Tidy up
This commit is contained in:
103 files changed
+3663
-3779
No files matched your search
@@ -10,7 +10,7 @@
|
||||
|
||||
**Asymmetric**
|
||||
|
||||
>“Methods which use separate, but related, private and public keys.”
|
||||
> “Methods which use separate, but related, private and public keys.”
|
||||
|
||||
**Protocols**
|
||||
|
||||
@@ -20,7 +20,7 @@
|
||||
|
||||
> “The science and art of breaking cryptosystems.”
|
||||
|
||||
### Modern Cyptography (1970-)
|
||||
### Modern Cryptography (1970-)
|
||||
|
||||
**Fundamentally different** - a scientific and mathematical discipline
|
||||
|
||||
@@ -46,13 +46,12 @@
|
||||
|
||||
- Modular arithmetic is a system of arithmetic for finite sets of integers
|
||||
- Common sets include
|
||||
- $\mathbb{N} = \{1,2,3,...\}$
|
||||
- $\mathbb{Z} = \{..., -3, -2, -1, 0,1,2,3,...\}$
|
||||
- Also $\mathbb{Q}, \mathbb{R}, \mathbb{C}$
|
||||
- $\mathbb{N} = \{1,2,3,...\}$
|
||||
- $\mathbb{Z} = \{..., -3, -2, -1, 0,1,2,3,...\}$
|
||||
- Also $\mathbb{Q}, \mathbb{R}, \mathbb{C}$
|
||||
- Cryptography is almost always interested in finite sets
|
||||
- This is useful as it avoids overflow errors
|
||||
- When we add or multiply two 1 byte binary digits, the result will always be 1 byte
|
||||
|
||||
- When we add or multiply two 1 byte binary digits, the result will always be 1 byte
|
||||
|
||||
###### Congruence
|
||||
|
||||
@@ -73,7 +72,7 @@ This can be rewritten as: $a = q\cdot m+r$
|
||||
###### Equivalence Classes
|
||||
|
||||
- The sets of all integers **mod 5** form a series of equivalence classes
|
||||
- All these numbers act the same in any modluo sum
|
||||
- All these numbers act the same in any modulo sum
|
||||
|
||||
For example
|
||||
|
||||
@@ -99,25 +98,25 @@ The integer ring $\mathbb{Z}_m$ consists of:
|
||||
|
||||
1. The set $\mathbb{Z}_m = \{0, 1,\ldots m-1\}$
|
||||
2. Two operations $+$ and $\cdot$ for all $a, b \in \mathbb{Z}_m$ such that:
|
||||
1. $a+b \equiv c \space (mod\space m), (c\in \mathbb{Z})$
|
||||
2. $a\cdot b \equiv d \space (mod\space m), (d\in \mathbb{Z})$
|
||||
1. $a+b \equiv c \space (mod\space m), (c\in \mathbb{Z})$
|
||||
2. $a\cdot b \equiv d \space (mod\space m), (d\in \mathbb{Z})$
|
||||
|
||||
Any time you add or multiply any two numbers in the set, the result is always in the set. We use $\equiv$ instead of $=$ as it could be an intermediatary number e.g. 12 instead of 2.
|
||||
Any time you add or multiply any two numbers in the set, the result is always in the set. We use $\equiv$ instead of $=$ as it could be an intermediate number, e.g. 12 instead of 2.
|
||||
|
||||
##### Properties of Rings
|
||||
|
||||
- We can add or multiply any two numbers in the ring, and the result is in the ring
|
||||
- It is closed
|
||||
- It is closed
|
||||
- Addition and multiplication are associative
|
||||
- (a+b)+c = a + (b+c)
|
||||
- (a+b)+c = a + (b+c)
|
||||
- There is a neutral element 0 for addition
|
||||
- $a + 0 \equiv a\space mod \space m$
|
||||
- $a + 0 \equiv a\space mod \space m$
|
||||
- The additive inverse always exists
|
||||
- $a + (-a) = 0\space mod \space m$
|
||||
- $a + (-a) = 0\space mod \space m$
|
||||
- There is a neutral element for multiplication
|
||||
- $a\cdot 1 \equiv a\space mod\space m$
|
||||
- $a\cdot 1 \equiv a\space mod\space m$
|
||||
- The multiplicative inverse exists for some but not all elements
|
||||
- $a\cdot a^{-1} \equiv 1 \space mod \space m$
|
||||
- $a\cdot a^{-1} \equiv 1 \space mod \space m$
|
||||
|
||||
#### Modular Inversion
|
||||
|
||||
@@ -158,7 +157,7 @@ $$
|
||||
|
||||
##### Frequency Analysis
|
||||
|
||||
- The frequency of occurrences of each character are very consistent
|
||||
- The frequency of occurrences of each character is very consistent
|
||||
- The longer a cipher text is, the easier this becomes
|
||||
|
||||
#### Affine Cipher
|
||||
@@ -174,23 +173,23 @@ $$
|
||||
|
||||
where $k=(a,b)$ and $gcd(a,26)=1$
|
||||
|
||||
This is a multiplication and a addition analagous to $y=mx+c$
|
||||
This is a multiplication and an addition analogous to $y=mx+c$
|
||||
|
||||
In a Affine cipher, letters can be themselves
|
||||
In an Affine cipher, letters can be themselves
|
||||
|
||||
- The keyspace of an affine cipher
|
||||
- a can be 0-25
|
||||
- b can be 0-12
|
||||
- 25*12=300
|
||||
- More secure than a caesar cipher
|
||||
- a can be 0-25
|
||||
- b can be 0-12
|
||||
- 25*12=300
|
||||
- More secure than a Caesar cipher
|
||||
|
||||
Frequency analysis can still be used, in this case the columns will not only be shifted, but jumbled aswell.
|
||||
Frequency analysis can still be used; in this case the columns will not only be shifted, but jumbled as well.
|
||||
|
||||
- This is not hard to crack
|
||||
|
||||
#### The Vigenere Cipher
|
||||
|
||||
- An early stream cipher, the Vigenere cipher is a shift cipher with a running key
|
||||
- Unlike caesar cipher, the key is repeated for as long as required.
|
||||
- Unlike the Caesar cipher, the key is repeated for as long as required.
|
||||
- It is the equivalent to multiple interleaved Caesar ciphers
|
||||
- Spreads outs occurrances of characters making frequency analysis hard.
|
||||
- Spreads out occurrences of characters, making frequency analysis hard.
|
||||
@@ -20,9 +20,7 @@ d_{s_i} (y_i) \equiv (x_i + 0\cdot s_i \space (mod\space 2) \\
|
||||
d_{s_i} (y_i) \equiv x_i
|
||||
$$
|
||||
|
||||
Note: 2 % 2 is 0, its like **xor**-ing twice.
|
||||
|
||||
|
||||
Note: 2 % 2 is 0; it's like **xor**-ing twice.
|
||||
|
||||
#### Security of XOR
|
||||
|
||||
@@ -44,12 +42,12 @@ The security of a stream cipher depends entirely on the nature of the key stream
|
||||
##### True Randomness
|
||||
|
||||
- True randomness is impossible to recreate except by chance
|
||||
- coin flips
|
||||
- coin flips
|
||||
- Computer systems often use hardware sources for randomness
|
||||
- Thermal or other noise
|
||||
- Radioactive decay
|
||||
- Clock drift
|
||||
- Random timings of interrupts
|
||||
- Thermal or other noise
|
||||
- Radioactive decay
|
||||
- Clock drift
|
||||
- Random timings of interrupts
|
||||
|
||||
##### Pseudo Randomness
|
||||
|
||||
@@ -58,7 +56,7 @@ The security of a stream cipher depends entirely on the nature of the key stream
|
||||
|
||||
###### Linear Congruential Generator
|
||||
|
||||
Cs `rand()` function, this is a PRNG
|
||||
C's `rand()` function is a PRNG
|
||||
|
||||
$$
|
||||
s_0 = 12345 \\
|
||||
@@ -76,7 +74,7 @@ $$
|
||||
|
||||
#### Unconditional Security
|
||||
|
||||
A crypto-system is **unconditional security** is unconditionally or information-theoretically secure if it cannot be broken, even with infinite computational resources.
|
||||
A cryptosystem has **unconditional security**: it is unconditionally or information-theoretically secure if it cannot be broken, even with infinite computational resources.
|
||||
|
||||
**Perfect Secrecy**: The cipher-text should reveal no information about the plain text
|
||||
|
||||
@@ -84,7 +82,7 @@ $\forall_{m_0, m_1} \in M$ where $|m_0| = |m_1|$ and $\forall_c \in C$
|
||||
|
||||
$Pr[E(k,m_0) = c] = Pr[E(k,m_1) = c]$
|
||||
|
||||
The probability that $m_0$ encrypts to $c$ is the same as the probability of $m_1$ also encrypted to $c$
|
||||
The probability that $m_0$ encrypts to $c$ is the same as the probability of $m_1$ also being encrypted to $c$
|
||||
|
||||
## One Time Pad
|
||||
|
||||
@@ -134,7 +132,7 @@ $$
|
||||
|
||||
#### Crib Dragging
|
||||
|
||||
This involves guessing $M_1$, this can be a common message such as `HTTP` request.
|
||||
This involves guessing $M_1$; this can be a common message such as an `HTTP` request.
|
||||
|
||||
This can be automated by checking $M_1$ over different parts of $M_2$.
|
||||
|
||||
@@ -145,14 +143,14 @@ This can be automated by checking $M_1$ over different parts of $M_2$.
|
||||
|
||||
- Numbers used once or *nonces* are vital for stream cipher security
|
||||
- Instead of always using a unique key, the security requirement is you always use a unique (key + nonce) pair
|
||||
- Nonces are not secret, they are public random seed for a key stream
|
||||
- Nonces are not secret; they are public random seeds for a key stream
|
||||
|
||||
### Could we use a LCG?
|
||||
### Could we use an LCG?
|
||||
|
||||
- LCG - Linear congruential generators
|
||||
- Seed using some key, then
|
||||
- $s_{i+1} \equiv A \cdot s_i + B \space (mod \space 2)$
|
||||
- $s_i, A, B$ are $log_2m$ bits long
|
||||
- $s_{i+1} \equiv A \cdot s_i + B \space (mod \space 2)$
|
||||
- $s_i, A, B$ are $log_2m$ bits long
|
||||
- This is trivial to break
|
||||
- Given known plaintext $x_1, x_2, x_3$
|
||||
- Calculate corresponding key $s_1, s_2, s_3$
|
||||
- Given known plaintext $x_1, x_2, x_3$
|
||||
- Calculate corresponding key $s_1, s_2, s_3$
|
||||
@@ -2,23 +2,23 @@
|
||||
|
||||
### Pseudo-randomness
|
||||
|
||||
- TRNGs - true Random Number Generator
|
||||
- Not feasible at scale
|
||||
- PRNGs - Pseudo Random Number Generator
|
||||
- CSPRNGs - Cryptographically Secure Pseudo Random Number Generator
|
||||
- TRNGs - True Random Number Generators
|
||||
- Not feasible at scale
|
||||
- PRNGs - Pseudo-random Number Generators
|
||||
- CSPRNGs - Cryptographically Secure Pseudo-random Number Generators
|
||||
|
||||
#### LFSRs
|
||||
|
||||
- A Linear-feedback Shift Register us a register if buts whose positions shift to the right
|
||||
- A linear-feedback shift register is a register of bits whose positions shift to the right
|
||||
- Usually comprised of flip-flops, the last bit represents the output
|
||||
|
||||
(Where the squares at the bottom are flip-flops)
|
||||
|
||||
- If initialised to `000`, nothing happens as $0\oplus0 = 0$.
|
||||
- Therefore, we have $2^n-1$ states
|
||||
- Statistical randomness
|
||||
- Therefore, we have $2^n-1$ states
|
||||
- Statistical randomness
|
||||
- To add more randomness to the setup, we can add another (more) `xor` gate
|
||||
- However, we have fewer states
|
||||
- However, we have fewer states
|
||||
|
||||
$$
|
||||
s_m \equiv s_{m-1}p_{m-1} + ... + s_1p_1 + s_0p_0\space (mod \space 2)\\
|
||||
@@ -27,11 +27,11 @@ $$
|
||||
|
||||
- We usually represent m-bit LFSRs using polynomials of degree m.
|
||||
- In general $P(x)=x^m + p_{m-1}x^{m-1} + ... + p_1x + p_0$
|
||||
- LFSRs that have primitive polynoimials produce sequences of maximum length
|
||||
- There are many and are easily computed
|
||||
- $x^5 + x^2 + 1$ has 31 states
|
||||
- $x^{10} + x^3 + 1$ has 1023
|
||||
- $x^{85}+x^8+x^2+x+1$ has $10^{26}$ states
|
||||
- LFSRs that have primitive polynomials produce sequences of maximum length
|
||||
- There are many, and they are easily computed
|
||||
- $x^5 + x^2 + 1$ has 31 states
|
||||
- $x^{10} + x^3 + 1$ has 1023
|
||||
- $x^{85}+x^8+x^2+x+1$ has $10^{26}$ states
|
||||
|
||||
##### Attacking LFSRs
|
||||
|
||||
@@ -55,31 +55,31 @@ $s_{2m+1} \equiv s_{2m-1}p_{m} + ... + s_mp_1 + s_{m-1}p_0$
|
||||
|
||||
- LFSRs are much more cryptographically secure if we combine more than one together in a non-linear way.
|
||||
|
||||
Trivium is 3 LFSR in a row
|
||||
Trivium is 3 LFSRs in a row
|
||||
|
||||
- Feedback between each with non-linear AND gates
|
||||
- Initialises the LFSR with an 80-bit key and 80-bit random value
|
||||
|
||||
### ChaCha20
|
||||
|
||||
- ChaCha is a stream cipher written by Daniel Berstein
|
||||
- ChaCha is a stream cipher written by Daniel Bernstein
|
||||
- A modification of a previous cipher, Salsa
|
||||
- Very lightweight, using only `add`, `xor` and rotate operations
|
||||
- One of two ciphers in `TLS 1.3`
|
||||
- Dashes represent bit length
|
||||
- Constants are not secret
|
||||
- The block number can skip to anywhere
|
||||
- Suppose someone skips ahead on a video stream, the cipher can skip unlike other synchronous stream ciphers
|
||||
- Suppose someone skips ahead on a video stream, the cipher can skip unlike other synchronous stream ciphers
|
||||
- Works well on low power devices, due to simplicity of encryption
|
||||
- Once the input and the mixed words are added together it is hard to know what the starting thing was
|
||||
- e.g. what two numbers have i added to make 100
|
||||
- e.g. what two numbers have I added to make 100
|
||||
|
||||
ChaCha performs **20** rounds
|
||||
|
||||
- Alternates column and diagonal rounds
|
||||
- Each round is 4 quarter rounds
|
||||
- Each round is 4 quarter rounds
|
||||
|
||||
#### Vulnerabilities
|
||||
|
||||
- Stream ciphers like ChaCha give us *confidentiality*, but *not integrity*
|
||||
- Running a stream cipher by itself is not sufficient
|
||||
- Running a stream cipher by itself is not sufficient
|
||||
@@ -4,35 +4,35 @@
|
||||
|
||||
- A pseudorandom permutation is a function that cannot be distinguished from a random permutation
|
||||
- Maps a set of values $\{0,1\}^n \times \{0,1\}^s \rightarrow \{0,1\}^n$ such that:
|
||||
- For any key, the function F is a *bijection* (1:1)
|
||||
- The key just changes the mapping
|
||||
- There is an *efficient algorithm* to calculate $F(x)$ for all keys and all messages
|
||||
- For any key, the function F is a *bijection* (1:1)
|
||||
- The key just changes the mapping
|
||||
- There is an *efficient algorithm* to calculate $F(x)$ for all keys and all messages
|
||||
|
||||

