0% found this document useful (0 votes)
7 views40 pages

Cryptography

The project report titled 'Study of Cryptography' by Anu A.P, Hareesh C.S, and Jissa Sabu explores the science of encrypting and decrypting data, its applications, types, and future prospects. It includes a detailed examination of symmetric and asymmetric key cryptography, their definitions, terminologies, historical context, and the importance of cryptographic protocols for data security. The report is submitted in partial fulfillment of the requirements for a Bachelor of Science in Mathematics at Mahatma Gandhi University, Kottayam.

Uploaded by

pkkuttymama
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
7 views40 pages

Cryptography

The project report titled 'Study of Cryptography' by Anu A.P, Hareesh C.S, and Jissa Sabu explores the science of encrypting and decrypting data, its applications, types, and future prospects. It includes a detailed examination of symmetric and asymmetric key cryptography, their definitions, terminologies, historical context, and the importance of cryptographic protocols for data security. The report is submitted in partial fulfillment of the requirements for a Bachelor of Science in Mathematics at Mahatma Gandhi University, Kottayam.

Uploaded by

pkkuttymama
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

St.

Thomas College Kozhencherry


Department of Mathematics

PROJECT REPORT
A STUDY OF CRYPTOGRAPHY
AUTHORS:
ANU A.P (Reg No: 180021036894)
HAREESH C.S (Reg No: 180021036905)
JISSA SABU (Reg No: 180021036910)
SUPERVISOR:
Mrs. PRIYA MATHEWS
ASSISTANT PROFESSOR
DEPARTMENT OF MATHEMATEMATICS
ST. THOMAS COLLEGE KOZHENCHERRY

A dissertation submitted in partial fulfillment of the requirements for the award of the Degree

of Bachelor of Science in Mathematics

of
MAHATMA GANDHI UNIVERSITY KOTTAYAM
31st March,2021
St. Thomas College, Kozhencherry
Department of Mathematics

CERTIFICATE FOR SUPERVISION


This is to certify that this dissertation titled, “STUDY OF CRYPTOGRAPHY”
submitted by
ANU A.P HAREESH C.S JISSA SABU
(Reg no:180021036894) (Reg No:180021036905) (Reg No:180021036910)

In partial fulfillment of the requirements for the degree of Bachelor of


Science in Mathematics of the MAHATMA GANDHI UNIVERSITY,
KOTTAYAM, is the bonafide record of the studies undertaken by them
under my supervision at this college during the period 2018-2021. This
project has not been submitted for the award of any other degree at this
college or any other institution.

Mrs. Priya Mathews


Project Supervisor and Assistant Professor

Department of Mathematics

St. Thomas college Kozhencherry

Prof. Ann Susa Thomas

Head and assistant professor

Department of mathematics

St. Thomas college Kozhencherry


St. Thomas College Kozhencherry
Department of Mathematics

DECLARATION OF AUTHORSHIP

We, hereby declare that this dissertation titled, “STUDY OF


CRYPTOGRAPHY” and the work presented in it is our own and has been
carried out under the supervision and guidance of Mrs. Priya Mathews of
department of mathematics.
We confirm that:

• This work was done wholly while in candidature for a Bachelor’s


degree at this College.
• Where any part of this dissertation has previously been submitted
for a degree or any other qualification at this college or any other
institution, this has been clearly stated.
• Where we have consulted the published work of others, this is
always clear attributed.
• Where we have quoted from the word of others, the source is always
given. with the exception of such quotation this dissertation is
entirely our own work.
• We have acknowledged all main sources of help.
• Where the dissertation is based on work done by ourselves jointly
with others, we have made clear exactly what was done by us and
what others have contributed themselves.
ANU A.P HAREESH C.S JISSA SABU

(Reg No:180021036894) (Reg No:180021036905) (Reg No:180021036910)

Date:
“Programming is one of the most difficult branches of
applied mathematics; the poorer mathematicians had better
remain pure mathematicians”
-Edsger Dijkstra-
St. Thomas College Kozhencherry
Department of Mathematics
Abstract
STUDY OF CRYPTOGRAPHY
BY
ANU A.P
(Reg No: 180021036894)
HAREESH C.S
(Reg No: 180021036905)
JISSA SABU
(Reg No: 180021036910)

