Files
notes/docs/lectures/security/03_cryptography.md
T

5.1 KiB
Raw Blame History

Symmetric Cryptography

  • Symmetric encryption gives us confidentiality
  • Implemented using block ciphers or stream ciphers
    • Lightweight and fast
    • Used for general communication

1644517237.png

Stream Cipher

  • Stream ciphers use an initial seed key to generate an infinite keystream of random looking bits

  • The message and keystream are usually combined using an xor (\oplus) which is reversible if applied twice

  • How ever using the same keystream to encrypt two messages makes messages easy to break

  • A random number used once nonce is added as an additional seed

  • The nonce is not a secret, it simply ensures the keystream is new

Pros and Cons

✅ Encrypting long continuous streams, possibly of unknown length

✅ Extremely fast with low memory footprint, ideal for low-power battery devices

✅ If designed well, can seek to any location in the stream

❌ The keystream must appear statistically random

❌ You must never reuse a key & nonce

❌ Stream ciphers do not protect the cipher-text

Block Ciphers

  • Block ciphers use a key to encrypt a fixed size block of plain text into a fixed-sized block of cipher-text
    • Changing and permuting the bits of the block depending on the key
  • Different lengths of messages can be handled by splitting the message up, and padding
SP-Network
  • Repeated substitution and permutation

1644517216.png

  • This round will be run multiple times (around 10-15 times)
Key Mixing
  • Mixing in the key prevents attackers from reversing the process

1644517396.png

  • To decrypt, reverse the process

Symmetric Algorithms

  • DES was used from 1970s to 2000s
  • 3DES (using DES 3 times) is sometimes found in legacy systems
  • AES and ChaCha20 are the only two ciphers used in TLS 1.3
Algorithm Cipher type Design Block Size (bits) Speed Memory Footprint Safe Implementation Difficulty Key Sizes
DES Block Feistel 64 Fast Low Easy 56
3DES Block Feistel 64 Slow Low Easy 112
AES Block SP-Network 128 very fast medium Hard 128/192
ChaCha20 Stream add-xor-rot N/A Very fast very low Easy 256

Attack Models

  1. Brute force
    • Weakest attack, guessing the key
    • If the key is 2^{128}, on a super computer would take 10^9 years
  2. Cipher text only
    • Static analysis on the cipher text, frequency analysis etc
    • e.g. looking at the enginma machine and recognising a letter cannot be itself
  3. Known plaintext
    • Where you know some plaintext and the corresponding ciphertext
    • e.g. Enigma being broken using “heil hitler”
  4. Chosen plaintext
    • Seeing if certain plain-texts takes the algorithm longer/shorter
  5. Chosen ciphertext
  6. Related-key attack
    • Get the same message encrypted in different keys
    • More of a theoretical attack

Modern algorithms are expected to overcome these attacks trivially

Asymmetric Encryption

  • Two keys, a public & private key
  • Public-key asymmetric cryptography hinges upon the premuse that:
    • It is computationally infeasible to calculate a private key from a public key
  • In practice this is achieved through intractable mathematical problems

Key Exchange

  • Diffie-Hellman key exchange allows two parties to mathematically agree a shared secret over an insecure channel

1644518533.png

It is extremely easy to go from a -> A but extremely difficult to go backwards.

  • Encryption performed by the public key can only be decrypted by the corresponding private key

Public key Encryption

  • Client encrypts message with servers public key, now only the server’s private key can be used to read it.
  • The authenticity of signatures generated by the private key can be verified by the public key

1644519300.png

Public key Algorithms
Algorithm Key Exchange Encryption Digital Signitures Mathematical Problem Elliptic Curves Typical Key Size
Diffie-Hellmen ✅ ❌ ❌ Discrete Logs ✅ 256
RSA ❌ ✅ ✅ Integer Factorisation ❌ 2048/4096
Elgamal ❌ ✅ ✅ Discrete Logs ✅ 2048
DSA ❌ ❌ ✅ Discrete Logs ✅ 256