|
||||
|
||||
**Confusion**: Obscure the relationship between plaintext, key and ciphertext
|
||||
|
||||
- Often achieved through substitution operations
|
||||
- Using lookup tables
|
||||
- Using lookup tables
|
||||
|
||||
**Diffusion**: Influence of each plaintext and key bit is distributed throughout the ciphertext
|
||||
|
||||
- Achieved via permutation
|
||||
- Swapping or otherwise mixing bits/bytes
|
||||
- Swapping or otherwise mixing bits/bytes
|
||||
|
||||
Shannon called a cipher like this a **product cipher**
|
||||
|
||||
### Feistal Network
|
||||
### Feistel Network
|
||||
|
||||
- A Feistal Network is one mechanism used to create block ciphers
|
||||
- Developed by Horst Feistal while he worked at IBM
|
||||
- A Feistel network is one mechanism used to create block ciphers
|
||||
- Developed by Horst Feistel while he worked at IBM
|
||||
- Underpins DES, GOST, Blowfish, Twofish and numerous others.
|
||||
|
||||

|
||||
|
||||
- To decrypt, we run the encrypted bits through the network again
|
||||
|
||||
##### A Single Feistal Round
|
||||
##### A Single Feistel Round
|
||||
|
||||
- During each round, only half of the block is encrypted
|
||||
|
||||
@@ -58,17 +58,17 @@ Note - the last round does a final swap so the left and right are in the correct
|
||||
|
||||
Basically the `xor`s cancel themselves out, the most important part is choosing a good function $f$
|
||||
|
||||
#### About Feistal Networks
|
||||
#### About Feistel Networks
|
||||
|
||||
- 1 or 2 rounds is not sufficient
|
||||
- 1 or 2 rounds are not sufficient
|
||||
- Luby and Rackoff show that if $f$ is a cryptographically secure pseudorandom function then:
|
||||
- 3 rounds are sufficient to make a pseudorandom permutation
|
||||
- 4 rounds are sufficient to make a strong pseudorandom permutation
|
||||
- Balanced Feistal networks
|
||||
- L and R are equal sizes
|
||||
- Unbalanced feistal networks
|
||||
- L and R can be different sizes
|
||||
- e.g. `skipjack`, `OAEP`
|
||||
- 3 rounds are sufficient to make a pseudorandom permutation
|
||||
- 4 rounds are sufficient to make a strong pseudorandom permutation
|
||||
- Balanced Feistel networks
|
||||
- L and R are equal sizes
|
||||
- Unbalanced Feistel networks
|
||||
- L and R can be different sizes
|
||||
- e.g. `skipjack`, `OAEP`
|
||||
|
||||
### DES
|
||||
|
||||
@@ -78,10 +78,10 @@ Basically the `xor`s cancel themselves out, the most important part is choosing
|
||||
|
||||
1976: NIST accepts an altered version of DES following consultation with NSA
|
||||
|
||||
- Feistal network with 64-bit block size
|
||||
- Feistel network with 64-bit block size
|
||||
- 56-bit key
|
||||
- The most studied cipher in history
|
||||
- Hasn’t been broken for over 46 years
|
||||
- Hasn’t been broken for over 46 years
|
||||
|
||||

|
||||
|
||||
@@ -93,7 +93,7 @@ This speeds up loading bits into registers
|
||||
|
||||

|
||||
|
||||
$S_1, S_2....$ are called s-boxes. These substitute 6 bits input to 4 bits output based on lookup tables. The lookup tables for each s-box is different.
|
||||
$S_1, S_2....$ are called s-boxes. These substitute 6-bit inputs with 4-bit outputs based on lookup tables. The lookup tables for each s-box are different.
|
||||
|
||||
##### Expansion
|
||||
|
||||
@@ -107,7 +107,7 @@ $S_1, S_2....$ are called s-boxes. These substitute 6 bits input to 4 bits outpu
|
||||
##### Substitution Boxes
|
||||
|
||||
- Add confusion
|
||||
- The s-boxes map 6 bit inputs to 4-bit outputs
|
||||
- The s-boxes map 6-bit inputs to 4-bit outputs
|
||||
- There are 8 s-boxes in total, each is different
|
||||
|
||||

|
||||
@@ -115,19 +115,19 @@ $S_1, S_2....$ are called s-boxes. These substitute 6 bits input to 4 bits outpu
|
||||
- This s-box is not random, very carefully designed
|
||||
- s-boxes need to be highly **non-linear**: $S(a) \oplus S(b) \neq S(a\oplus b)$
|
||||
- This prevents simple systems of linear equations such as we saw in LFSRs.
|
||||
- The formula needed to represent DES is too complicated
|
||||
- The formula needed to represent DES is too complicated
|
||||
- Key design principles
|
||||
1. No output bit should be too close to a linear combination of input bits
|
||||
2. 1-bit change input should lead to at least 2-bits output
|
||||
3. If you only change the 4 middle bits, each output must occur exactly once
|
||||
4. If the first two bits are different but the last two are identical, the output must differ
|
||||
5. For any non-zero difference in input, no more than 8 of the 32 inputs exhibiting this difference should share the same output difference
|
||||
- We want to limit the number of predictable swaps
|
||||
6. A collision (zero difference) is only possible for 3 adjacent s-boxes
|
||||
1. No output bit should be too close to a linear combination of input bits
|
||||
2. 1-bit change input should lead to at least 2-bits output
|
||||
3. If you only change the 4 middle bits, each output must occur exactly once
|
||||
4. If the first two bits are different but the last two are identical, the output must differ
|
||||
5. For any non-zero difference in input, no more than 8 of the 32 inputs exhibiting this difference should share the same output difference
|
||||
- We want to limit the number of predictable swaps
|
||||
6. A collision (zero difference) is only possible for 3 adjacent s-boxes
|
||||
|
||||
##### Permutation
|
||||
|
||||
- At the end of $f()$ is a permuatation
|
||||
- At the end of $f()$ is a permutation
|
||||
- This moves bits between s-boxes on the next round
|
||||
|
||||

|
||||
@@ -138,11 +138,11 @@ $S_1, S_2....$ are called s-boxes. These substitute 6 bits input to 4 bits outpu
|
||||
|
||||
If you input all 0s, we will see a random cipher text
|
||||
|
||||
However if we change one 0 to a 1, how does this effect the result.
|
||||
However, if we change one 0 to a 1, how does this affect the result?
|
||||
|
||||
- On average, if you change one (first) bit in $R$, one bit will change in the expansion
|
||||
- Due to the way the s-boxes are setup, at least 2 of the 4 bits in the output will be different
|
||||
- Due to the way the s-boxes are set up, at least 2 of the 4 bits in the output will be different
|
||||
- Now when the permutation happens, these two changes are spread to other s-boxes
|
||||
- Now next round we’ll get 4 changes, then 8, then 16 …
|
||||
|
||||
For DES the worst case scenario when one bit is changed (with 5 rounds) is there will be an effect on every bit on the output.
|
||||
For DES the worst case scenario when one bit is changed (with 5 rounds) is there will be an effect on every bit on the output.
|
||||
@@ -3,11 +3,11 @@
|
||||
#### Key Schedule
|
||||
|
||||
- The **DES** key schedule simply returns various permutations of $k$ as sub-keys
|
||||
- $k_1, ... k_{16}$
|
||||
- $k_1, ... k_{16}$
|
||||
|
||||
##### PC-1
|
||||
|
||||
- Permutated Choice 1 (PC-1) selects 56 of the 64 bits
|
||||
- Permuted Choice 1 (PC-1) selects 56 of the 64 bits
|
||||
- The other ‘parity’ bits are discarded: DES only uses a 56-bit key
|
||||
- Key bits are spread throughout the initial state of the key schedule
|
||||
- Key bits 8, 16, 24,…64 are not used
|
||||
@@ -16,14 +16,14 @@
|
||||
|
||||
#### Left Rotation
|
||||
|
||||
- Left rotations (often written as `<<<`) represent a lift shift where the left most numbers wrap around to the right hand side
|
||||
- Left rotations (often written as `<<<`) represent a left shift where the leftmost numbers wrap around to the right-hand side
|
||||
- In DES, each 28-bit block is rotated left by `<<<1` for rounds 1,2,9,16 and `<<<2` otherwise
|
||||
- The total rotation is $4\cdot 1 + 12\cdot 2 = 28$ which means $C_0 = C_{16}$ and $D_0 = D_{16}$
|
||||
- NOTE: $C_0$ or $D_0$ is not used
|
||||
- NOTE: $C_0$ or $D_0$ is not used
|
||||
|
||||
##### PC-2
|
||||
|
||||
- Permuted Choice 2 select 48 of the 56 bits to be used as a round key
|
||||
- Permuted Choice 2 selects 48 of the 56 bits to be used as a round key
|
||||
|
||||