This project deals with the study of cryptography, Some of its applications, Types of
cryptography with examples and future of cryptography.
Acknowledgements
We are grateful to all those who provided their assistance and cooperation during the
development of our dissertation “study of cryptography”
We thank GOD ALMIGHTY for give us the knowledge and wisdom to complete the work.
We express our sincere gratitude to THE PRINCIPAL, ST. THOMAS COLLEGE
KOZHENCHERRY for the encouragement by providing the facilities in the college for the
smooth conduct of project work.
We are also thankful to prof. ANN SUSA THOMAS, Head of the department for the
valuable suggestions and guidance.
We are extremely grateful to our project supervisor Mrs. Priya Mathews for the active
interest taken in our work and valuable guidance throughout.
We take this opportunity to thank all our teachers and friends for the support, cooperation
and encouragement rendered to us.
The completion of the project owes a lot to our parents and family members.
ANU A.P HAREESH C.S
(Reg No: 180021036894) (Reg No: 180021036905)
JISSA SABU
(Reg No: 180021036910)

Kozhencherry

Date:
To our Teachers, Parents and Friends….
CONTENTS
Certificate of supervision
Declaration of authorship
Abstract
Acknowledgement
Introduction
CHAPTER-1
●Cryptography
● Definition
●Terminology
● History
●Goal and services
CHAPTER-2

• Types of Cryptography
o Symmetric Key Cryptography
o Asymmetric Key Cryptography
o Hash Cryptography
• PGP Encryption
• Key management
• Digital certificate
• Certifying authority
• Certificate management system
• Benefit and drawback of cryptography
• Future of cryptography
• Conclusion
INTRODUCTION

Cryptography is the science of encrypting and decrypting data. Based on


complex mathematics, cryptography provides several important information
security services such as authentication, confidentiality, integrity, and non-
repudiation. Cryptographic protocols and applications make cryptography user-
friendly and enable users to secure their data without having to carry out the
complex mathematics themselves. Modern cryptography relies on cryptographic
keys, usually a short string of text, for encoding and decoding messages in
combination with cryptographic algorithms. Based on the type of keys used,
cryptography is classified as either symmetric or asymmetric key cryptography.
Both symmetric and asymmetric key cryptography provide data confidentiality.
Asymmetric key encryption is sometimes called public key encryption. Digital
signatures, one of the by-products of public key cryptography, enable the
verification of authenticity, integrity, and non-repudiation. Network encryption
ensures that data sent across a network from one host to another is secure. If a
sniffer intercepts the data, it is unusable because the data is encrypted. Therefore,
a hacker cannot view any usernames or passwords, and any information sent
across the network, such as confidential data, is safe. To display the problems
associated with unencrypted data transmission, one captures unencrypted
network traffic and analyses it for security vulnerabilities.
CHAPTER -1

DEFINITION

Cryptography is the science of using mathematics to encrypt and decrypt data.

(Phil Zimmermann)

Cryptography is the art and science of keeping message secure.

(Bruce Schneier)

The art and science of concealing the messages to introduce secrecy in


information security is recognized as cryptography.
TERMINOLOGIES
A message is Plaintext (sometimes called cleartext). The process of disguising a
message in such a way as to hide its substance is encryption. An encrypted
message is ciphertext. The process of turning ciphertext back into plaintext is
decryption.

A cipher (or cypher) is an algorithm for performing encryption or decryption- a


series of well- defined steps that can be followed as a procedure.

TERMINOLOGY
A Cryptosystem is an implementation of cryptographic techniques and their
accompanying infrastructure to provide information security services. A
cryptosystem is also referred to as a cipher system. The various components of a
basic cryptosystem are as follows

• Plaintext
• Encryption Algorithm
• Ciphertext
• Decryptions Algorithm
• Encryption Key
• Decryption Key
While cryptography is the science of securing data, cryptanalysis is the science
of analyzing and breaking secure communication. Classical cryptanalysis
involves an interesting combination of analytical reasoning, application of
mathematical tools, pattern finding, patience, determination, and luck.
Cryptanalysis are also called attackers.
Cryptology embraces both cryptography and cryptanalysis.

HISTORY OF CRYPTOGRAHY
As civilizations evolved, human beings got organized in tribes, groups, and
kingdoms. This led to the emergence of ideas such as power, battles, supremacy,
and politics. These ideas further fueled the natural need of people to communicate
secretly with selective recipient which in turn ensured the continuous evolution
of cryptography as well.
The root of cryptography is found in Roman and Egyptian civilizations.
HIEROGLYPH
The first known evidence of cryptography can be traced to the use of ‘hieroglyph’.
Some 4000 years ago, the Egyptians use to communicate by messages written in
hieroglyph.

