Files
2026-10-04 15:24:17 +01:00

120 lines
5.1 KiB
Markdown
Raw Permalink Blame History

This file contains ambiguous Unicode characters
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
# Symmetric Cryptography
- Symmetric encryption gives us confidentiality
- Implemented using block ciphers or stream ciphers
- Lightweight and fast
- Used for general communication
![1644517237.png](img/1644517237.png)
### Stream Cipher
- Stream ciphers use an initial seed key to generate an infinite keystream of random looking bits
- The message and keystream are usually combined using an `xor` ($\oplus$) which is reversible if applied twice
- However, using the same keystream to encrypt two messages makes messages easy to break
- A random *number used once* nonce is added as an additional seed
- The nonce is not a secret, it simply ensures the keystream is new
##### Pros and Cons
✅ Encrypting long continuous streams, possibly of unknown length
✅ Extremely fast with low memory footprint, ideal for low-power battery devices
✅ If designed well, can seek to any location in the stream
❌ The keystream must appear statistically random
❌ You must **never** reuse a key & nonce
❌ Stream ciphers do not protect the cipher-text
#### Block Ciphers
- Block ciphers use a key to encrypt a fixed size block of plain text into a *fixed-sized block* of cipher-text
- Changing and permuting the bits of the block depending on the key
- Different lengths of messages can be handled by splitting the message up, and padding
##### SP-Network
- Repeated substitution and permutation
![1644517216.png](img/1644517216.png)
- This round will be run multiple times (around 10-15 times)
###### Key Mixing
- Mixing in the key prevents attackers from reversing the process
![1644517396.png](img/1644517396.png)
- To decrypt, reverse the process
#### Symmetric Algorithms
- `DES` was used from 1970s to 2000s
- `3DES` (using DES 3 times) is sometimes found in legacy systems
- `AES` and `ChaCha20` are the only two ciphers used in `TLS 1.3`
| Algorithm | Cipher type | Design | Block Size (bits) | Speed | Memory Footprint | Safe Implementation Difficulty | Key Sizes |
| ---------- | ----------- | ------------ | ----------------- | --------- | ---------------- | ------------------------------ | --------- |
| `DES` | Block | `Feistel` | 64 | Fast | Low | Easy | 56 |
| `3DES` | Block | `Feistel` | 64 | Slow | Low | Easy | 112 |
| `AES` | Block | `SP-Network` | 128 | very fast | medium | Hard | 128/192 |
| `ChaCha20` | Stream | add-xor-rot | N/A | Very fast | very low | Easy | 256 |
### Attack Models
1. Brute force
- Weakest attack, guessing the key
- If the key is $2^{128}$, on a supercomputer it would take $10^9$ years
2. Cipher text only
- Static analysis on the cipher text, frequency analysis etc
- e.g. looking at the Enigma machine and recognising a letter cannot be itself
3. Known plaintext
- Where you know some plaintext and the corresponding ciphertext
- e.g. Enigma being broken using “heil hitler”
4. Chosen plaintext
- Seeing if certain plain-texts take the algorithm longer/shorter
5. Chosen ciphertext
6. Related-key attack
- Get the same message encrypted in different keys
- More of a theoretical attack
Modern algorithms are expected to overcome these attacks trivially
## Asymmetric Encryption
- Two keys, a public & private key
- Public-key asymmetric cryptography hinges upon the premise that:
- It is computationally infeasible to calculate a private key from a public key
- In practice this is achieved through intractable mathematical problems
#### Key Exchange
- Diffie-Hellman key exchange allows two parties to mathematically agree a shared secret over an insecure channel
![1644518533.png](img/1644518533.png)
It is extremely easy to go from a -> A but extremely difficult to go backwards.
- Encryption performed by the **public** key can only be decrypted by the corresponding **private** key
#### Public key Encryption
- Client encrypts message with the server’s public key; now only the server’s private key can be used to read it.
- The authenticity of signatures generated by the private key can be verified by the public key
![1644519300.png](img/1644519300.png)
##### Public key Algorithms
| Algorithm | Key Exchange | Encryption | Digital Signatures | Mathematical Problem | Elliptic Curves | Typical Key Size |
| :------------- | :----------: | :--------: | :----------------: | --------------------- | :-------------: | ---------------- |
| Diffie-Hellman | ✅ | ❌ | ❌ | Discrete Logs | ✅ | 256 |
| `RSA` | ❌ | ✅ | ✅ | Integer Factorisation | ❌ | 2048/4096 |
| `Elgamal` | ❌ | ✅ | ✅ | Discrete Logs | ✅ | 2048 |
| `DSA` | ❌ | ❌ | ✅ | Discrete Logs | ✅ | 256 |