|
||||
|
||||
@@ -31,8 +31,8 @@
|
||||
|
||||
- Is entirely permutation based
|
||||
- Doesn’t use `xor`, addition or any other mixing operation
|
||||
- Because $C_0 = C_{16}$ and $D_0 = D_{16}$ we don’t need to write seperate encrpt and decrypt functions
|
||||
- Usful for writing implementations on low memory devices (smart cards)
|
||||
- Because $C_0 = C_{16}$ and $D_0 = D_{16}$ we don’t need to write separate encrypt and decrypt functions
|
||||
- Useful for writing implementations on low-memory devices (smart cards)
|
||||
|
||||
### Breaking DES
|
||||
|
||||
@@ -47,10 +47,10 @@ NOTE: $2^{56}-1$ is a very large number
|
||||
|
||||
#### Key Collisions
|
||||
|
||||
- For a 56-bit key but a 64-bit block is possible (though unlikely) a different key would work
|
||||
- For a 56-bit key but a 64-bit block, it is possible (though unlikely) that a different key would work
|
||||
- How likely is this to happen for a 1 bit key and an $n$ bit block cipher
|
||||
- $\frac{2^l}{2^n}$ where $l$ is the length of the block and $n$ is the key length
|
||||
- $\frac{2^{64}}{2^{56}} = 2^8$
|
||||
- $\frac{2^l}{2^n}$ where $l$ is the length of the block and $n$ is the key length
|
||||
- $\frac{2^{64}}{2^{56}} = 2^8$
|
||||
|
||||

|
||||
|
||||
@@ -64,15 +64,15 @@ NOTE: $2^{56}-1$ is a very large number
|
||||
|
||||

|
||||
|
||||
- Naive brute fource suggests $2^{56}\cdot 2^{56} = 2^{112}$ keyspace
|
||||
- However using a meet-in-the middle attack this becomes trival.
|
||||
- Step 1: Calculate encryptions of $x_1$ for all $k_{1...,i}$ and store intermediate values $Z_{1..,i}$
|
||||
- Step 2: Calculate all decryptions of $y_1$ for all $k_{R, j}$ to find $Z_{R,i}$
|
||||
- Step 3: Find any value of $Z_{R,j}$ matching existing $Z_L,i$
|
||||
- Naive brute force suggests $2^{56}\cdot 2^{56} = 2^{112}$ keyspace
|
||||
- However, using a meet-in-the-middle attack, this becomes trivial.
|
||||
- Step 1: Calculate encryptions of $x_1$ for all $k_{1...,i}$ and store intermediate values $Z_{1..,i}$
|
||||
- Step 2: Calculate all decryptions of $y_1$ for all $k_{R, j}$ to find $Z_{R,i}$
|
||||
- Step 3: Find any value of $Z_{R,j}$ matching existing $Z_L,i$
|
||||
|
||||

|
||||
|
||||
Meet-in-the-middle requires $2^{k+1}$ attemps rather than $2^{k\cdot 2}$
|
||||
Meet-in-the-middle requires $2^{k+1}$ attempts rather than $2^{k\cdot 2}$
|
||||
|
||||
- This is much better than brute force, but doesn’t make it easy
|
||||
- Trades off computation for storage - Petabytes for DES
|
||||
@@ -81,7 +81,7 @@ Meet-in-the-middle requires $2^{k+1}$ attemps rather than $2^{k\cdot 2}$
|
||||
## 3DES
|
||||
|
||||
- Triple DES uses three different keys
|
||||
- Either `enc -> enc -> enc` or `enc -> dec -> enc`
|
||||
- Either `enc -> enc -> enc` or `enc -> dec -> enc`
|
||||
- Often used in banking, smart cards and other payment systems
|
||||
|
||||

|
||||
@@ -100,34 +100,34 @@ This is why banking systems use 3DES as they already have the infrastructure for
|
||||
|
||||

|
||||
|
||||
- Theoretically this provides a seach space of $2^{k+2n}$ but meet-in-the-middle can be used here, as well as other more advanced attacks
|
||||
- In practive securtity is $2^{k+n-m}$ where an attack has $2^m$ known plain texts
|
||||
- Theoretically this provides a search space of $2^{k+2n}$ but meet-in-the-middle can be used here, as well as other more advanced attacks
|
||||
- In practice, security is $2^{k+n-m}$ where an attack has $2^m$ known plain texts
|
||||
|
||||
# Cryptanalysis
|
||||
|
||||
#### What is a break?
|
||||
|
||||
- In modern cryptography, a cipher is declared broken by essentially any attack that is more efficient than brute force
|
||||
- For example, *differential cryptanalysis* requires $2^{47}$ operations on DES rather than $2^{56}$
|
||||
- For example, *differential cryptanalysis* requires $2^{47}$ operations on DES rather than $2^{56}$
|
||||
- These are often academic breaks, rather than a practical security concern
|
||||
- For example there is a *related key* attack on AES of $2^{99.5}$, compared to brute force of $2^{128}$
|
||||
- Remember that a $2^{n-1}$ takes half the time $2^n$ does
|
||||
- For example there is a *related key* attack on AES of $2^{99.5}$, compared to brute force of $2^{128}$
|
||||
- Remember that a $2^{n-1}$ takes half the time $2^n$ does
|
||||
|
||||
##### Analytical Attacks
|
||||
|
||||
- Exploit some underlying structureal or mathematical weakness in a cipher
|
||||
- e.g. meet in the middle attack
|
||||
- Derivation of taps in LFSRs
|
||||
- Exploit some underlying structural or mathematical weakness in a cipher
|
||||
- e.g. meet in the middle attack
|
||||
- Derivation of taps in LFSRs
|
||||
|
||||
##### Statistical Attacks
|
||||
|
||||
- Capture statistical patterns between input and output to recover key bits
|
||||
- Differential cryptanalysis
|
||||
- Linear cryptanalysis
|
||||
- Differential cryptanalysis
|
||||
- Linear cryptanalysis
|
||||
|
||||
###### Differential Cryptanalysis
|
||||
|
||||
- Different cryptanalysis is prehaps now the most important modern method for breaking block ciphers
|
||||
- Differential cryptanalysis is perhaps now the most important modern method for breaking block ciphers
|
||||
- It is a **chosen plaintext** attack
|
||||
- We aim to find predictable changes in output bits caused by known changes in the input bits
|
||||
|
||||
@@ -141,15 +141,15 @@ This is why banking systems use 3DES as they already have the infrastructure for
|
||||

|
||||
|
||||
- Tracing differentials through a cipher provides us with **differential characteristics** e.g.
|
||||
- $(\Delta x, \Delta y) =$ (0x80, 0xA0) where $p \geq 2^{-3} = 1/8$
|
||||
- $(\Delta x, \Delta y) =$ (0x80, 0xA0) where $p \geq 2^{-3} = 1/8$
|
||||
- These can be calculated by hand or using automated tools
|
||||
- The attack then looks for these expected differentials as you manipulate sub-key bits
|
||||
|
||||
###### Resisting differential cryptanalysis
|
||||
|
||||
- S-boxes must be designed such that the probability of any pair $(\Delta x, \Delta y)$ is as low as possible
|
||||
- AES has a maximum likelihood of a differential per s-box of $2^{-6}$
|
||||
- This is because AES has such good diffusion
|
||||
- AES has a maximum likelihood of a differential per s-box of $2^{-6}$
|
||||
- This is because AES has such good diffusion
|
||||
- More rounds make differentials even less likely
|
||||
- Good permuation to involve more s-boxes is vital
|
||||
- DES was specifically designed to resist this kind of attack
|
||||
- Good permutation to involve more s-boxes is vital
|
||||
- DES was specifically designed to resist this kind of attack
|
||||
@@ -1,12 +1,12 @@
|
||||
# Finite Field Arithmetic
|
||||
|
||||
- A **finite field** is a set containing a finite number of elements
|
||||
- This is sometimes called a *Galois Field*
|
||||
- This is sometimes called a *Galois Field*
|
||||
- In a Galois field you can:
|
||||
- Add
|
||||
- Subtract
|
||||
- Multiply
|
||||
- Invert (divide)
|
||||
- Add
|
||||
- Subtract
|
||||
- Multiply
|
||||
- Invert (divide)
|
||||
- Fields are an extension of *groups* and related to *rings*
|
||||
|
||||
### Groups
|
||||
@@ -14,9 +14,9 @@
|
||||
A group is a set of elements $G$ together with an operation $\circ$ that combines two elements of $G$
|
||||
|
||||
> 1. The operation $\circ$ is **closed**
|
||||
> - i.e. for all $a,b \in G$ then $a\circ b=c\in G$
|
||||
> - i.e. for all $a,b \in G$ then $a\circ b=c\in G$
|
||||
> 2. The operation is associative
|
||||
> - i.e. $a\circ(b\circ c) = (a\circ b)\circ c$ for all $a,b,c \in G$
|
||||
> - i.e. $a\circ(b\circ c) = (a\circ b)\circ c$ for all $a,b,c \in G$
|
||||
> 3. There is an element $1\in G$ called a **neutral element** such that $a\circ 1 = 1\circ a = a$ for all $a\in G$
|
||||
> 4. For each $a \in G$ there exists an element $a^{-1}\in G$ called the **inverse** of $a$ such that $a\circ a^{-1} = a^{-1}\circ a = 1$
|
||||
> 5. A group $G$ is **abelian** (commutative) if $a\circ b = b \circ a$ for all $a,b\in G$
|
||||
@@ -26,7 +26,7 @@ A group is a set of elements $G$ together with an operation $\circ$ that combine
|
||||
- The set of integers $\mathbb{Z}_m = \{0,1,...m-1\}$ with the operation addition modulo m form a group with the neutral element 0
|
||||
- Every element would have an inverse where $a + (-a) = 0$ mod m
|
||||
- This group would not form a group with multiplication, as not all elements would have an inverse
|
||||
- We wouldn’t have an inverse, we would need $5\times \frac15=1$ however $\frac15 \notin \mathbb{Z}$
|
||||
- We wouldn’t have an inverse; we would need $5\times \frac15=1$, but $\frac15 \notin \mathbb{Z}$
|
||||
|
||||
### Fields
|
||||
|
||||
@@ -35,12 +35,12 @@ A field $F$ is a set of elements with the following properties
|
||||
> 1. All elements of $F$ form an **additive group** with the group operation $+$ and the neutral element 0
|
||||
> 2. All elements of $F$ except 0 form a multiplicative group with the group operation $\times$ and the neutral element 1
|
||||
> 3. When the two group operations are mixed, the distributivity law holds.
|
||||
> - i.e. for all $a,b,c \in F, a\cdot(b+c) = (a\cdot b) + (a\cdot c)$
|
||||
> - i.e. for all $a,b,c \in F, a\cdot(b+c) = (a\cdot b) + (a\cdot c)$
|
||||
|
||||
##### Example Field
|
||||
|
||||
- The set of real numbers $\mathbb{R}$ is a field with neutral element 0 for addition and 1 for multiplication
|
||||
- Every real number $a$ has a additive inverse $-a$
|
||||
- Every real number $a$ has an additive inverse $-a$
|
||||
- Every non-zero number $a$ has a multiplicative inverse $\frac{1}{a}$
|
||||
|
||||

|
||||
@@ -80,7 +80,7 @@ $a \cdot a^{-1} \equiv 1 \space (mod \space p)$
|
||||
|
||||
- A modular inverse exists when $gcd(a,p) = 1$
|
||||
- Because $p$ is prime, every number has a multiplicative inverse
|
||||
- $gcd(a,p) = 1, \forall a \neq0 \in GF(p)$
|
||||
- $gcd(a,p) = 1, \forall a \neq0 \in GF(p)$
|
||||
- $a^{-1}$ can be calculated using the **extended Euclidean algorithm**
|
||||
|
||||
#### Extension Fields
|
||||
@@ -97,16 +97,16 @@ The coefficients of the polynomial are elements in $GF(2)$ the **sub-field**
|
||||
##### Example $GF(2^3)$
|
||||
|
||||
- The field $GF(2^3)$, sometimes called $GF(8)$ is an extension field containing elements of the form: $A(x) = a_2 x^2 + a_1x^1 + a_0$
|
||||
- Its often easier to simply write the coefficients $(a_2, a_1, a_0)$ e.g. 001 or 101
|
||||
- It's often easier to simply write the coefficients $(a_2, a_1, a_0)$ e.g. 001 or 101
|
||||
- $GF(2^3) = \{0, 1, x, x+1, x^2, x^2+1, x^2 + x, x^2 + x + 1\}$
|
||||
- $|GF(2^3)| = 8$
|
||||
- $|GF(2^3)| = 8$
|
||||
|
||||
#### Arithmetic in $GF(2^3)$
|
||||
|
||||
- Adding or subtracting two polynomials happens as expected, but adding the coefficients
|
||||
- $A(x) = x^2 + x + 1$
|
||||
- $B(x) = x^2 + 1$
|
||||
- $A(x) + B(x) = (1+1)x^2 + (1)x + (1+1) = x$
|
||||
- $A(x) = x^2 + x + 1$
|
||||
- $B(x) = x^2 + 1$
|
||||
- $A(x) + B(x) = (1+1)x^2 + (1)x + (1+1) = x$
|
||||
- mod 2 is simply `xor`
|
||||
- Addition and subtraction are identical
|
||||
|
||||
@@ -130,7 +130,7 @@ $$
|
||||
|
||||
- Inversion is performed in a similar way to prime fields, we find:
|
||||
- $A(x) \cdot A^{-1}(x) \equiv 1 \space (mod \space P(x))$
|
||||
- $A^{-1}(x)$ is calculated using the extended euclidean algorithm
|
||||
- $A^{-1}(x)$ is calculated using the extended Euclidean algorithm
|
||||
|
||||
### AES’ Finite Field
|
||||
|
||||
|
||||
@@ -2,7 +2,7 @@
|
||||
|
||||
- AES superseded DES as a standard in 2002
|
||||
|
||||