CAESAR SHIFT CIPHER


Caesar Shift Cipher, relies on shifting the letter of a message by an agreed number
(three was a common choice), the recipient of this message would then shift the
letters back by the same number and obtain the original message.
The Caesar Cipher is named after Julius Caesar, who used it with a shift of three
to protect message of military significance.
PLAINTEXT: internet society ghana chapter
CYPHERTEXT: lqwhuqhw vrflhwb fkdswhu
KAMASUTRA CIPHER
The Kamasutra cipher is one of the earliest known substitution methods.
It is described in the Kamasutra are 400BC.
The purpose was to teach women how to hide secret messages from prying eyes.
The techniques involve randomly pairing letters of the alphabets and then
substituting each letter in the original message with its partner.

The key is the permutation of the alphabet.


INTERNET SOCIETY GHANA CHAPTER
DWRCTWCR FKEDCRL VZJWJ EZJXRCT
GOAL AND SERVICES
GOAL: The primary goal of cryptography is to secure important data on the hard
disk or as it passes through a medium that may not be secure itself. Usually, that
medium is a computer network.

Services: cryptography can provide the following services

• Confidentially (secrecy)
• Integrity (anti-tampering)
• Authentication
• Non-repudiation
Confidentially:

• Ensuring that no one can read the message except the intended receiver
• Data is kept secret from those without the proper credential, even if
that data travels through an insure medium
Integrity(anti-tampering)

• Assuring the receiver that the received message has not been altered
in any way from the original.
Authentication

• Cryptography can help establish identity for authentication purposes.


The process of proving one’s identity. (the primary form of host to host
authentication on the internet today are name-based or address based, both
of which are notoriously weak).
Non-repudiation
A mechanism to prove that the sender really sent this message.
CHAPTER-2

Types of cryptography

• Symmetric key cryptography


• Asymmetric key cryptography
• Hash Functions
Symmetric key cryptography
Also known as secret key cryptography or conventional cryptography, symmetric
key. cryptography is an encryption system in which the sender and receiver of a
message share a single, common key that is used to encrypt and decrypt the
message.
The algorithm use is also known as a secret key algorithm or sometimes called a
symmetric algorithm.
A key is a piece of information (a parameter) that determines the functional
output cryptography algorithm or cipher.
The key for encrypting and decrypting the file had to known to all the recipients.
Else, the message could not be decrypted by conventional means.
Data Encryption Standard (DES)
The data Encryption Standard was published in 1977 by the U.S. National Bureau
of standards.
DES uses a 56bits key and maps a 64bit input block of plaintext onto a 64bit
output block of ciphertext.56 bits is a rather small key for today’s computing
power.
Triple DES
Triple DES was the answer to many of the shortcomings of DES. Since it based
on the DES algorithm, it is very easy to modify existing software to use triple
DES. It also has the advantage of proven reliability and a longer key length that
eliminates many of the shortcut attacks that can be used to reduce the amount of
time it takes to break DES.
Advanced Encryption Standard (AES)
Advanced encryption standard (AES)is an encryption standard adopted by the
U.S. government. The standard comprises three block ciphers, AES-128, AES-
192, AES-256, adopted from a larger collection originally published as Rijndael.

Each AES cipher has a 128-bit block size, with key sizes of 128, 192 and 256bits
respectively. The AES ciphers have been analyzed extensively and are now use
worldwide, as was the case with its predecessor, the Data Encryption Standard
(DES).

Kerckhoffs’s Principle for Cryptosystem

In the 19th century, a Dutch cryptographer A. Kerckhoff furnished the


requirements of a good cryptosystem. Kerckhoffs stated that a cryptographic
system should be secure even if everything about the system, except the key, is
public knowledge. The six design principles defined by Kerckhoffs for
cryptosystem are −
• The cryptosystem should be unbreakable practically, if not
mathematically.
• Falling of the cryptosystem in the hands of an intruder should not lead to
any compromise of the system, preventing any inconvenience to the user.
• The key should be easily communicable, memorable, and changeable.
• The ciphertext should be transmissible by telegraph, an unsecure channel.
• The encryption apparatus and documents should be portable and operable
by a single person.
• Finally, it is necessary that the system be easy to use, requiring neither
mental strain nor the knowledge of a long series of rules to observe.
The second rule is currently known as Kerckhoffs principle. It is applied in
virtually all the contemporary encryption algorithms such as DES, AES, etc.
These public algorithms are considered to be thoroughly secure. The security of
the encrypted message depends solely on the security of the secret encryption
key.
Keeping the algorithms secret may act as a significant barrier to cryptanalysis.
However, keeping the algorithms secret is possible only when they are used in a
strictly limited circle.
In modern era, cryptography needs to cater to users who are connected to the
Internet. In such cases, using a secret algorithm is not feasible, hence Kerckhoff
principles became essential guidelines for designing algorithms in modern
cryptography.

