signatures
- DSA signature scheme, based on Elgamal signatures
- Similar schemes involving the alternative curves such as `Ed25519` and `Ed448`
+22 -22
View File
@@ -1,8 +1,8 @@
# Elgamal Encryption
#### Extending Diffie-Hellmen to Encryption
#### Extending Diffie-Hellman to Encryption
We could do is multiply the plain text by the key generated
What we could do is multiply the plain text by the key generated
$y\equiv x\cdot k_{ab}\mod p \rightarrow x\equiv y\cdot k_{ab}^{-1}$
@@ -28,35 +28,35 @@ $y\equiv x\cdot k_{ab}\mod p \rightarrow x\equiv y\cdot k_{ab}^{-1}$
1. Choose $a\in \{1,2,...,p-1\}$
2. Compute ephemeral key
- $k_E\equiv g^a\mod p$
- Remember ephemeral means the key is generated every time communication happens
- $k_E\equiv g^a\mod p$
- Remember ephemeral means the key is generated every time communication happens
3. Compute masking key
- $k_M\equiv B^a\mod p$
- $k_M\equiv B^a\mod p$
4. Encrypt message $x\in\mathbb{Z}^*_p$
- $y\equiv x\cdot k_M\mod p$
- $y\equiv x\cdot k_M\mod p$
5. Send $(k_E,y)$
#### Elgamal Decryption
1. Compute masking key
- $k_M\equiv k_E^b\mod p$
- $k_M\equiv k_E^b\mod p$
2. Decrypt message
- $x\equiv y\cdot k_M^{-1}\mod p$
- $x\equiv y\cdot k_M^{-1}\mod p$
### Computational Efficiency
To calculate bobs private key we use one exponentiation
To calculate Bob's private key we use one exponentiation
Alice has to do two binary exponentiation to send a message to bob
Alice has to do two binary exponentiations to send a message to Bob
![1648752755.png](img/1648752755.png)
- Both the exponentiations during encryption can be pre-computed during down time
- Both the exponentiations during encryption can be pre-computed during downtime
- We can also improve on the decryption step using Fermat’s little theorem
- Fermat’s Little Theorem: $a^{p-1}\equiv 1\mod p$
1. Compute $k_M=k_E^b\mod 67$
2. Compute $k_M^{-1}$
3. Decrypt $y=y\cdot k_M^{-1}\mod p$
1. Compute $k_M=k_E^b\mod 67$
2. Compute $k_M^{-1}$
3. Decrypt $y=y\cdot k_M^{-1}\mod p$
#### Practicalities
@@ -119,17 +119,17 @@ Recall: $a^{p-1}\equiv 1\mod p$ for some $m$
- Computed in a subgroup of prime order q, which is usually 160 bits
- This means the signature (r, s) is 320 bits
- Hashing is enforced by the algorithm, and a hash function must match the key size
- e.g. SHA-1 for 160-bit q, SHA-256 for 256 bit q
- e.g. SHA-1 for 160-bit q, SHA-256 for 256 bit q
- Index calculus does not apply to the sub-group, so 160 bit DSA has a security of 80 bits
- In practice larger keys would be required now
- In practice larger keys would be required now
#### ECDSA
- Identical to DSA, ECDSA operates on an elliptic curve over $\mathbb{Z}_p$ with the signature calculated over a subgroup of prime order $\#q$
- More efficient, does not require modulus of thousands of bits
- Identical to DSA, ECDSA operates on an elliptic curve over $\mathbb{Z}_p$ with the signature calculated over a subgroup of prime order $\#q$
- More efficient, does not require modulus of thousands of bits
- Security level is based on generic attacks against EC
- i.e $\sqrt{|\#q|}$
- i.e. $\sqrt{|\#q|}$
- Deterministic generation of $k$ is often used for safety (RFC 6979)
- This is where the ephemeral key isn’t random, it’s based off the hash of the message
- This is because reusing the ephemeral key is bad news
- Other variants like EdDSA using Edwards curves (Ed25519 / Ed448) exist
- This is where the ephemeral key isn’t random, it’s based off the hash of the message
- This is because reusing the ephemeral key is bad news
- Other variants like EdDSA using Edwards curves (Ed25519 / Ed448) exist
@@ -3,7 +3,7 @@
- A signature is proof of authenticity of the sender
- Verification is performed by checking the signature against a known signature
- Mostly works for the real world, not very robust
- This does not scale
- This does not scale
#### Electronic Signature
@@ -33,7 +33,7 @@ $$
>
> This requires using a private key
Symetric Signatures gives us:
Symmetric signatures give us:
**Authenticity**: The sender is confirmed as authentic - only Alice or Bob could have generated the signature
@@ -41,7 +41,7 @@ Symetric Signatures gives us:
**Non-Repudiation**: We don’t have this - the symmetric key means that either Alice or Bob could have sent the message
### Pubic Key Signatures
### Public Key Signatures
- By using asymmetric cryptography we have non-repudiation.
