Tidy up
This commit is contained in:
103 files changed
+3663
-3779
No files matched your search
@@ -5,23 +5,25 @@
|
||||
- Most messages don’t come in convenient 128-bit block lengths
|
||||
- We’ll need to run a block cipher repeatedly on consecutive blocks
|
||||
- Why not use stream ciphers?
|
||||
- Historically stream ciphgers have proven harder to implement
|
||||
- Historically, stream ciphers have proven harder to implement
|
||||
|
||||
##### Padding
|
||||
|
||||
- ECB and some other modes require message length to be a multiple of the block size
|
||||
- Public Key Cryptography Standards `PKCS7` is a common padding scheme:
|
||||
1. Padding bytes are always added to the plaintext **before it is encrypted**
|
||||
2. Each padding byte has a *value equal to the total number of padding bytes* that are added
|
||||
3. The total number of padding bytes is **atleast one**
|
||||
1. Padding bytes are always added to the plaintext **before it is encrypted**
|
||||
2. Each padding byte has a *value equal to the total number of padding bytes* that are added
|
||||
3. The total number of padding bytes is **at least one**
|
||||
|
||||
- 
|
||||
|
||||
- Note in this example there are 7 `7`s and 16 `16`s
|
||||
- Note the bottom left example there is 1 `1`. This could be interpreted as 1 bytes of padding or some plaintext. This is why every block must contain at least one padding byte
|
||||
- Note that in the bottom-left example there is 1 `1`. This could be interpreted as 1 byte of padding or some plaintext. This is why every block must contain at least one padding byte
|
||||
|
||||
### Electronic Code Book Mode (ECB)
|
||||
|
||||
- Just encrypt each block one after another
|
||||
- This is quick as can be easily parallelised
|
||||
- This is quick as it can be easily parallelised
|
||||
|
||||

|
||||
|
||||
@@ -44,7 +46,7 @@
|
||||
### Deterministic vs Probabilistic Encryption
|
||||
|
||||
- An encryption scheme is **deterministic** if some plaintext is mapped to a fixed ciphertext if the key is unchanged
|
||||
- ECB is deterministic, but most modern modes of operation of **probabilistic**
|
||||
- ECB is deterministic, but most modern modes of operation are **probabilistic**
|
||||
- Probabilistic encryption schemes add randomness to the encryption process to achieve a non-deterministic generation of the ciphertext
|
||||
|
||||

|
||||
@@ -55,9 +57,9 @@
|
||||
|
||||
- `XOR` the output of each cipher block with the next input
|
||||
- $IV$ - **Initialisation Vector**
|
||||
- The initial random seed that randomises the whole stream
|
||||
- If you encrypted the same plaintext later it will be different
|
||||
- An attacker will be unable to tell if $y_1$ and $y_2$ are the same message but with different $IV$ or different messages with different $IV$
|
||||
- The initial random seed that randomises the whole stream
|
||||
- If you encrypted the same plaintext later it will be different
|
||||
- An attacker will be unable to tell if $y_1$ and $y_2$ are the same message but with different $IV$ or different messages with different $IV$
|
||||
|
||||

|
||||
|
||||
@@ -79,29 +81,31 @@ x_i = d_k(y_i) \oplus y_{i-1}
|
||||
$$
|
||||
|
||||
- If we lost $y_1$ we would be unable to decrypt $y_2$
|
||||
- We would be able to decrypt $y_3$ though
|
||||
- We would be able to decrypt $y_3$ though
|
||||
|
||||
##### Weaknesses
|
||||
|
||||
- CBC was the primary method of encryption for many years
|
||||
- Now it is less common
|
||||
- CBC was the primary method of encryption for many years
|
||||
- Now it is less common
|
||||
|
||||
- 
|
||||
|
||||
- If you flip the first bit in $y_2$, the same bit is flipped for $x_3$
|
||||
- Changing $y_2$ means $x_2$ no longer decrypts properly
|
||||
- Changing $y_2$ means $x_2$ no longer decrypts properly
|
||||
|
||||
### Padding Oracles
|
||||
|
||||
- Here, an **oracle** is a system we can query and it will tell us if, once decrypt, some text has **valid padding**
|
||||
- Here, an **oracle** is a system we can query and it will tell us if, once decrypted, some text has **valid padding**
|
||||
- A system is unlikely to tell you directly, but it might give away some clue
|
||||
- Image an example `api` that receives a CBC encrypted authorisation token
|
||||
- Imagine an example `api` that receives a CBC-encrypted authorisation token
|
||||
|
||||

|
||||
|
||||
#### Padding Oracle Attacks
|
||||
|
||||
- Lets look at a single decryption block in CBC
|
||||
- Let's look at a single decryption block in CBC
|
||||
- The attack is essentially the same for multiple blocks, just one at a time
|
||||
- You attack the last block, which contains the padding
|
||||
- You attack the last block, which contains the padding
|
||||
|
||||
> The general strategy is to manipulate bits in the IV to find valid padding and recover $z_i$
|
||||
|
||||
@@ -116,22 +120,22 @@ $$
|
||||
### Counter Mode (CTR)
|
||||
|
||||
- Encrypt a nonce + counter and use this to mask the plaintext with `XOR`
|
||||
- This is very easily parallelised
|
||||
- Each block is encrypted differently, avoiding the issues with ECB mode
|
||||
- This is very easily parallelised
|
||||
- Each block is encrypted differently, avoiding the issues with ECB mode
|
||||
|
||||

|
||||
|
||||
- We are now using our block cipher as a stream cipher
|
||||
- The keystream generation (AES) is run through blocks
|
||||
- The keystream generation (AES) is run through blocks
|
||||
- Decrypting is super easy, just the reverse
|
||||
|
||||
### Galois Counter Mode
|
||||
|
||||
- Extends counter mode to add authenticity
|
||||
- The sender definitely sent that message and it hasn’t been modified
|
||||
- Very similar to ocunter mode, but **adds authentication tag**
|
||||
- Uses multiplication in a Galois Finite field $GF(2^{128})$ modulo $x^{128} + x^7 + x^2 + x + 1$
|
||||
- Extremely parallelsiable
|
||||
- The sender definitely sent that message and it hasn’t been modified
|
||||
- Very similar to counter mode, but **adds an authentication tag**
|
||||
- Uses multiplication in a Galois Finite field $GF(2^{128})$ modulo $x^{128} + x^7 + x^2 + x + 1$
|
||||
- Extremely parallelisable
|
||||
- Robust to message modification
|
||||
- Is now standard in `TLS1.3`
|
||||
|
||||
|
||||
Reference in new issue
Block a user