IDEA:- The International Data Encryption Algorithm was developed in 1991. It


uses a 128bit key to encrypt a 64bit block of plaintext into a 64bit block of
ciphertext.
Idea’s general structure is very similar to DES, it performs 17 rounds, each round
taking 64bit of input to produce a 64bit output, using per-round keys generated
from the 128bit key.

Symmetric key cryptography-examples

LUCIFER _ MADRYGA
FEAL _ REDOC
LOKI _ GOST
CAST _ BLOWFISH
SAFER _ CRAB
RCS _

Key management
Symmetric key management system are simpler and faster; their main drawback
is that the two parties must somehow exchange the key in a secure way and kept
after that.
Key management caused nightmare for the parties using the symmetric key
cryptography. They were worried about how to get the keys safely and securely
across to all users so that the decryption of the message would be possible. This
gave the chance for third party to intercept the key in transit to decode to top-
secret message. Thus, if the key was compromised the entire coding system was
compromised and a “secret” would no longer remain a “secret”.
This is why “public key cryptography” came into existence.

Asymmetric key cryptography


Asymmetric key cryptography, also know as public key cryptography, refers to a
cryptographic algorithm which requires two separate keys, one which is private
and the other is public. The public key used to encrypt the message and the private
is used to decrypt the message.

Asymmetric key cryptography-example


Digital signature standard (DSS)
Digital signature standard (DSS) is the digital signature algorithm (DSA)
developed in U.S. National Security Agency (NSA) to generate a digital signature
for the authentication of electronic documents. DSS was put forth by the national
institute of standard and technology (NIST) IN 1994, and has become the united
states government standard for authentication of electronic documents. DSS is
specified I federal information processing standard (FIPS) 186.

Algorithm-RSA
RSA (Rivest, shamir and Adleman who first publicly described in 1977) is an
algorithm for public-key [Link] is first algorithm known to be suitable for
signing as well as encryption, and one of the first great advance in public key
cryptography.
RSA is widely used in electronic commerce protocols, and is believed to be secure
given sufficiently long key and the use of up-to-date implementations.
RSA Cryptanalysis
Rivest, shamir and adleman placed a challenge in martin gardner’s column in
scientific American(journal)in which the readers where invited to crack.
C=114,381,625,757,888,867,669,235,779,976,146,612,010,218,296,721,242,36
2,562,561,842,935,706,935,245,733,897,830,597,125,563,958,705,058,989,075
,147,599,290,026,879,543,541
This was solved in April 26, 1994, cracked by an international effort via the
internet with the use of 1600 workstations, mainframes, and supercomputers
attacked the number for eight months before finding its public key and its private
key.
Encryption key = 9007
The message “first solver wins one hundred dollars”.
Of course, the RSA algorithm is safe, as it would we incredibility difficult
together up such international participation to commit malicious acts.
ElGamal

• ElGamal is a public key method that is used in both encryption and


digital signing.
• The encryption algorithm is similar in nature of Diffie-Hellman key
agreement protocol
• It is used in many applications and uses discrete logarithms.
• ElGamal encryption is used in the free GNU Privacy Guard software

Generation of ElGamal Key Pair


Each user of ElGamal cryptosystem generates the key pair through as follows −
• Choosing a large prime p. Generally a prime number of 1024 to 2048
bits length is chosen.
• Choosing a generator element g.
o This number must be between 1 and p − 1, but cannot be any
number.
o It is a generator of the multiplicative group of integers modulo p.
This means for every integer m co-prime to p, there is an integer k
such that gk=a mod n.
For example, 3 is generator of group 5 (Z5 = {1, 2, 3, 4}).