|
||||

|
||||
|
||||
- Uses rounds of 4 layers and a final round of 3
|
||||
- Bytes are represented as a 4x4 block called the *state*
|
||||
@@ -19,12 +19,12 @@ First row doesn’t move, second row is shifted to the left by 1, the third row
|
||||
|
||||
Then, when the columns are mixed, this means the overall diffusion is extremely good
|
||||
|
||||
The last round doesn’t have a **mix column** step as its reversible and wouldn’t add additional security.
|
||||
The last round doesn’t have a **mix column** step as it's reversible and wouldn’t add additional security.
|
||||
|
||||
#### S-Box
|
||||
|
||||
- The AES s-box is based around the multiplicative inverse of 8-bit values in $GF(2^8)$
|
||||
- This is strongly *non-linear* mapping
|
||||
- This is a strongly *non-linear* mapping
|
||||
|
||||
$$
|
||||
A_i \cdot A_i^{-1} \equiv 1 \space (mod \space P(x)) \\
|
||||
@@ -37,7 +37,7 @@ $$
|
||||

|
||||
|
||||
- Note: 0 maps to 0
|
||||
- The inverses $B'_i$ then undergo an **affine transformation** to produce the final s-box
|
||||
- The inverses $B'_i$ then undergo an **affine transformation** to produce the final s-box
|
||||
- This destroys any remaining mathematical structure
|
||||
|
||||

|
||||
@@ -46,15 +46,15 @@ Remember an affine transformation is a multiplication and addition by two consta
|
||||
|
||||
##### S-box Properties
|
||||
|
||||
- The s-box simply described, and is bijective, an invertible 1:1 mapping
|
||||
- The s-box is simply described, and is bijective, an invertible 1:1 mapping
|
||||
- It has no fixed points
|
||||
- i.e. no $A_i$ for which $S(A_i) = A_i$
|
||||
- i.e. no $A_i$ for which $S(A_i) = A_i$
|
||||
- No inverse fixed points
|
||||
- i.e. no $A_i$ for which $S(A_i) \oplus A_i = FF$
|
||||
- i.e. no $A_i$ for which $S(A_i) \oplus A_i = FF$
|
||||
- Minimisation of the largest non-trivial correlation between linear combinations of input bits and linear combinations of output bits
|
||||
- 0 is a non-trivial combination
|
||||
- 0 is a non-trivial combination
|
||||
- Minimisation of the largest non-trivial value in the `EXOR` table
|
||||
- This stops differential cryptanalysis
|
||||
- This stops differential cryptanalysis
|
||||
|
||||
#### AES Diffusion
|
||||
|
||||
@@ -86,48 +86,54 @@ When multiplying by $x$, there’s a shortcut we can implement. We can set the e
|
||||
|
||||
- The first round key used is just the key
|
||||
- We then take $W[3]$ and put it through the $g$ function which just permutes it
|
||||
- $g$ takes the word, shifts it one to the right and then passes it through the s-boxes
|
||||
- We then `xor` it with $RC[i]$ which is just a constant value to ensure *something* changes
|
||||
- Like for example if we had a bit stream of all 0s
|
||||
- $g$ takes the word, shifts it one to the right and then passes it through the s-boxes
|
||||
- We then `xor` it with $RC[i]$ which is just a constant value to ensure *something* changes
|
||||
- Like for example if we had a bit stream of all 0s
|
||||
|
||||
### Implementation
|
||||
|
||||
1. All addition and subtractions are `xor`
|
||||
1. All additions and subtractions are `xor`
|
||||
|
||||
2. Multiply by `01` has no effect
|
||||
2. Multiplying by `01` has no effect
|
||||
|
||||
3. Multiplying by `02` (which is $x$) is simply a left shift followed by modular reduction
|
||||
|
||||
- Left shift multiplies by $x$
|
||||
- Left shift multiplies by $x$
|
||||
|
||||
- If the original $x^7$ bit was set, then we must `xor` with `0x1B`
|
||||
- If the original $x^7$ bit was set, then we must `xor` with `0x1B`
|
||||
|
||||
- ```java
|
||||
// xtime
|
||||
if ((a & 0x80) > 0) {
|
||||
a = (a << 1) ^ 0x1b;
|
||||
} else {
|
||||
a <<= 1;
|
||||
}
|
||||
```
|
||||
- Example:
|
||||
|
||||
4. Multiply by `03` ($x+1$) is simply `xtime(a) ^ a`
|
||||
```java
|
||||
// xtime
|
||||
if ((a & 0x80) > 0) {
|
||||
a = (a << 1) ^ 0x1b;
|
||||
} else {
|
||||
a <<= 1;
|
||||
}
|
||||
```
|
||||
|
||||
- Inverse multiplications are by `09`, `11`, `13`, `14`. these require either a more general function or lookup tables
|
||||
4. Multiplying by `03` ($x+1$) is simply `xtime(a) ^ a`
|
||||
|
||||
- Inverse multiplications are by `09`, `11`, `13`, `14`. These require either a more general function or lookup tables
|
||||
|
||||
- Consider the sum:
|
||||
|
||||
- $$
|
||||
a = x^6 + x^4 + x^2 + 1 \\
|
||||
b = x^7 + x^4 + x^2 + x \\
|
||||
\therefore a\cdot b = a\cdot x^7 + a\cdot x^4 + a\cdot x^2 + a\cdot x
|
||||
$$
|
||||
- Product:
|
||||
|
||||
- $$
|
||||
a\curvearrowright a\cdot x \curvearrowright a\cdot x^2 \curvearrowright a\cdot x^3 \curvearrowright a\cdot x^4 \curvearrowright a\cdot x^5
|
||||
$$
|
||||
$$
|
||||
a = x^6 + x^4 + x^2 + 1 \\
|
||||
b = x^7 + x^4 + x^2 + x \\
|
||||
\therefore a\cdot b = a\cdot x^7 + a\cdot x^4 + a\cdot x^2 + a\cdot x
|
||||
$$
|
||||
|
||||
- Here in $a\cdot b$, $a$ is just being multiplied by various powers of $x$. This can be easily calculated by repeated multiplying $a$ by $x$.
|
||||
- Repeated multiplication:
|
||||
|
||||
$$
|
||||
a\curvearrowright a\cdot x \curvearrowright a\cdot x^2 \curvearrowright a\cdot x^3 \curvearrowright a\cdot x^4 \curvearrowright a\cdot x^5
|
||||
$$
|
||||
|
||||
- Here in $a\cdot b$, $a$ is just being multiplied by various powers of $x$. This can be easily calculated by repeatedly multiplying $a$ by $x$.
|
||||
|
||||
- AES is very **fast in software** and pretty **fast in hardware**
|
||||
|
||||
@@ -135,11 +141,11 @@ When multiplying by $x$, there’s a shortcut we can implement. We can set the e
|
||||
|
||||
- Much of the algorithm can be converted into a series of lookup tables
|
||||
|
||||
- **Trade off** between **speed** and **space**
|
||||
- **Trade-off** between **speed** and **space**
|
||||
|
||||
- There are numerous cache-timing and other attacks possible
|
||||
|
||||
- Implementation must be constant time
|
||||
- CPU instructions help mitigate this
|
||||
- Implementation must be constant time
|
||||
- CPU instructions help mitigate this
|
||||
|
||||
- In general AES is much harder to implement safely than `ChaCha20`
|
||||
@@ -5,23 +5,25 @@
|
||||
- Most messages don’t come in convenient 128-bit block lengths
|
||||
- We’ll need to run a block cipher repeatedly on consecutive blocks
|
||||
- Why not use stream ciphers?
|
||||
- Historically stream ciphgers have proven harder to implement
|
||||
- Historically, stream ciphers have proven harder to implement
|
||||
|
||||
##### Padding
|
||||
|
||||
- ECB and some other modes require message length to be a multiple of the block size
|
||||
- Public Key Cryptography Standards `PKCS7` is a common padding scheme:
|
||||
1. Padding bytes are always added to the plaintext **before it is encrypted**
|
||||
2. Each padding byte has a *value equal to the total number of padding bytes* that are added
|
||||
3. The total number of padding bytes is **atleast one**
|
||||
1. Padding bytes are always added to the plaintext **before it is encrypted**
|
||||
2. Each padding byte has a *value equal to the total number of padding bytes* that are added
|
||||
3. The total number of padding bytes is **at least one**
|
||||
|
||||
- 
|
||||
|
||||
- Note in this example there are 7 `7`s and 16 `16`s
|
||||
- Note the bottom left example there is 1 `1`. This could be interpreted as 1 bytes of padding or some plaintext. This is why every block must contain at least one padding byte
|
||||
- Note that in the bottom-left example there is 1 `1`. This could be interpreted as 1 byte of padding or some plaintext. This is why every block must contain at least one padding byte
|
||||
|
||||
### Electronic Code Book Mode (ECB)
|
||||
|
||||
- Just encrypt each block one after another
|
||||
- This is quick as can be easily parallelised
|
||||
- This is quick as it can be easily parallelised
|
||||
|
||||

|
||||
|
||||
@@ -44,7 +46,7 @@
|
||||
### Deterministic vs Probabilistic Encryption
|
||||
|
||||
- An encryption scheme is **deterministic** if some plaintext is mapped to a fixed ciphertext if the key is unchanged
|
||||
- ECB is deterministic, but most modern modes of operation of **probabilistic**
|
||||
- ECB is deterministic, but most modern modes of operation are **probabilistic**
|
||||
- Probabilistic encryption schemes add randomness to the encryption process to achieve a non-deterministic generation of the ciphertext
|
||||
|
||||

|
||||
@@ -55,9 +57,9 @@
|
||||
|
||||
- `XOR` the output of each cipher block with the next input
|
||||
- $IV$ - **Initialisation Vector**
|
||||
- The initial random seed that randomises the whole stream
|
||||
- If you encrypted the same plaintext later it will be different
|
||||
- An attacker will be unable to tell if $y_1$ and $y_2$ are the same message but with different $IV$ or different messages with different $IV$
|
||||
- The initial random seed that randomises the whole stream
|
||||
- If you encrypted the same plaintext later it will be different
|
||||
- An attacker will be unable to tell if $y_1$ and $y_2$ are the same message but with different $IV$ or different messages with different $IV$
|
||||
|
||||

|
||||
|
||||
@@ -79,29 +81,31 @@ x_i = d_k(y_i) \oplus y_{i-1}
|
||||
$$
|
||||
|
||||
- If we lost $y_1$ we would be unable to decrypt $y_2$
|
||||
- We would be able to decrypt $y_3$ though
|
||||
- We would be able to decrypt $y_3$ though
|
||||
|
||||
##### Weaknesses
|
||||
|
||||
- CBC was the primary method of encryption for many years
|
||||
- Now it is less common
|
||||
- CBC was the primary method of encryption for many years
|
||||
- Now it is less common
|
||||
|
||||
- 
|
||||
|
||||
- If you flip the first bit in $y_2$, the same bit is flipped for $x_3$
|
||||
- Changing $y_2$ means $x_2$ no longer decrypts properly
|
||||
- Changing $y_2$ means $x_2$ no longer decrypts properly
|
||||
|
||||
### Padding Oracles
|
||||
|
||||
- Here, an **oracle** is a system we can query and it will tell us if, once decrypt, some text has **valid padding**
|
||||
- Here, an **oracle** is a system we can query and it will tell us if, once decrypted, some text has **valid padding**
|
||||
- A system is unlikely to tell you directly, but it might give away some clue
|
||||
- Image an example `api` that receives a CBC encrypted authorisation token
|
||||
- Imagine an example `api` that receives a CBC-encrypted authorisation token
|
||||
|
||||