@@ -65,14 +65,14 @@ Verification: $s^e\mod n$
- Signing and verification require one use of the *square and multiply* algorithm
- Efficiency depends on the exponents
- We often keep $e$ small
- $65537=2^{16}+1=10000000000001_2$
- $65537=2^{16}+1=10000000000001_2$
- This prioritises verification speed
##### Signature Forgeries
- A forgery is the ability to create a valid message / signature pair $(m,s)$ where $m$ hasn’t previously been signed by the legitimate signer
- For example replay attack using a previous $(m,s)$ wouldn’t count as a forgery
- As we cannot control the message contents
- For example, a replay attack using a previous $(m,s)$ wouldn’t count as a forgery
- As we cannot control the message contents
- Various severities of attack exist depending on the control over the message $m$
###### Existential Forgeries
@@ -84,49 +84,51 @@ Verification: $s^e\mod n$
An attacker has access to Alice’s public key $(n,e)$
- They can calculate
- $s=\textrm{random}$
- $m' =s^e\mod n$
- It is trival to generate message and signature pairs based on an RSA public key
- Not very useful
- $s=\textrm{random}$
- $m' =s^e\mod n$
- It is trivial to generate message and signature pairs based on an RSA public key
- Not very useful
###### Selective Forgeries
- The attacker is able to create a valid message / signature pair $(m,s)$ where they have selected $m$ in advanced
- $m$ may have some mathematical proprieties, or be all zeros etc
- The attacker is able to create a valid message / signature pair $(m,s)$ where they have selected $m$ in advance
- $m$ may have some mathematical properties, or be all zeros etc.
- It is a requirement that $m$ be fixed prior to the attack
###### Universal Forgeries
- The attacker can create a valid signature from any message $m$
- This is the strongest attack, and implies the previous attacks too
- In RSA, this would imply the attack has access to the private key
- In RSA, this would imply the attacker has access to the private key
### Malleability
- RSA is also malleable: $RSA(m_1\cdot m_2)=RSA(m_1)\cdot RSA(m_2)$
- Given two messages $x_1, x_2$ and corresponding signatures $s_1,s_2$
- $(m_3,s_3)\equiv(m_1\cdot m_2, s_1\cdot s_2)(\mod m)$
- $(m_3,s_3)\equiv(m_1\cdot m_2, s_1\cdot s_2)(\mod m)$
- This is more control for an attacker than we would like to have for a signature scheme
- Malleability is a weakness of encryption with textbook RSA too
### Padding
- If we enforce rules about valid formatting on $m$, random messages produced by attackers are unlikely to pass
- ![1649188921.png](img/1649188921.png)
- ![1649188921.png](img/1649188921.png)
- Likelihood of a successful forgery is $2^{-y}$
- Probability of last bit $2^{-1}$
- Probability of last 2 bits $2^{-2}$
- etc up to $y$
- Probability of last bit $2^{-1}$
- Probability of last 2 bits $2^{-2}$
- etc. up to $y$
#### Hash-then-sign
- It is common to hash the message within any padding scheme
- $sig_{k_{prvA}}(x)\equiv H(x)^d \mod n$
- $sig_{k_{prvA}}(x)\equiv H(x)^d \mod n$
- Verification recomputes the hash
- $ver_{k_{pubA}}(x,s)= s^e \mod n \equiv H(x)'$
- $H(x)\stackrel{?}{=}H(x)'$
- $ver_{k_{pubA}}(x,s)= s^e \mod n \equiv H(x)'$
- $H(x)\stackrel{?}{=}H(x)'$
- Existential forgeries are much harder
- You’d need a random message that’s also a valid hash
- You’d need a random message that’s also a valid hash