N 3n 3n mod 5

1 3 3

2 9 4

3 27 2

4 81 1

• Choosing the private key. The private key x is any number bigger than 1
and smaller than p−1.
• Computing part of the public key. The value y is computed from the
parameters p, g and the private key x as follows −
y = gx mod p
• Obtaining Public key. The ElGamal public key consists of the three
parameters (p, g, y).
For example, suppose that p = 17 and that g = 6 (It can be confirmed that
6 is a generator of group Z17). The private key x can be any number bigger
than 1 and smaller than 71, so we choose x = 5. The value y is then
computed as follows −
y = 65 mod 17 = 7
• Thus the private key is 62 and the public key is (17, 6, 7).
Encryption and Decryption
The generation of an ElGamal key pair is comparatively simpler than the
equivalent process for RSA. But the encryption and decryption are slightly more
complex than RSA.
ElGamal Encryption
Suppose sender wishes to send a plaintext to someone whose ElGamal public
key is (p, g, y), then −
• Sender represents the plaintext as a series of numbers modulo p.
• To encrypt the first plaintext P, which is represented as a number modulo
p. The encryption process to obtain the ciphertext C is as follows −
o Randomly generate a number k;
o Compute two values C1 and C2, where −
k
C1 = g mod p
C2 = (P*yk) mod p
• Send the ciphertext C, consisting of the two separate values (C1, C2), sent
together.
• Referring to our ElGamal key generation example given above, the
plaintext P = 13 is encrypted as follows −
o Randomly generate a number, say k = 10
o Compute the two values C1 and C2, where −
10
C1 = 6 mod 17
C2 = (13*710) mod 17 = 9
• Send the ciphertext C = (C1, C2) = (15, 9).
ElGamal Decryption
• To decrypt the ciphertext (C1, C2) using private key x, the following two
steps are taken −
o Compute the modular inverse of (C1)x modulo p, which is (C1)-x ,
generally referred to as decryption factor.
o Obtain the plaintext by using the following formula −
C2 × (C1)-x mod p = Plaintext
• In our example, to decrypt the ciphertext C = (C1, C2) = (15, 9) using
private key x = 5, the decryption factor is
15-5 mod 17 = 9
• Extract plaintext P = (9 × 9) mod 17 = 13.
ElGamal Analysis
In ElGamal system, each user has a private key x. and has three components of
public key − prime modulus p, generator g, and public Y = gx mod p. The
strength of the ElGamal is based on the difficulty of discrete logarithm problem.
The secure key size is generally > 1024 bits. Today even 2048 bits long key are
used. On the processing speed front, Elgamal is quite slow, it is used mainly for
key authentication protocols. Due to higher processing efficiency, Elliptic Curve
variants of ElGamal are becoming increasingly popular.

Elliptic Curve Cryptography (ECC)

Elliptic Curve Cryptography (ECC) is a term used to describe a suite of


cryptographic tools and protocols whose security is based on special versions of
the discrete logarithm problem. It does not use numbers modulo p.
ECC is based on sets of numbers that are associated with mathematical objects
called elliptic curves. There are rules for adding and computing multiples of
these numbers, just as there are for numbers modulo p.
ECC includes a variants of many cryptographic schemes that were initially
designed for modular numbers such as ElGamal encryption and Digital
Signature Algorithm.
It is believed that the discrete logarithm problem is much harder when applied
to points on an elliptic curve. This prompts switching from numbers modulo p
to points on an elliptic curve. Also an equivalent security level can be obtained
with shorter keys if we use elliptic curve-based variants.
The shorter keys result in two benefits −

• Ease of key management


• Efficient computation
These benefits make elliptic-curve-based variants of encryption scheme highly
attractive for application where computing resources are constrained.

RSA and ElGamal Schemes – A Comparison

Let us briefly compare the RSA and ElGamal schemes on the various aspects.
RSA ElGamal

It is more efficient for encryption. It is more efficient for decryption.

It is less efficient for decryption. It is more efficient for decryption.

For a particular security level, lengthy For the same level of security, very
keys are required in RSA. short keys are required.

It is widely accepted and used. It is new and not very popular in


market.

HASH FUNCTIONS
What is a Hash function?
A cryptographic hash function is a hash function that takes an arbitrary block of
data and returns a fixed-size to string, the cryptographic hash value, such that any
(accidental or intentional) change to the data will (with very high probability)
change the hash value. The data to be encode are often called the message, and
the hash value is sometime called the message digest or simply digest.
The ideal cryptography hash function has four main properties;

• It is easy to compute the hash value for any given message


• It is infeasible to generate a message that has a given hash
• It is infeasible to modify a message without changing the hash
• It is infeasible to find two different messages with the same hash.
HASH FUNCTION-EXAMPLES

Snefru Ralph Merkle


N-Hash Nippon T.T.
Message Digest MD2 (RFC1115) [Link]
MD4 (RFC1320) Ron Rivest
MD5 (RFC1321) Ron Rivest
MD6
SHA1
SHA2
COLLUSION DISCOVERY
In march 2005 Xiaoyun Wang and Hongbo Yu of Shandong university in China
created a pair of files that share the same MD5 checksum hence prove that there
is a collusion when using MD5
SHA
The secure Hash Algorithm (SHA) hash functions are a set of cryptography hash
function designed by the national security agency (NSA) and published by the
NIST as a U.S federal information processing standard.

• SHA stands for secure hash algorithm.