|
||||
|
||||
#### Padding Oracle Attacks
|
||||
|
||||
- Lets look at a single decryption block in CBC
|
||||
- Let's look at a single decryption block in CBC
|
||||
- The attack is essentially the same for multiple blocks, just one at a time
|
||||
- You attack the last block, which contains the padding
|
||||
- You attack the last block, which contains the padding
|
||||
|
||||
> The general strategy is to manipulate bits in the IV to find valid padding and recover $z_i$
|
||||
|
||||
@@ -116,22 +120,22 @@ $$
|
||||
### Counter Mode (CTR)
|
||||
|
||||
- Encrypt a nonce + counter and use this to mask the plaintext with `XOR`
|
||||
- This is very easily parallelised
|
||||
- Each block is encrypted differently, avoiding the issues with ECB mode
|
||||
- This is very easily parallelised
|
||||
- Each block is encrypted differently, avoiding the issues with ECB mode
|
||||
|
||||

|
||||
|
||||
- We are now using our block cipher as a stream cipher
|
||||
- The keystream generation (AES) is run through blocks
|
||||
- The keystream generation (AES) is run through blocks
|
||||
- Decrypting is super easy, just the reverse
|
||||
|
||||
### Galois Counter Mode
|
||||
|
||||
- Extends counter mode to add authenticity
|
||||
- The sender definitely sent that message and it hasn’t been modified
|
||||
- Very similar to ocunter mode, but **adds authentication tag**
|
||||
- Uses multiplication in a Galois Finite field $GF(2^{128})$ modulo $x^{128} + x^7 + x^2 + x + 1$
|
||||
- Extremely parallelsiable
|
||||
- The sender definitely sent that message and it hasn’t been modified
|
||||
- Very similar to counter mode, but **adds an authentication tag**
|
||||
- Uses multiplication in a Galois Finite field $GF(2^{128})$ modulo $x^{128} + x^7 + x^2 + x + 1$
|
||||
- Extremely parallelisable
|
||||
- Robust to message modification
|
||||
- Is now standard in `TLS1.3`
|
||||
|
||||
|
||||
@@ -11,15 +11,15 @@ $$
|
||||
|
||||
#### Euclidean Algorithm
|
||||
|
||||
- The euclidean algorithm calculates the greatest common divisor of two numbers $gcd(r_0, r_1)$
|
||||
- This is the largest number that divides both $r_0$ and $r_1$
|
||||
- The Euclidean algorithm calculates the greatest common divisor of two numbers $gcd(r_0, r_1)$
|
||||
- This is the largest number that divides both $r_0$ and $r_1$
|
||||
- If $gcd(x,y)=1$ then $x$ and $y$ are **coprime** (sometimes called relatively prime)
|
||||
- The Euclidean algorithm is based around the fact:
|
||||
- $gcd(r_0, r_1) = gcd(r_1, r_0 - r_1)$
|
||||
- $gcd(r_0, r_1) = gcd(r_1, r_0 - r_1)$
|
||||
|
||||

|
||||
|
||||
- Computing $(x-y)\cdot gcd(r_0, r_1)$ is easier as its a smaller number
|
||||
- Computing $(x-y)\cdot gcd(r_0, r_1)$ is easier as it's a smaller number
|
||||
- Doing this repeatedly is slow, we can use $gcd(r_0,r_1) = gcd(r_1, r_0\space mod \space r_1)$
|
||||
|
||||

|
||||
@@ -37,16 +37,16 @@ $r_0=q\cdot r_1 + r_2 \\57=4\cdot 12 + 9\\ r_1=q\cdot r_2 + r_3 \\ 12=1\cdot 9 +
|
||||
|
||||

|
||||
|
||||
#### Bezout’s Identity
|
||||
#### Bézout’s Identity
|
||||
|
||||
- Bezout’s identity tells us that the greatest common divisor of two numbers can be expressed as the sum of multiples of these numbers
|
||||
- Bézout’s identity tells us that the greatest common divisor of two numbers can be expressed as the sum of multiples of these numbers
|
||||
- $gcd(r_0,r_1) = s\cdot r_0 + t\cdot r_1$
|
||||
- e.g. $gcd(99,20)=-1\cdot 99+5\cdot 20=1$
|
||||
- $gcd(141,50)=11\cdot 141+-31\cdot 50=1$
|
||||
- e.g. $gcd(99,20)=-1\cdot 99+5\cdot 20=1$
|
||||
- $gcd(141,50)=11\cdot 141+-31\cdot 50=1$
|
||||
|
||||
##### Extended Euclidean Algorithm
|
||||
|
||||
- The extended euclidean algorithm calculates the $gcd(r_0,r_1)$ as normal, and in addition calculates $s$ and $t$.
|
||||
- The extended Euclidean algorithm calculates the $gcd(r_0,r_1)$ as normal, and in addition calculates $s$ and $t$.
|
||||
|
||||
| Euclidean Algorithm | Extended Euclidean Algorithm |
|
||||
| ---------------------------------- | ------------------------------------------------------------ |
|
||||
@@ -81,4 +81,3 @@ $$
|
||||
$$
|
||||
|
||||
Where $t$ is our multiplicative inverse
|
||||
|
||||
@@ -21,19 +21,17 @@
|
||||
### Euler Totient Function
|
||||
|
||||
- Integers $a$ and $m$ are *relatively prime* if they do not share a divisor (except 1)
|
||||
- $gcd(a,m) = 1$
|
||||
- $gcd(a,m) = 1$
|
||||
- The **Euler totient** $\Phi$ is the number of integers in $\mathbb{Z}_m = \{0,1,...m-1\}$ for which $gcd(a,m)=1$
|
||||
- For example $\Phi(9)=6$ as:
|
||||
- $gcd(1,9)=1$ :white_check_mark:
|
||||
- $gcd(2,9)=1$ :white_check_mark:
|
||||
- $gcd(3,9)=3$ ❌
|
||||
- $gcd(4,9)=1$ :white_check_mark:
|
||||
- $gcd(5,9)=1$ :white_check_mark:
|
||||
- $gcd(6,9)=3$ ❌
|
||||
- $gcd(7,9)=1$ :white_check_mark:
|
||||
- $gcd(8,9)=1$ :white_check_mark:
|
||||
|
||||
###
|
||||
- For example $\Phi(9)=6$ as:
|
||||
- $gcd(1,9)=1$ :white_check_mark:
|
||||
- $gcd(2,9)=1$ :white_check_mark:
|
||||
- $gcd(3,9)=3$ ❌
|
||||
- $gcd(4,9)=1$ :white_check_mark:
|
||||
- $gcd(5,9)=1$ :white_check_mark:
|
||||
- $gcd(6,9)=3$ ❌
|
||||
- $gcd(7,9)=1$ :white_check_mark:
|
||||
- $gcd(8,9)=1$ :white_check_mark:
|
||||
|
||||
#### Integer Factorisation
|
||||
|
||||
@@ -64,19 +62,19 @@ $$
|
||||
#### Fermat’s Little Theorem
|
||||
|
||||
- Fermat’s little theorem states that for some prime $p$, and any integer $a$:
|
||||
- $a^{p-1} \equiv 1 \space (mod \space p)$
|
||||
- Also note that $a^{p-1} = a\cdot a^{p-2} \equiv 1 \space (mod \space p)$
|
||||
- Therefore $a^{p-2}$ is actually the inverse of $a\space (mod \space p)$
|
||||
- It follows that $a^p \equiv p \space (mod \space p)$
|
||||
- $a^{p-1} \equiv 1 \space (mod \space p)$
|
||||
- Also note that $a^{p-1} = a\cdot a^{p-2} \equiv 1 \space (mod \space p)$
|
||||
- Therefore $a^{p-2}$ is actually the inverse of $a\space (mod \space p)$
|
||||
- It follows that $a^p \equiv p \space (mod \space p)$
|
||||
|
||||
#### Euler’s Theorem
|
||||
|
||||
- Generalisation of Fermat’s little theorem, not exclusive to primes
|
||||
- $a^{\Phi(m)} \equiv 1 \space (mod \space m)$
|
||||
- If $gcd(a,m)=1$
|
||||
- $a^{\Phi(m)} \equiv 1 \space (mod \space m)$
|
||||
- If $gcd(a,m)=1$
|
||||
- This works for any integer ring $\mathbb{Z}_m$
|
||||
- We can see that FLT is a special case of this
|
||||
- $\Phi(p) = (p-1) \therefore a^{\Phi(p)} = a^{p-1} \equiv 1 \space (mod \space p)$
|
||||
- We can see that FLT is a special case of this
|
||||
- $\Phi(p) = (p-1) \therefore a^{\Phi(p)} = a^{p-1} \equiv 1 \space (mod \space p)$
|
||||
|
||||
## RSA Key Generation
|
||||
|
||||
@@ -86,7 +84,7 @@ $$
|
||||
4. Choose a value $e\in \{2, ..., \Phi(n) -1\}$ where $gcd(\Phi(n),e)=1$
|
||||
5. Compute $d$ where $d\cdot e \equiv 1 \space (mod \space \Phi(n))$
|
||||
|
||||

|
||||

|
||||
|
||||
$d$ is very easy to calculate if you know $p$ and $q$
|
||||
|
||||
@@ -97,29 +95,29 @@ $d$ is very easy to calculate if you know $p$ and $q$
|
||||
##### Encryption
|
||||
|
||||
- Now we have a public key $(3, 187)$ and private key $107$
|
||||
- Encryption and decryption is performed by:
|
||||
- $x^e \equiv y \space (mod \space n)$
|
||||
- $y^d \equiv x \space (mod \space n)$
|
||||
- Encryption and decryption are performed by:
|
||||
- $x^e \equiv y \space (mod \space n)$
|
||||
- $y^d \equiv x \space (mod \space n)$
|
||||
|
||||