- Longer messages can be signed, the hash outputs a smaller message digest
##### PKCS v1.5
@@ -135,7 +137,7 @@ An attacker has access to Alice’s public key $(n,e)$
- Modern padding schemes use hashing and padding for security
- Prevents existential forgeries, and attacks on small messages
- This is deterministic, the same message gives the same signature
- This is deterministic, the same message gives the same signature
![1649192054.png](img/1649192054.png)
@@ -145,8 +147,8 @@ An attacker has access to Alice’s public key $(n,e)$
- “with appendix” refers to any scheme that sends $(m,s)$ separately
- PKCS and similar schemes are deterministic
- The probabilistic signature scheme adds a random salt to the process, meaning repeated singatures on the same document produce different results
- Doesn’t effect security that much, some standards have gone back to a probabilistic approach
- The probabilistic signature scheme adds a random salt to the process, meaning repeated signatures on the same document produce different results
- Doesn’t affect security that much; some standards have gone back to a probabilistic approach
###### PSS Encoding
@@ -157,7 +159,7 @@ An attacker has access to Alice’s public key $(n,e)$
5. Expand $H$ using $MGF$
6. Calculate $DB \oplus MGF(H)$ to create maskedDB
7. Output is maskedDB, $H$ and a constant `0xbc`
- `0xbc` is just a constant, no specific meaning other than formatting
- `0xbc` is just a constant, no specific meaning other than formatting
8. Use RSA to calculate signature and send $(m,s)$ as normal
![1649192548.png](img/1649192548.png)
@@ -180,4 +182,4 @@ An attacker has access to Alice’s public key $(n,e)$
Nothing is faster than RSA verification, signing is slower
Its quick because of how 65537 is structured
It's quick because of how 65537 is structured
@@ -4,7 +4,7 @@
- Could we simply split up a message and sign parts?
![1649192960.png](img/1649192960.png)\
![1649192960.png](img/1649192960.png)
A lot of faff for signing large files
@@ -16,7 +16,7 @@ A lot of faff for signing large files
2. Fixed output length
3. Pre-image resistance (one way)
4. Second pre-image resistance
- If we have a hashed message, we cannot find another message with the same hash
- If we have a hashed message, we cannot find another message with the same hash
5. Collision resistance
#### Pre-image Resistance
@@ -24,7 +24,7 @@ A lot of faff for signing large files
- Hash functions must be one-way
- Given a hash of a message $H(x)$ it must be infeasible to calculate $x$
- Less applicable to digital signatures
- Crucial to password storage and key derivation
- Crucial to password storage and key derivation
#### Second Pre-image Resistance
@@ -37,7 +37,7 @@ A lot of faff for signing large files
![1649193645.png](img/1649193645.png)
Oscar finds a weak message (one of the messages is known ahead of time), he replaces the message $x_1$ with $x_2$. Now Oscar can send a signed message to Alice
Oscar finds a weak message (one of the messages is known ahead of time); he replaces the message $x_1$ with $x_2$. Now Oscar can send a signed message to Alice
#### Collision Resistance
@@ -80,8 +80,8 @@ P(n)&=(1-\frac{1}{365})\cdot (1-\frac{2}{365})\dots (1-\frac{n-1}{365})
$$
- The probability of at least one collision is $1 – P(\textrm{no collision})$.