• Because of the successful attacks on MD5, SHA-0 and theoretical
attacks on SHA-1, NIST perceived a need for an alternative dissimilar
cryptographic hash, which became SHA-3.
• In October 2012, the national institute of standards technology (NIST)
choose the KECCAK algorithm as the new SHA-3 standard.
Example
An example of generating RSA Key pair is given below. (For ease of
understanding, the primes p & q taken here are small values. Practically, these
values are very high).
• Let two primes be p = 7 and q = 13. Thus, modulus n = pq = 7 x 13 = 91.
• Select e = 5, which is a valid choice since there is no number that is
common factor of 5 and (p − 1)(q − 1) = 6 × 12 = 72, except for 1.
• The pair of numbers (n, e) = (91, 5) forms the public key and can be made
available to anyone whom we wish to be able to send us encrypted
messages.
• Input p = 7, q = 13, and e = 5 to the Extended Euclidean Algorithm. The
output will be d = 29.
• Check that the d calculated is correct by computing −
de = 29 × 5 = 145 = 1 mod 72
• Hence, public key is (91, 5) and private keys is (91, 29).
Encryption and Decryption
Once the key pair has been generated, the process of encryption and decryption
are relatively straightforward and computationally easy.
Interestingly, RSA does not directly operate on strings of bits as in case of
symmetric key encryption. It operates on numbers modulo n. Hence, it is
necessary to represent the plaintext as a series of numbers less than n.

PGP Encryption
Pretty Good Privacy (PGP) is an encryption system used for both sending
encrypted emails and encrypting sensitive files. Since its invention back in 1991,
PGP has become the de facto standard for email security.

How Does PGP Encryption Work?

PGP shares some features with other encryption systems you may have heard of,
like Kerberos encryption (which is used to authenticate network users) and SSL
encryption (which is used to secure websites).

At a basic level, PGP encryption uses a combination of two forms of encryption:


symmetric key encryption, and public-key encryption

The mathematics behind encryption can get pretty complex (though you can take
a look at the math if you like), so here we’ll stick to the basic concepts. At the
highest level, this is how PGP encryption works:

First, PGP generates a random session key using one of two (main) algorithms.
This key is a huge number that cannot be guessed, and is only used once.

Next, this session key is encrypted. This is done using the public key of the
intended recipient of the message. The public key is tied to a particular person’s
identity, and anyone can use it to send them a message.
The sender sends their encrypted PGP session key to the recipient, and they are
able to decrypt it using their private key. Using this session key, the recipient is
now able to decrypt the actual message.

Key Management

It goes without saying that the security of any cryptosystem depends upon how
securely its keys are managed. Without secure procedures for the handling of
cryptographic keys, the benefits of the use of strong cryptographic schemes are
potentially lost.
It is observed that cryptographic schemes are rarely compromised through
weaknesses in their design. However, they are often compromised through poor
key management.
There are some important aspects of key management which are as follows −
• Cryptographic keys are nothing but special pieces of data. Key
management refers to the secure administration of cryptographic keys.
• Key management deals with entire key lifecycle as depicted in the
following illustration −
• There are two specific requirements of key management for public key
cryptography.
o Secrecy of private keys. Throughout the key lifecycle, secret keys
must remain secret from all parties except those who are owner and
are authorized to use them.
o Assurance of public keys. In public key cryptography, the public
keys are in open domain and seen as public pieces of data. By
default there are no assurances of whether a public key is correct,
with whom it can be associated, or what it can be used for. Thus
key management of public keys needs to focus much more
explicitly on assurance of purpose of public keys.
The most crucial requirement of ‘assurance of public key’ can be achieved
through the public-key infrastructure (PKI), a key management system for
supporting public-key cryptography.

PUBLIC KEY INFRASTRUCTURE (PKI)

PKI provides assurance of public key. It provides the identification of public


keys and their distribution. An anatomy of PKI comprises of the following
components.

• Public Key Certificate, commonly referred to as ‘digital certificate’.


• Private Key tokens.
• Certification Authority.
• Registration Authority.
• Certificate Management System.

DIGITAL CERTIFICATE

For analogy, a certificate can be considered as the ID card issued to the person.
People use ID cards such as a driver's license, passport to prove their identity. A
digital certificate does the same basic thing in the electronic world, but with one
difference.
Digital Certificates are not only issued to people but they can be issued to
computers, software packages or anything else that need to prove the identity in
the electronic world.
• Digital certificates are based on the ITU standard X.509 which defines a
standard certificate format for public key certificates and certification
validation. Hence digital certificates are sometimes also referred to as
X.509 certificates.
Public key pertaining to the user client is stored in digital certificates by
The Certification Authority (CA) along with other relevant information
such as client information, expiration date, usage, issuer etc.
• CA digitally signs this entire information and includes digital signature in
the certificate.
• Anyone who needs the assurance about the public key and associated
information of client, he carries out the signature validation process using
CA’s public key. Successful validation assures that the public key given
in the certificate belongs to the person whose details are given in the
certificate.
The process of obtaining Digital Certificate by a person/entity is depicted in the
following illustration.
As shown in the illustration, the CA accepts the application from a client to
certify his public key. The CA, after duly verifying identity of client, issues a
digital certificate to that client.