|
||||
|
||||
#### Proof
|
||||
|
||||
- We want to show that $(x^e)^d = x^{ed} \equiv x \space (mod \space n)$
|
||||
- Let’s assume $gcd(x,n)=1$ So Euler’s theorem applies
|
||||
- $e\cdot d=1\space (mod \space \Phi(n))$
|
||||
- $\therefore e\cdot d = 1 + k\cdot \Phi(n)$
|
||||
- $x^{e\cdot d} = x^{1+k\cdot \Phi(n)} = x\cdot x^{k+\Phi(n)}$
|
||||
- $x\cdot (x^{\Phi(n)})^k=x\cdot(1)^k=x$
|
||||
- Let’s assume $gcd(x,n)=1$, so Euler’s theorem applies
|
||||
- $e\cdot d=1\space (mod \space \Phi(n))$
|
||||
- $\therefore e\cdot d = 1 + k\cdot \Phi(n)$
|
||||
- $x^{e\cdot d} = x^{1+k\cdot \Phi(n)} = x\cdot x^{k+\Phi(n)}$
|
||||
- $x\cdot (x^{\Phi(n)})^k=x\cdot(1)^k=x$
|
||||
|
||||
### Why is RSA Secure
|
||||
|
||||
- We’d like the message $x$ based on some ciphertext $y$, given the public key $e$:
|
||||
- $y \equiv ?^d \space (mod \space n)$
|
||||
- $x \equiv y^? \space (mod \space n)$
|
||||
- $y \equiv ?^d \space (mod \space n)$
|
||||
- $x \equiv y^? \space (mod \space n)$
|
||||
- It can be fairly easy to calculate $d$:
|
||||
- $e\cdot d \equiv q \space (mod \space \Phi(n))$
|
||||
- $\Phi(n) = (p-1)(q-1)$
|
||||
- $e\cdot d \equiv q \space (mod \space \Phi(n))$
|
||||
- $\Phi(n) = (p-1)(q-1)$
|
||||
- As an attacker we only have access to $e$ and $d$
|
||||
|
||||
### Exponentiation
|
||||
@@ -129,7 +127,7 @@ x^4 = x^2 \cdot x^2 \\
|
||||
x^8 = x^4 \cdot x^4
|
||||
$$
|
||||
|
||||
When calculating a exponent raised to a power of two, we can use previously calculated values.
|
||||
When calculating an exponent raised to a power of two, we can use previously calculated values.
|
||||
|
||||
##### Binary Exponentiation
|
||||
|
||||
@@ -158,8 +156,7 @@ $$
|
||||
##### Computational Complexity
|
||||
|
||||
- What is the computational complexity of exponentiation?
|
||||
- For a 2048 key:
|
||||
- $X^{2^{2048}}$ - A ridiculously big number
|
||||
- Where as using square and multiply
|
||||
- $2048=T$ we need $\frac{3T}{2}$ calculations
|
||||
|
||||
- For a 2048 key:
|
||||
- $X^{2^{2048}}$ - A ridiculously big number
|
||||
- Whereas using square and multiply
|
||||
- $2048=T$ we need $\frac{3T}{2}$ calculations
|
||||
@@ -2,7 +2,7 @@
|
||||
|
||||
- Two parties can jointly agree a *shared secret* over an *insecure channel*
|
||||
- Mathematically, what we are doing is both calculating the same value, mod a prime $p$
|
||||
- Remember $p$ is $\times 10^{600}$
|
||||
- Remember $p$ is $\times 10^{600}$
|
||||
- The parties separately compute the same key, rather than share it
|
||||
|
||||
### $\mathbb{Z}_n^*$
|
||||
@@ -12,7 +12,7 @@
|
||||
> This set forms an *abelian* group under multiplication modulo $n$. The identity element is 1
|
||||
|
||||
- In the majority of cases, we use a prime number as the modulus:
|
||||
- $\mathbb{Z}_p^* = \{1,2,...,p-1\}$
|
||||
- $\mathbb{Z}_p^* = \{1,2,...,p-1\}$
|
||||
|
||||
**Group Cardinality** - The number of elements in that group
|
||||
|
||||
@@ -21,11 +21,11 @@ $$
|
||||
|\mathbb{Z}_m^*| = \Phi(n) \\
|
||||
$$
|
||||
|
||||
- The security of ciphers often depend on the cardinality of the group
|
||||
- The security of ciphers often depends on the cardinality of the group
|
||||
|
||||
#### Cyclic Groups
|
||||
|
||||
- Lets consider group $\mathbb{Z}_{11}^*$
|
||||
- Let's consider group $\mathbb{Z}_{11}^*$
|
||||
- Consider calculating powers of 3 in this group
|
||||
|
||||
$$
|
||||
@@ -71,28 +71,30 @@ $$
|
||||
|
||||
- A group that contains an element $g$ of maximum order is called a cyclic group
|
||||
- Any element of maximum order is called a primitive root, or a generator
|
||||
- $2$ is a generator of $\mathbb{Z}_{11}^* \quad ord(2)=10$
|
||||
- 3 is not a generator $\mathbb{Z}_{11}^* \quad ord(3)=5$
|
||||
- $2$ is a generator of $\mathbb{Z}_{11}^* \quad ord(2)=10$
|
||||
- 3 is not a generator $\mathbb{Z}_{11}^* \quad ord(3)=5$
|
||||
|
||||
##### Cyclic Subgroups
|
||||
|
||||
- For all primes, $(\mathbb{Z}_{11}^*, \cdot)$ is an *abelian finite cyclic group*
|
||||
- Let $g \in G$ where $G$ is a cyclic group:
|
||||
1. $g^{|G|}=1$
|
||||
2. $ord(g)$ divides $|G|$
|
||||
- These are called **cyclic subgroups**
|
||||
- Let $g \in G$ where $G$ is a cyclic group:
|
||||
1. $g^{|G|}=1$
|
||||
2. $ord(g)$ divides $|G|$
|
||||
- These are called **cyclic subgroups**
|
||||
- Orders of $\mathbb{Z}_{11}^*$
|
||||
- 
|
||||
- Note the neutral element generates an order of $1$
|
||||
|
||||
- 
|
||||
|
||||
- Note the neutral element generates an order of $1$
|
||||
|
||||
## Diffie-Hellman
|
||||
|
||||
1. Alice and Bob agree on a large prime $p$, and a generator $g$ that is a primitive root of $p$
|
||||
2. Alice and Bob choose private numbers $a$ and $b$ at random in $\mathbb{Z}_p^*$
|
||||
- Where $a\in \{1,2,...,p-1\}$
|
||||
- and $b\in \{1,2,...,p-1\}$
|
||||
- Where $a\in \{1,2,...,p-1\}$
|
||||
- and $b\in \{1,2,...,p-1\}$
|
||||
3. Alice calculates $A=g^a\space mod \space p$ and sends $A$ publicly to Bob
|
||||
4. Bob calculates $B=g^b\space mod \space p$ and sends $B$ pubicly to Alice
|
||||
4. Bob calculates $B=g^b\space mod \space p$ and sends $B$ publicly to Alice
|
||||
5. Alice computes $k_{ab}=B^a\space mod \space p$
|
||||
6. Bob computes $k_{ab}=A^b\space mod \space p$
|
||||
|
||||
@@ -105,13 +107,13 @@ $$
|
||||
|
||||
- Why is Diffie-Hellman so hard to break
|
||||
- Consider $\mathbb{Z}^*_{10000079},\space g=3$
|
||||
- Alice calculates $A=3^a\space mod \space 10000079 = 4675535$
|
||||
- What is $a$?
|
||||
- Alice calculates $A=3^a\space mod \space 10000079 = 4675535$
|
||||
- What is $a$?
|
||||
- This is the discrete logarithm problem
|
||||
|
||||
**Brute Force** requires $O(|G|)$
|
||||
|
||||
**Shank’s Baby-Step Giant-Step** requires $O(\sqrt{|G|})$ and $\sim \sqrt{|G|}$ space
|
||||
**Shanks’ Baby-Step Giant-Step** requires $O(\sqrt{|G|})$ and $\sim \sqrt{|G|}$ space
|
||||
|
||||
- Using 128 bits, this is $2^{64}$, which would need a cluster
|
||||
|
||||
@@ -121,15 +123,13 @@ $$
|
||||
|
||||
- The discrete log problem is solved mod each prime factor and the results combined using the Chinese remainder theorem
|
||||
|
||||
**Index calculus** directly attacks $\mathbb{Z}_p^*$ and is the reason Elliptic Curves is so much more efficient
|
||||
**Index calculus** directly attacks $\mathbb{Z}_p^*$ and is the reason elliptic curves are so much more efficient
|
||||
|
||||
##### Choosing Primes
|
||||
|
||||
- To avoid any unexpected small subgroup attacks, commonly used DH primes are **safe primes**
|
||||
- A safe prime is a prime $p$ where $\frac{(p-1)}{2}$ is also a prime
|
||||
- Consider the order of $\mathbb{Z}_p^*$ for a safe prime
|
||||
- This will have two subgroups of order $p-1$ and $2$
|
||||
- By choosing a generator of the **subgroup of large prime order**, we avoid attacks on small factors of the group order
|
||||
- Basically this ensures the prime factorisation has one massive prime in it
|
||||
|
||||
|
||||
- This will have two subgroups of order $p-1$ and $2$
|
||||
- By choosing a generator of the **subgroup of large prime order**, we avoid attacks on small factors of the group order
|
||||
- Basically this ensures the prime factorisation has one massive prime in it
|
||||
@@ -6,15 +6,15 @@ $$
|
||||
ax^2+by^2=r^2
|
||||
$$
|
||||
|
||||
- There are an infinite amount of solutions to this equation
|
||||
- However if we restrict to only integers ($\mathbb{Z}$) and use mod, we have a finite set
|
||||
- There are an infinite number of solutions to this equation
|
||||
- However if we restrict to only integers ($\mathbb{Z}$) and use mod, we have a finite set
|
||||
|
||||
- We define an elliptic curve over points in $\mathbb{Z}_p, \space p>3$
|
||||
- Set of all pairs where:
|
||||
- $y^2 \equiv x^3 + ax + b \space (mod \space p)$
|
||||
- $y^2 \equiv x^3 + ax + b \space (mod \space p)$
|
||||
- The neutral element is 0
|
||||
- One requirement is:
|
||||
- $4a^3 + 27b^2 \neq 0 \space (mod \space p)$
|
||||
- $4a^3 + 27b^2 \neq 0 \space (mod \space p)$
|
||||
|
||||
This is $y^2 \equiv x^3 -3x +3$ over $\mathbb{R}$
|
||||
|
||||
@@ -23,8 +23,8 @@ This is $y^2 \equiv x^3 -3x +3$ over $\mathbb{R}$
|
||||
Notice the symmetry about the x axis, this is because we have a $y^2$ term meaning we have two solutions
|
||||
|
||||
- For a DLP problem, we need a cyclic group
|
||||
- Elements within the group
|
||||
- A group operation
|
||||
- Elements within the group
|
||||
- A group operation
|
||||
- For ECs the elements are points on the curve
|
||||
- The operation is point addition
|
||||
|
||||
@@ -47,23 +47,23 @@ In elliptic curves, to get $4P$, we can either do $P+3P$ or $2P+2P$
|
||||
##### Group Properties
|
||||
|
||||
- Closed
|
||||
- Any closed addition operation will end up somewhere on the curve
|
||||
- Any closed addition operation will end up somewhere on the curve
|
||||
- Associative
|
||||
- The order of calculations doesn’t matter
|
||||
- The order of calculations doesn’t matter
|
||||
|
||||
##### Point Addition Equations
|
||||
|
||||
- We can derive equations for this based on the equation for a line that intersects the curve in three places
|
||||
- Given $y^3=x^3+ax+b$ and points:
|
||||
- $P=(x_1,y_1)$
|
||||
- $Q=(x_2, y_2)$
|
||||
- line $y=s\cdot x + m$
|
||||
- Given $y^3=x^3+ax+b$ and points:
|
||||
- $P=(x_1,y_1)$
|
||||
- $Q=(x_2, y_2)$
|
||||
- line $y=s\cdot x + m$
|
||||
- $(sx+m)^2 = x^3 + ax + b$
|
||||
- $s^2x^2 + 2sxm + m^2 = x^3+ax+b$
|
||||
- Plugging in $x_1, y_1, x_2, y_2$
|
||||
- $P+Q=(x_3, y_3)$
|
||||
- $x_3 = s^2 - x_1 - x_2$
|
||||
- $y_3 = s(x_1 - x_3) - y_1$
|
||||
- $P+Q=(x_3, y_3)$
|
||||
- $x_3 = s^2 - x_1 - x_2$
|
||||
- $y_3 = s(x_1 - x_3) - y_1$
|
||||
|
||||
$$
|
||||
s = \cases{\frac{y_2-y_1}{x_2-x_1} \quad (mod\space p); P\neq Q\\{\frac{3x_1^2+a}{2y_1}}\quad (mod\space p); P=Q}
|
||||
@@ -107,20 +107,20 @@ These are a pain as they don’t intersect the curve, we say they cross the curv
|
||||
|
||||
#### The Point $\mathcal O$ at Infinity
|
||||
|
||||
- The point at infinity is the neutral element on a elliptic curve
|
||||
- $P+(-P)=\mathcal O$
|
||||
- $P+\mathcal O=P$
|
||||
- The point at infinity is the neutral element on an elliptic curve
|
||||
- $P+(-P)=\mathcal O$
|
||||
- $P+\mathcal O=P$
|
||||
- In practice the point doesn’t have coordinates, and can’t be used within the normal formula
|
||||
- $P=(x,y)$
|
||||
- $-P=(x,-y)$
|
||||
- $P=(x,y)$
|
||||
- $-P=(x,-y)$
|
||||
- When implementing, you have to detect when the x values are equal and y values are inverses $\mod p$
|
||||
- e.g. $(7,6)+(7,11)$
|
||||
- $\frac{y_2-y_1}{x_2-x_1}=\frac{-5}{0} = \mathcal O$
|
||||
- e.g. $(7,6)+(7,11)$
|
||||
- $\frac{y_2-y_1}{x_2-x_1}=\frac{-5}{0} = \mathcal O$
|
||||
|
||||
### Cyclic Groups
|
||||
|
||||
- The points on an elliptic curve including the neutral element $\mathcal O$ form a cyclic subgroup
|
||||
- Under certain conditions all points for a cyclic group
|
||||
- Under certain conditions all points form a cyclic group
|
||||
|
||||

