5.1 KiB
Symmetric Cryptography
- Symmetric encryption gives us confidentiality
- Implemented using block ciphers or stream ciphers
- Lightweight and fast
- Used for general communication
Stream Cipher
-
Stream ciphers use an initial seed key to generate an infinite keystream of random looking bits
-
The message and keystream are usually combined using an
xor(\oplus) which is reversible if applied twice -
However, using the same keystream to encrypt two messages makes messages easy to break
-
A random number used once nonce is added as an additional seed
-
The nonce is not a secret, it simply ensures the keystream is new
Pros and Cons
✅ Encrypting long continuous streams, possibly of unknown length
✅ Extremely fast with low memory footprint, ideal for low-power battery devices
✅ If designed well, can seek to any location in the stream
❌ The keystream must appear statistically random
❌ You must never reuse a key & nonce
❌ Stream ciphers do not protect the cipher-text
Block Ciphers
- Block ciphers use a key to encrypt a fixed size block of plain text into a fixed-sized block of cipher-text
- Changing and permuting the bits of the block depending on the key
- Different lengths of messages can be handled by splitting the message up, and padding
SP-Network
- Repeated substitution and permutation
- This round will be run multiple times (around 10-15 times)
Key Mixing
- Mixing in the key prevents attackers from reversing the process
- To decrypt, reverse the process
Symmetric Algorithms
DESwas used from 1970s to 2000s3DES(using DES 3 times) is sometimes found in legacy systemsAESandChaCha20are the only two ciphers used inTLS 1.3
| Algorithm | Cipher type | Design | Block Size (bits) | Speed | Memory Footprint | Safe Implementation Difficulty | Key Sizes |
|---|---|---|---|---|---|---|---|
DES |
Block | Feistel |
64 | Fast | Low | Easy | 56 |
3DES |
Block | Feistel |
64 | Slow | Low | Easy | 112 |
AES |
Block | SP-Network |
128 | very fast | medium | Hard | 128/192 |
ChaCha20 |
Stream | add-xor-rot | N/A | Very fast | very low | Easy | 256 |
Attack Models
- Brute force
- Weakest attack, guessing the key
- If the key is
2^{128}, on a supercomputer it would take10^9years
- Cipher text only
- Static analysis on the cipher text, frequency analysis etc
- e.g. looking at the Enigma machine and recognising a letter cannot be itself
- Known plaintext
- Where you know some plaintext and the corresponding ciphertext
- e.g. Enigma being broken using “heil hitler”
- Chosen plaintext
- Seeing if certain plain-texts take the algorithm longer/shorter
- Chosen ciphertext
- Related-key attack
- Get the same message encrypted in different keys
- More of a theoretical attack
Modern algorithms are expected to overcome these attacks trivially
Asymmetric Encryption
- Two keys, a public & private key
- Public-key asymmetric cryptography hinges upon the premise that:
- It is computationally infeasible to calculate a private key from a public key
- In practice this is achieved through intractable mathematical problems
Key Exchange
- Diffie-Hellman key exchange allows two parties to mathematically agree a shared secret over an insecure channel
It is extremely easy to go from a -> A but extremely difficult to go backwards.
- Encryption performed by the public key can only be decrypted by the corresponding private key
Public key Encryption
- Client encrypts message with the server’s public key; now only the server’s private key can be used to read it.
- The authenticity of signatures generated by the private key can be verified by the public key
Public key Algorithms
| Algorithm | Key Exchange | Encryption | Digital Signatures | Mathematical Problem | Elliptic Curves | Typical Key Size |
|---|---|---|---|---|---|---|
| Diffie-Hellman | ✅ | ❌ | ❌ | Discrete Logs | ✅ | 256 |
RSA |
❌ | ✅ | ✅ | Integer Factorisation | ❌ | 2048/4096 |
Elgamal |
❌ | ✅ | ✅ | Discrete Logs | ✅ | 2048 |
DSA |
❌ | ❌ | ✅ | Discrete Logs | ✅ | 256 |




