# Symmetric Cryptography - Symmetric encryption gives us confidentiality - Implemented using block ciphers or stream ciphers - Lightweight and fast - Used for general communication ![1644517237.png](img/1644517237.png) ### Stream Cipher - Stream ciphers use an initial seed key to generate an infinite keystream of random looking bits - The message and keystream are usually combined using an `xor` ($\oplus$) which is reversible if applied twice - However, using the same keystream to encrypt two messages makes messages easy to break - A random *number used once* nonce is added as an additional seed - The nonce is not a secret, it simply ensures the keystream is new ##### Pros and Cons ✅ Encrypting long continuous streams, possibly of unknown length ✅ Extremely fast with low memory footprint, ideal for low-power battery devices ✅ If designed well, can seek to any location in the stream ❌ The keystream must appear statistically random ❌ You must **never** reuse a key & nonce ❌ Stream ciphers do not protect the cipher-text #### Block Ciphers - Block ciphers use a key to encrypt a fixed size block of plain text into a *fixed-sized block* of cipher-text - Changing and permuting the bits of the block depending on the key - Different lengths of messages can be handled by splitting the message up, and padding ##### SP-Network - Repeated substitution and permutation ![1644517216.png](img/1644517216.png) - This round will be run multiple times (around 10-15 times) ###### Key Mixing - Mixing in the key prevents attackers from reversing the process ![1644517396.png](img/1644517396.png) - To decrypt, reverse the process #### Symmetric Algorithms - `DES` was used from 1970s to 2000s - `3DES` (using DES 3 times) is sometimes found in legacy systems - `AES` and `ChaCha20` are the only two ciphers used in `TLS 1.3` | Algorithm | Cipher type | Design | Block Size (bits) | Speed | Memory Footprint | Safe Implementation Difficulty | Key Sizes | | ---------- | ----------- | ------------ | ----------------- | --------- | ---------------- | ------------------------------ | --------- | | `DES` | Block | `Feistel` | 64 | Fast | Low | Easy | 56 | | `3DES` | Block | `Feistel` | 64 | Slow | Low | Easy | 112 | | `AES` | Block | `SP-Network` | 128 | very fast | medium | Hard | 128/192 | | `ChaCha20` | Stream | add-xor-rot | N/A | Very fast | very low | Easy | 256 | ### Attack Models 1. Brute force - Weakest attack, guessing the key - If the key is $2^{128}$, on a supercomputer it would take $10^9$ years 2. Cipher text only - Static analysis on the cipher text, frequency analysis etc - e.g. looking at the Enigma machine and recognising a letter cannot be itself 3. Known plaintext - Where you know some plaintext and the corresponding ciphertext - e.g. Enigma being broken using “heil hitler” 4. Chosen plaintext - Seeing if certain plain-texts take the algorithm longer/shorter 5. Chosen ciphertext 6. Related-key attack - Get the same message encrypted in different keys - More of a theoretical attack Modern algorithms are expected to overcome these attacks trivially ## Asymmetric Encryption - Two keys, a public & private key - Public-key asymmetric cryptography hinges upon the premise that: - It is computationally infeasible to calculate a private key from a public key - In practice this is achieved through intractable mathematical problems #### Key Exchange - Diffie-Hellman key exchange allows two parties to mathematically agree a shared secret over an insecure channel ![1644518533.png](img/1644518533.png) It is extremely easy to go from a -> A but extremely difficult to go backwards. - Encryption performed by the **public** key can only be decrypted by the corresponding **private** key #### Public key Encryption - Client encrypts message with the server’s public key; now only the server’s private key can be used to read it. - The authenticity of signatures generated by the private key can be verified by the public key ![1644519300.png](img/1644519300.png) ##### Public key Algorithms | Algorithm | Key Exchange | Encryption | Digital Signatures | Mathematical Problem | Elliptic Curves | Typical Key Size | | :------------- | :----------: | :--------: | :----------------: | --------------------- | :-------------: | ---------------- | | Diffie-Hellman | ✅ | ❌ | ❌ | Discrete Logs | ✅ | 256 | | `RSA` | ❌ | ✅ | ✅ | Integer Factorisation | ❌ | 2048/4096 | | `Elgamal` | ❌ | ✅ | ✅ | Discrete Logs | ✅ | 2048 | | `DSA` | ❌ | ❌ | ✅ | Discrete Logs | ✅ | 256 |