|
||||
|
||||
@@ -136,48 +136,50 @@ $$
|
||||
This is the graph modulus $p$
|
||||
|
||||
- Given a generator point, points on elliptic curves generate cyclic groups
|
||||
- $y^2 \equiv x^3+2x+2 \mod 17$
|
||||
- 
|
||||
- Here the next two points is the point at infinity ($\mathcal O$) and then it loops back round to $(5,1)$
|
||||
- $y^2 \equiv x^3+2x+2 \mod 17$
|
||||
|
||||
- 
|
||||
|
||||
- Here the next two points are the point at infinity ($\mathcal O$) and then it loops back round to $(5,1)$
|
||||
- Each cyclic group includes the point at infinity
|
||||
|
||||
## Elliptic Curve Discrete Logarithm
|
||||
|
||||
- We can construct a DLP in a very similar way to the modular exponentiation equivalent
|
||||
- $aP = \underbrace{P+P+...+P}_{a \space\textrm{ times}} = A$
|
||||
- $aP = \underbrace{P+P+...+P}_{a \space\textrm{ times}} = A$
|
||||
- Given points $P$ and $A$, find scalar value $a$
|
||||
- Its important to remember the distinction between points on the curve, and integer values
|
||||
- It's important to remember the distinction between points on the curve and integer values
|
||||
- On elliptic curves, private keys such as $a$ are integers
|
||||
- Generators and public keys are points
|
||||
|
||||
#### Group Cardinality
|
||||
|
||||
- The size of cyclic groups is very important to the security
|
||||
- While easy to calculate for modular arithmetic, the number of points on a give elliptic curve is not so obvious
|
||||
- While easy to calculate for modular arithmetic, the number of points on a given elliptic curve is not so obvious
|
||||
- You might imagine that a curve would have $2p+1$ points, in reality it is fewer than this
|
||||
- This is closer to $p$
|
||||
- This is closer to $p$
|
||||
- Hasse’s theorem states that for a curve $E$ over a field $\mathbb{Z}_p$, the number of elements $\#E$ is bounded by:
|
||||
- $\#E=p+1+\epsilon$
|
||||
- where $|\epsilon| \leq 2\sqrt{p}$
|
||||
- $\#E=p+1+\epsilon$
|
||||
- where $|\epsilon| \leq 2\sqrt{p}$
|
||||
|
||||
##### #E
|
||||
|
||||
- A large #E is very important to prevent various attacks on ECDLP
|
||||
- Calculating it exactly is hard, it can be done with Shoof’s algorithm
|
||||
- Calculating it exactly is hard; it can be done with Schoof’s algorithm
|
||||
- Various properties of #E enable or restrict certain attacks
|
||||
|
||||
##### How Hard is ECDLP
|
||||
|
||||
- There are generic algorithms like **Polig-Hellman** that are applicable to any category of DLP
|
||||
- Polig-Hellman requires $O(\sqrt{\#E})$ steps
|
||||
- These are generic attacks mean curves and parameters should be chosen with care
|
||||
- There are generic algorithms like **Pohlig-Hellman** that are applicable to any category of DLP
|
||||
- Pohlig-Hellman requires $O(\sqrt{\#E})$ steps
|
||||
- These generic attacks mean curves and parameters should be chosen with care
|
||||
- The most powerful attack on modular arithmetic based DLP is **index calculus**
|
||||
- It is this attack that forces modular arithmetic based crypto-systems to use >2000 bit keys
|
||||
- Index calculus does not work on elliptic curves so they only need to remain secure against generic attacks
|
||||
- It is this attack that forces modular arithmetic based crypto-systems to use >2000 bit keys
|
||||
- Index calculus does not work on elliptic curves so they only need to remain secure against generic attacks
|
||||
|
||||
#### Efficient Computation
|
||||
|
||||
- There is no nautral way of calculating $a\cdot P$
|
||||
- There is no natural way of calculating $a\cdot P$
|
||||
- Think back to binary exponentiation, square and multiply `->` double and add
|
||||
|
||||
| Decimal | Binary |
|
||||
@@ -199,13 +201,11 @@ E, \#E, G \\
|
||||
\mathrm{Bob}: a\in \{1,2,...,\#E-1\} \\
|
||||
$$
|
||||
|
||||
|
||||
|
||||
Alice takes point $G$ on the curve and add it to $a$: $A = a\cdot G$
|
||||
Alice takes point $G$ on the curve and adds it to $a$: $A = a\cdot G$
|
||||
|
||||
Bob does the same: $B=b\cdot G$
|
||||
|
||||
Alice takes bob’s public key $k_{ab} = a\cdot B$
|
||||
Alice takes Bob’s public key $k_{ab} = a\cdot B$
|
||||
|
||||
Bob does the same: $k_{ab}=b\cdot A$
|
||||
|
||||
@@ -227,7 +227,7 @@ Where each layer builds on the one beneath
|
||||
|
||||
- Since we know the formula for a given curve, we do not need to transport full $(x,y)$ coordinates
|
||||
- Each point contains a unique $x$, and one or two $y$ where
|
||||
- $y=\sqrt{x^3 + 2x + 2}\mod p$
|
||||
- $y=\sqrt{x^3 + 2x + 2}\mod p$
|
||||
- Most implementations will use the full $x$ value, and append a single bit representing a positive or negative y value
|
||||
|
||||
#### Projective Coordinates
|
||||
@@ -244,11 +244,11 @@ Where each layer builds on the one beneath
|
||||
|
||||
- The choice of curve parameters influences both security and efficiency of crypto-systems based around ECs
|
||||
- Never use a randomly generated curve!
|
||||
- The chances are the number of points we generate will have a subgroup susecpible to Polig-Hellmen
|
||||
- The chances are the number of points we generate will have a subgroup susceptible to Pohlig-Hellman
|
||||
- Standard curves exist in various forms
|
||||
- Varied equations
|
||||
- Different implementation methods
|
||||
- Different choices of prime
|
||||
- Varied equations
|
||||
- Different implementation methods
|
||||
- Different choices of prime
|
||||
|
||||
##### P-256
|
||||
|
||||
@@ -259,8 +259,8 @@ Where each layer builds on the one beneath
|
||||

|
||||
|
||||
- $h$ is the cofactor, the size of the subgroup in $G$
|
||||
- Because its 1 it means all the points are being generated
|
||||
- If it was 2, only half of the points are being generated
|
||||
- Because it's 1 it means all the points are being generated
|
||||
- If it was 2, only half of the points are being generated
|
||||
|
||||
##### secp256k1
|
||||
|
||||
@@ -289,5 +289,5 @@ Where each layer builds on the one beneath
|
||||
#### Primary Applications
|
||||
|
||||
- Elliptic Curve Diffie Hellman
|
||||
- DSA Signatures scheme, based on Elgamal signatures
|
||||
- DSA signature scheme, based on Elgamal signatures
|
||||
- Similar schemes involving the alternative curves such as `Ed25519` and `Ed448`
|
||||
@@ -1,8 +1,8 @@
|
||||
# Elgamal Encryption
|
||||
|
||||
#### Extending Diffie-Hellmen to Encryption
|
||||
#### Extending Diffie-Hellman to Encryption
|
||||
|
||||
We could do is multiply the plain text by the key generated
|
||||
What we could do is multiply the plain text by the key generated
|
||||
|
||||
$y\equiv x\cdot k_{ab}\mod p \rightarrow x\equiv y\cdot k_{ab}^{-1}$
|
||||
|
||||
@@ -28,35 +28,35 @@ $y\equiv x\cdot k_{ab}\mod p \rightarrow x\equiv y\cdot k_{ab}^{-1}$
|
||||
|
||||
1. Choose $a\in \{1,2,...,p-1\}$
|
||||
2. Compute ephemeral key
|
||||
- $k_E\equiv g^a\mod p$
|
||||
- Remember ephemeral means the key is generated every time communication happens
|
||||
- $k_E\equiv g^a\mod p$
|
||||
- Remember ephemeral means the key is generated every time communication happens
|
||||
3. Compute masking key
|
||||
- $k_M\equiv B^a\mod p$
|
||||
- $k_M\equiv B^a\mod p$
|
||||
4. Encrypt message $x\in\mathbb{Z}^*_p$
|
||||
- $y\equiv x\cdot k_M\mod p$
|
||||
- $y\equiv x\cdot k_M\mod p$
|
||||
5. Send $(k_E,y)$
|
||||
|
||||
#### Elgamal Decryption
|
||||
|
||||
1. Compute masking key
|
||||
- $k_M\equiv k_E^b\mod p$
|
||||
- $k_M\equiv k_E^b\mod p$
|
||||
2. Decrypt message
|
||||
- $x\equiv y\cdot k_M^{-1}\mod p$
|
||||
- $x\equiv y\cdot k_M^{-1}\mod p$
|
||||
|
||||
### Computational Efficiency
|
||||
|
||||
To calculate bobs private key we use one exponentiation
|
||||
To calculate Bob's private key we use one exponentiation
|
||||
|
||||
Alice has to do two binary exponentiation to send a message to bob
|
||||
Alice has to do two binary exponentiations to send a message to Bob
|
||||
|
||||

|
||||
|
||||
- Both the exponentiations during encryption can be pre-computed during down time
|
||||
- Both the exponentiations during encryption can be pre-computed during downtime
|
||||
- We can also improve on the decryption step using Fermat’s little theorem
|
||||
- Fermat’s Little Theorem: $a^{p-1}\equiv 1\mod p$
|
||||
1. Compute $k_M=k_E^b\mod 67$
|
||||
2. Compute $k_M^{-1}$
|
||||
3. Decrypt $y=y\cdot k_M^{-1}\mod p$
|
||||
1. Compute $k_M=k_E^b\mod 67$
|
||||
2. Compute $k_M^{-1}$
|
||||
3. Decrypt $y=y\cdot k_M^{-1}\mod p$
|
||||
|
||||
#### Practicalities
|
||||
|
||||
@@ -119,17 +119,17 @@ Recall: $a^{p-1}\equiv 1\mod p$ for some $m$
|
||||
- Computed in a subgroup of prime order q, which is usually 160 bits
|
||||
- This means the signature (r, s) is 320 bits
|
||||
- Hashing is enforced by the algorithm, and a hash function must match the key size
|
||||
- e.g. SHA-1 for 160-bit q, SHA-256 for 256 bit q
|
||||
- e.g. SHA-1 for 160-bit q, SHA-256 for 256 bit q
|
||||
- Index calculus does not apply to the sub-group, so 160 bit DSA has a security of 80 bits
|
||||
- In practice larger keys would be required now
|
||||
- In practice larger keys would be required now
|
||||
|
||||
#### ECDSA
|
||||
|
||||
- Identical to DSA, ECDSA operates on an elliptic curve over $\mathbb{Z}_p$ with the signature calculated over a subgroup of prime order $\#q$
|
||||
- More efficient, does not require modulus of thousands of bits
|
||||
- Identical to DSA, ECDSA operates on an elliptic curve over $\mathbb{Z}_p$ with the signature calculated over a subgroup of prime order $\#q$
|
||||
- More efficient, does not require modulus of thousands of bits
|
||||
- Security level is based on generic attacks against EC
|
||||
- i.e $\sqrt{|\#q|}$
|
||||
- i.e. $\sqrt{|\#q|}$
|
||||
- Deterministic generation of $k$ is often used for safety (RFC 6979)
|
||||
- This is where the ephemeral key isn’t random, it’s based off the hash of the message
|
||||
- This is because reusing the ephemeral key is bad news
|
||||
- Other variants like EdDSA using Edwards curves (Ed25519 / Ed448) exist
|
||||
- This is where the ephemeral key isn’t random, it’s based off the hash of the message
|
||||
- This is because reusing the ephemeral key is bad news
|
||||
- Other variants like EdDSA using Edwards curves (Ed25519 / Ed448) exist
|
||||
@@ -3,7 +3,7 @@
|
||||
- A signature is proof of authenticity of the sender
|
||||
- Verification is performed by checking the signature against a known signature
|
||||
- Mostly works for the real world, not very robust
|
||||
- This does not scale
|
||||
- This does not scale
|
||||
|
||||
#### Electronic Signature
|
||||
|
||||
@@ -33,7 +33,7 @@ $$
|
||||
>
|
||||
> This requires using a private key
|
||||
|
||||
Symetric Signatures gives us:
|
||||
Symmetric signatures give us:
|
||||
|
||||
**Authenticity**: The sender is confirmed as authentic - only Alice or Bob could have generated the signature
|
||||
|
||||
@@ -41,7 +41,7 @@ Symetric Signatures gives us:
|
||||
|
||||
**Non-Repudiation**: We don’t have this - the symmetric key means that either Alice or Bob could have sent the message
|
||||
|
||||
### Pubic Key Signatures
|
||||
### Public Key Signatures
|
||||
|
||||
- By using asymmetric cryptography we have non-repudiation.
|
||||
|
||||
@@ -65,14 +65,14 @@ Verification: $s^e\mod n$
|
||||
- Signing and verification require one use of the *square and multiply* algorithm
|
||||
- Efficiency depends on the exponents
|
||||
- We often keep $e$ small
|
||||
- $65537=2^{16}+1=10000000000001_2$
|
||||
- $65537=2^{16}+1=10000000000001_2$
|
||||
- This prioritises verification speed
|
||||
|
||||
##### Signature Forgeries
|
||||
|
||||
- A forgery is the ability to create a valid message / signature pair $(m,s)$ where $m$ hasn’t previously been signed by the legitimate signer
|
||||
- For example replay attack using a previous $(m,s)$ wouldn’t count as a forgery
|
||||
- As we cannot control the message contents
|
||||
- For example, a replay attack using a previous $(m,s)$ wouldn’t count as a forgery
|
||||
- As we cannot control the message contents
|
||||
- Various severities of attack exist depending on the control over the message $m$
|
||||
|
||||
###### Existential Forgeries
|
||||
@@ -84,49 +84,51 @@ Verification: $s^e\mod n$
|
||||
An attacker has access to Alice’s public key $(n,e)$
|
||||
|
||||
- They can calculate
|
||||
- $s=\textrm{random}$
|
||||
- $m' =s^e\mod n$
|
||||
- It is trival to generate message and signature pairs based on an RSA public key
|
||||
- Not very useful
|
||||
- $s=\textrm{random}$
|
||||
- $m' =s^e\mod n$
|
||||
- It is trivial to generate message and signature pairs based on an RSA public key
|
||||
- Not very useful
|
||||
|
||||
###### Selective Forgeries
|
||||
|
||||
- The attacker is able to create a valid message / signature pair $(m,s)$ where they have selected $m$ in advanced
|
||||
- $m$ may have some mathematical proprieties, or be all zeros etc
|
||||
- The attacker is able to create a valid message / signature pair $(m,s)$ where they have selected $m$ in advance
|
||||
- $m$ may have some mathematical properties, or be all zeros etc.
|
||||
- It is a requirement that $m$ be fixed prior to the attack
|
||||
|
||||
###### Universal Forgeries
|
||||
|
||||
- The attacker can create a valid signature from any message $m$
|
||||
- This is the strongest attack, and implies the previous attacks too
|
||||
- In RSA, this would imply the attack has access to the private key
|
||||
- In RSA, this would imply the attacker has access to the private key
|
||||
|
||||
### Malleability
|
||||
|
||||
- RSA is also malleable: $RSA(m_1\cdot m_2)=RSA(m_1)\cdot RSA(m_2)$
|
||||
- Given two messages $x_1, x_2$ and corresponding signatures $s_1,s_2$
|
||||
- $(m_3,s_3)\equiv(m_1\cdot m_2, s_1\cdot s_2)(\mod m)$
|
||||
- $(m_3,s_3)\equiv(m_1\cdot m_2, s_1\cdot s_2)(\mod m)$
|
||||
- This is more control for an attacker than we would like to have for a signature scheme
|
||||
- Malleability is a weakness of encryption with textbook RSA too
|
||||
|
||||
### Padding
|
||||
|
||||
- If we enforce rules about valid formatting on $m$, random messages produced by attackers are unlikely to pass
|
||||
- 
|
||||
|
||||
- 
|
||||
|
||||
- Likelihood of a successful forgery is $2^{-y}$
|
||||
- Probability of last bit $2^{-1}$
|
||||
- Probability of last 2 bits $2^{-2}$
|
||||
- etc up to $y$
|
||||
- Probability of last bit $2^{-1}$
|
||||
- Probability of last 2 bits $2^{-2}$
|
||||
- etc. up to $y$
|
||||
|
||||
#### Hash-then-sign
|
||||
|
||||
- It is common to hash the message within any padding scheme
|
||||
- $sig_{k_{prvA}}(x)\equiv H(x)^d \mod n$
|
||||
- $sig_{k_{prvA}}(x)\equiv H(x)^d \mod n$
|
||||
- Verification recomputes the hash
|
||||
- $ver_{k_{pubA}}(x,s)= s^e \mod n \equiv H(x)'$
|
||||
- $H(x)\stackrel{?}{=}H(x)'$
|
||||
- $ver_{k_{pubA}}(x,s)= s^e \mod n \equiv H(x)'$
|
||||
- $H(x)\stackrel{?}{=}H(x)'$
|
||||
- Existential forgeries are much harder
|
||||
- You’d need a random message that’s also a valid hash
|
||||
- You’d need a random message that’s also a valid hash
|
||||
- Longer messages can be signed, the hash outputs a smaller message digest
|
||||
|
||||
##### PKCS v1.5
|
||||
@@ -135,7 +137,7 @@ An attacker has access to Alice’s public key $(n,e)$
|
||||
|
||||
- Modern padding schemes use hashing and padding for security
|
||||
- Prevents existential forgeries, and attacks on small messages
|
||||
- This is deterministic, the same message gives the same signature
|
||||
- This is deterministic, the same message gives the same signature
|
||||
|
||||