Certifying Authority (CA)

As discussed above, the CA issues certificate to a client and assist other users to verify
the certificate. The CA takes responsibility for identifying correctly the identity of the
client asking for a certificate to be issued, and ensures that the information contained
within the certificate is correct and digitally signs it.
KEY FUNCTIONS OF CA

The key functions of a CA are as follows −


Generating key pairs − The CA may generate a key pair independently or jointly with the
client.

ISSUING DIGITAL CERTIFICATES − The CA could be thought of as the PKI


equivalent of a passport agency − the CA issues a certificate after client provides the
credentials to confirm his identity. The CA then signs the certificate to prevent
modification of the details contained in the certificate.

PUBLISHING CERTIFICATES − The CA need to publish certificates so that users can


find them. There are two ways of achieving this. One is to publish certificates in the
equivalent of an electronic telephone directory. The other is to send your certificate out to
those people you think might need it by one means or another.

VERIFYING CERTIFICATES − The CA makes its public key available in environment


to assist verification of his signature on clients’ digital certificate.

REVOCATION OF CERTIFICATES − At times, CA revokes the certificate issued due


to some reason such as compromise of private key by user or loss of trust in the client.
After revocation, CA maintains the list of all revoked certificate that is available to the
environment.
Classes of Certificates

THERE ARE FOUR TYPICAL CLASSES OF CERTIFICATE:−

CLASS 1 − These certificates can be easily acquired by supplying an email address.

CLASS 2 − These certificates require additional personal information to be supplied.

CLASS 3 − These certificates can only be purchased after checks have been made about
the requestor’s identity.
CLASS 4 − They may be used by governments and financial organizations needing very
high levels of trust.

REGISTRATION AUTHORITY (RA)

CA may use a third-party Registration Authority (RA) to perform the necessary checks
on the person or company requesting the certificate to confirm their identity. The RA may
appear to the client as a CA, but they do not actually sign the certificate that is issued.

Certificate Management System (CMS)

It is the management system through which certificates are published, temporarily or


permanently suspended, renewed, or revoked. Certificate management systems do not
normally delete certificates because it may be necessary to prove their status at a point in
time, perhaps for legal reasons. A CA along with associated RA runs certificate
management systems to be able to track their responsibilities and liabilities.

PRIVATE KEY TOKENS

While the public key of a client is stored on the certificate, the associated secret private
key can be stored on the key owner’s computer. This method is generally not adopted. If
an attacker gains access to the computer, he can easily gain access to private key. For this
reason, a private key is stored on secure removable storage token access to which is
protected through a password.
Different vendors often use different and sometimes proprietary storage formats for
storing keys. For example ,Entrust uses the proprietary .EPF format, while Verisign,
Global Sign, and Baltimore use the standard. P12 format.

HIERARCHY OF CA

With vast networks and requirements of global communications, it is practically not


feasible to have only one trusted CA from whom all users obtain their certificates.
Secondly, availability of only one CA may lead to difficulties if CA is compromised.
In such case, the hierarchical certification model is of interest since it allows public key
certificates to be used in environments where two communicating parties do not have
trust relationships with the same CA.
The root CA is at the top of the CA hierarchy and the root CA's certificate is a self-signed
certificate.
The CAs, which are directly subordinate to the root CA (For example, CA1 and CA2)
have CA certificates that are signed by the root CA.
The CAs under the subordinate CAs in the hierarchy (For example, CA5 and CA6) have
their CA certificates signed by the higher-level subordinate CAs.
Certificate authority (CA) hierarchies are reflected in certificate chains. A certificate chain
traces a path of certificates from a branch in the hierarchy to the root of the hierarchy.