- The probability of a collision with only 23 people is ~50%!
- For 40 people it’s ~90%
- The probability of a collision with only 23 people is ~50%!
- For 40 people it’s ~90%
- The same principle applies to hash functions, the more hashes computed, the more likely a collision becomes
![1649194470.png](img/1649194470.png)
@@ -93,4 +93,4 @@ $$
- You will find a collision after approx $\sqrt{(2^n)}=2^{\frac n2}$ random attempts
- This means that your bit length needs to be double the size of your desired security margin
- `SHA-256` therefore offers equivalent security to `AES 128`
- left at `25:55`
- left at `25:55`
@@ -3,8 +3,8 @@
### Message Authentication Codes
- Provide integrity and authenticity - not confidentiality
- Protecting system files
- Ensuring messages haven’t been altered
- Protecting system files
- Ensuring messages haven’t been altered
- Calculate a keyed hash of the message, then append this to the end of the message
![1653664490.png](img/1653664490.png)
@@ -18,7 +18,7 @@
#### Authenticated Encryption (AEAD)
- It’s common to attach MACs to the end of ciphertext, that this is now usually built into ciphers as part of AEAD mode
- It’s common to attach MACs to the end of ciphertext; this is now usually built into ciphers as part of AEAD mode
- You’re often able to authenticate non-encrypted “associated” data too
![1653664720.png](img/1653664720.png)
@@ -30,19 +30,19 @@
- TLS is a protocol that provides *authenticated* and *encrypted* sessions
- Secure Socket Layer (SSL) came first, then after `v3.0` it became TLS
- Transport Layer Security has two layers
1. The record layer
- Using established symmetric keys and other session info, will encrypt application packets, very like IPsec
2. The handshake layer
- Used to establish session keys, as well as authenticate either party - usually the server using a public key certificate
1. The record layer
- Using established symmetric keys and other session info, will encrypt application packets, very like IPsec
2. The handshake layer
- Used to establish session keys, as well as authenticate either party - usually the server using a public key certificate
##### TLS Handshake
- The TLS handshake allows us to
- Establish the master secret
- Resume sessions
- Authenticate the identity of the server or client
- Establish the master secret
- Resume sessions
- Authenticate the identity of the server or client
- This is for TLS 1.2 - ECDHE_RSA
- Elliptic curve with Diffie-Hellman ephemeral with RSA
- Elliptic curve with Diffie-Hellman ephemeral with RSA
![1653665054.png](img/1653665054.png)
@@ -71,6 +71,7 @@ Random Number: 16cf43a...
Suite: TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256
[Session ID]
```
Random nonce used to stop replay attacks
**Certificate**
@@ -97,7 +98,7 @@ Digital Signature calculated over the DH parameters
**[Certificate Request]**
Optional request for a certificate and singature from the client - only used in mutual TLS
Optional request for a certificate and signature from the client - only used in mutual TLS
Imagine two banks communicating where both parties need to prove their identity.
@@ -117,7 +118,7 @@ Optional client certificate, verified by the server using PKI
**[Certificate Verify]**
Digital signature computed over the bytes send in the handshake so far
Digital signature computed over the bytes sent in the handshake so far
**Change Cipher Spec**
@@ -147,7 +148,7 @@ Mitigates man-in-the-middle attacks
## Public Key Infrastructure
#### Why do we need PKI?
#### Why do we need PKI?
![1653666858.png](img/1653666858.png)
@@ -184,7 +185,7 @@ Mitigates man-in-the-middle attacks
##### Who manages the Root Certificates?
- Major OS vendors operate *root certificate programs*
- Apple for iOS and OS X
- Microsoft for Windows
- Mozilla maintains root certificate store
- Used in linux & firefox
- Apple for iOS and OS X
- Microsoft for Windows
- Mozilla maintains a root certificate store
- Used in Linux & Firefox