|
||||
|
||||
@@ -145,8 +147,8 @@ An attacker has access to Alice’s public key $(n,e)$
|
||||
|
||||
- “with appendix” refers to any scheme that sends $(m,s)$ separately
|
||||
- PKCS and similar schemes are deterministic
|
||||
- The probabilistic signature scheme adds a random salt to the process, meaning repeated singatures on the same document produce different results
|
||||
- Doesn’t effect security that much, some standards have gone back to a probabilistic approach
|
||||
- The probabilistic signature scheme adds a random salt to the process, meaning repeated signatures on the same document produce different results
|
||||
- Doesn’t affect security that much; some standards have gone back to a probabilistic approach
|
||||
|
||||
###### PSS Encoding
|
||||
|
||||
@@ -157,7 +159,7 @@ An attacker has access to Alice’s public key $(n,e)$
|
||||
5. Expand $H$ using $MGF$
|
||||
6. Calculate $DB \oplus MGF(H)$ to create maskedDB
|
||||
7. Output is maskedDB, $H$ and a constant `0xbc`
|
||||
- `0xbc` is just a constant, no specific meaning other than formatting
|
||||
- `0xbc` is just a constant, no specific meaning other than formatting
|
||||
8. Use RSA to calculate signature and send $(m,s)$ as normal
|
||||
|
||||

|
||||
@@ -180,4 +182,4 @@ An attacker has access to Alice’s public key $(n,e)$
|
||||
|
||||
Nothing is faster than RSA verification, signing is slower
|
||||
|
||||
Its quick because of how 65537 is structured
|
||||
It's quick because of how 65537 is structured
|
||||
@@ -4,7 +4,7 @@
|
||||
|
||||
- Could we simply split up a message and sign parts?
|
||||
|
||||
\
|
||||

|
||||
|
||||
A lot of faff for signing large files
|
||||
|
||||
@@ -16,7 +16,7 @@ A lot of faff for signing large files
|
||||
2. Fixed output length
|
||||
3. Pre-image resistance (one way)
|
||||
4. Second pre-image resistance
|
||||
- If we have a hashed message, we cannot find another message with the same hash
|
||||
- If we have a hashed message, we cannot find another message with the same hash
|
||||
5. Collision resistance
|
||||
|
||||
#### Pre-image Resistance
|
||||
@@ -24,7 +24,7 @@ A lot of faff for signing large files
|
||||
- Hash functions must be one-way
|
||||
- Given a hash of a message $H(x)$ it must be infeasible to calculate $x$
|
||||
- Less applicable to digital signatures
|
||||
- Crucial to password storage and key derivation
|
||||
- Crucial to password storage and key derivation
|
||||
|
||||
#### Second Pre-image Resistance
|
||||
|
||||
@@ -37,7 +37,7 @@ A lot of faff for signing large files
|
||||
|
||||

|
||||
|
||||
Oscar finds a weak message (one of the messages is known ahead of time), he replaces the message $x_1$ with $x_2$. Now Oscar can send a signed message to Alice
|
||||
Oscar finds a weak message (one of the messages is known ahead of time); he replaces the message $x_1$ with $x_2$. Now Oscar can send a signed message to Alice
|
||||
|
||||
#### Collision Resistance
|
||||
|
||||
@@ -80,8 +80,8 @@ P(n)&=(1-\frac{1}{365})\cdot (1-\frac{2}{365})\dots (1-\frac{n-1}{365})
|
||||
$$
|
||||
|
||||
- The probability of at least one collision is $1 – P(\textrm{no collision})$.
|
||||
- The probability of a collision with only 23 people is ~50%!
|
||||
- For 40 people it’s ~90%
|
||||
- The probability of a collision with only 23 people is ~50%!
|
||||
- For 40 people it’s ~90%
|
||||
- The same principle applies to hash functions, the more hashes computed, the more likely a collision becomes
|
||||
|
||||

|
||||
@@ -93,4 +93,4 @@ $$
|
||||
- You will find a collision after approx $\sqrt{(2^n)}=2^{\frac n2}$ random attempts
|
||||
- This means that your bit length needs to be double the size of your desired security margin
|
||||
- `SHA-256` therefore offers equivalent security to `AES 128`
|
||||
- left at `25:55`
|
||||
- left at `25:55`
|
||||
@@ -3,8 +3,8 @@
|
||||
### Message Authentication Codes
|
||||
|
||||
- Provide integrity and authenticity - not confidentiality
|
||||
- Protecting system files
|
||||
- Ensuring messages haven’t been altered
|
||||
- Protecting system files
|
||||
- Ensuring messages haven’t been altered
|
||||
- Calculate a keyed hash of the message, then append this to the end of the message
|
||||
|
||||

|
||||
@@ -18,7 +18,7 @@
|
||||
|
||||
#### Authenticated Encryption (AEAD)
|
||||
|
||||
- It’s common to attach MACs to the end of ciphertext, that this is now usually built into ciphers as part of AEAD mode
|
||||
- It’s common to attach MACs to the end of ciphertext; this is now usually built into ciphers as part of AEAD mode
|
||||
- You’re often able to authenticate non-encrypted “associated” data too
|
||||
|
||||

|
||||
@@ -30,19 +30,19 @@
|
||||
- TLS is a protocol that provides *authenticated* and *encrypted* sessions
|
||||
- Secure Socket Layer (SSL) came first, then after `v3.0` it became TLS
|
||||
- Transport Layer Security has two layers
|
||||
1. The record layer
|
||||
- Using established symmetric keys and other session info, will encrypt application packets, very like IPsec
|
||||
2. The handshake layer
|
||||
- Used to establish session keys, as well as authenticate either party - usually the server using a public key certificate
|
||||
1. The record layer
|
||||
- Using established symmetric keys and other session info, will encrypt application packets, very like IPsec
|
||||
2. The handshake layer
|
||||
- Used to establish session keys, as well as authenticate either party - usually the server using a public key certificate
|
||||
|
||||
##### TLS Handshake
|
||||
|
||||
- The TLS handshake allows us to
|
||||
- Establish the master secret
|
||||
- Resume sessions
|
||||
- Authenticate the identity of the server or client
|
||||
- Establish the master secret
|
||||
- Resume sessions
|
||||
- Authenticate the identity of the server or client
|
||||
- This is for TLS 1.2 - ECDHE_RSA
|
||||
- Elliptic curve with Diffie-Hellman ephemeral with RSA
|
||||
- Elliptic curve with Diffie-Hellman ephemeral with RSA
|
||||
|
||||

|
||||
|
||||
@@ -71,6 +71,7 @@ Random Number: 16cf43a...
|
||||
Suite: TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256
|
||||
[Session ID]
|
||||
```
|
||||
|
||||
Random nonce used to stop replay attacks
|
||||
|
||||
**Certificate**
|
||||
@@ -97,7 +98,7 @@ Digital Signature calculated over the DH parameters
|
||||
|
||||
**[Certificate Request]**
|
||||
|
||||
Optional request for a certificate and singature from the client - only used in mutual TLS
|
||||
Optional request for a certificate and signature from the client - only used in mutual TLS
|
||||
|
||||
Imagine two banks communicating where both parties need to prove their identity.
|
||||
|
||||
@@ -117,7 +118,7 @@ Optional client certificate, verified by the server using PKI
|
||||
|
||||
**[Certificate Verify]**
|
||||
|
||||
Digital signature computed over the bytes send in the handshake so far
|
||||
Digital signature computed over the bytes sent in the handshake so far
|
||||
|
||||
**Change Cipher Spec**
|
||||
|
||||
@@ -147,7 +148,7 @@ Mitigates man-in-the-middle attacks
|
||||
|
||||
## Public Key Infrastructure
|
||||
|
||||
#### Why do we need PKI?
|
||||
#### Why do we need PKI?
|
||||
|
||||

|
||||
|
||||
@@ -184,7 +185,7 @@ Mitigates man-in-the-middle attacks
|
||||
##### Who manages the Root Certificates?
|
||||
|
||||
- Major OS vendors operate *root certificate programs*
|
||||
- Apple for iOS and OS X
|
||||
- Microsoft for Windows
|
||||
- Mozilla maintains root certificate store
|
||||
- Used in linux & firefox
|
||||
- Apple for iOS and OS X
|
||||
- Microsoft for Windows
|
||||
- Mozilla maintains a root certificate store
|
||||
- Used in Linux & Firefox
|
||||
Reference in new issue
Block a user