The following illustration shows a CA hierarchy with a certificate chain leading from an
entity certificate through two subordinate CA certificates (CA6 and CA3) to the CA
certificate for the root CA.
Verifying a certificate chain is the process of ensuring that a specific certificate chain is
valid, correctly signed, and trustworthy. The following procedure verifies a certificate
chain, beginning with the certificate that is presented for authentication −
A client whose authenticity is being verified supplies his certificate, generally along with
the chain of certificates up to Root CA.
Verifier takes the certificate and validates by using public key of issuer. The issuer’s
public key is found in the issuer’s certificate which is in the chain next to client’s
certificate.
Now if the higher CA who has signed the issuer’s certificate, is trusted by the verifier,
verification is successful and stops here.
Else, the issuer's certificate is verified in a similar manner as done for client in above steps.
This process continues till either trusted CA is found in between or else it continues till
Root CA.
Nowadays, the networks have gone global and information has taken the digital form of
bits and bytes. Critical information now gets stored, processed and transmitted in digital
form on computer systems and open communication channels.

Since information plays such a vital role, adversaries are targeting the computer systems
and open communication channels to either steal the sensitive information or to disrupt
the critical information system.

Modern cryptography provides a robust set of techniques to ensure that the malevolent
intentions of the adversary are thwarted while ensuring the legitimate users get access to
information. Here in this chapter, we will discuss the benefits that we draw from
cryptography, its limitations, as well as the future of cryptography.

CRYPTOGRAPHY – BENEFITS

Cryptography is an essential information security tool. It provides the four most basic
services of information security −
Confidentiality − Encryption technique can guard the information and communication
from unauthorized revelation and access of information.

DATA INTEGRITY –

The cryptographic hash functions are playing vital role in assuring the users about the
data integrity.

CRYPTOGRAPHY – DRAWBACKS

Apart from the four fundamental elements of information security, there are other issues
that affect the effective use of information.
A strongly encrypted, authentic, and digitally signed information can be difficult to access
even for a legitimate user at a crucial time of decision-making. The network or the
computer system can be attacked and rendered non-functional by an intruder.

High availability, one of the fundamental aspects of information security, cannot be


ensured through the use of cryptography. Other methods are needed to guard against the
threats such as denial of service or complete breakdown of information system.
Another fundamental need of information security of selective access control also cannot
be realized through the use of cryptography. Administrative controls and procedures are
required to be exercised for the same.

Cryptography does not guard against the vulnerabilities and threats that emerge from the
poor design of systems, protocols, and procedures. These need to be fixed through proper
design and setting up of a defensive infrastructure.

Cryptography comes at cost. The cost is in terms of time and money −


Addition of cryptographic techniques in the information processing leads to delay.
The use of public key cryptography requires setting up and maintenance of public key
infrastructure requiring the handsome financial budget.
The security of cryptographic technique is based on the computational difficulty of
mathematical problems. Any breakthrough in solving such mathematical problems or
increasing the computing power can render a cryptographic technique vulnerable.

Future of Cryptography

Elliptic Curve Cryptography (ECC) has already been invented but its
advantages and disadvantages are not yet fully understood. ECC allows to
perform encryption and decryption in a drastically lesser time, thus allowing a
higher amount of data to be passed with equal security. However, as other
methods of encryption, ECC must also be tested and proven secure before it is
accepted for governmental, commercial, and private use.

Quantum computation is the new phenomenon. While modern computers store


data using a binary format called a "bit" in which a "1" or a "0" can be stored; a
quantum computer stores data using a quantum superposition of multiple states.
These multiple valued states are stored in "quantum bits" or "qubits". This allows
the computation of numbers to be several orders of magnitude faster than
traditional transistor processors.

To comprehend the power of quantum computer, consider RSA-640, a number


with 193 digits, which can be factored by eighty 2.2GHz computers over the span
of 5 months, one quantum computer would factor in less than 17 seconds.
Numbers that would typically take billions of years to compute could only take a
matter of hours or even minutes with a fully developed quantum computer.
In view of these facts, modern cryptography will have to look for
computationally harder problems or devise completely new techniques of
archiving the goals presently served by modern cryptography.

CONCLUSION

The purpose of this section is to present how cryptography can be used to


implement security in the Web. It starts with a list of challenges for protecting
information, continues with the presentation of the basic cryptographic
algorithms and protocols, presents the Secure Sockets Layer protocol, and
concludes with an example of how cryptography is used in a commercial
transaction on the Internet.

From a technical point of view, cryptography is the solution to many of the


security challenges that are present in the Internet. The technology exists to solve
most of the problems. However, there are several issues that have obstructed the
widespread use of cryptography in the Internet. First of all, cryptography, as a
science, faces a difficult problem. Most of the algorithms cannot be proven
secure. For this reason, there is suspicion around many of the cryptographic
algorithms. Another aspect is related to the intellectual property associated with
the algorithms. Most algorithms are patented, and only some companies have
licensed them for use.

Finally, cryptography can be used to harm society. Governments are concerned


that encryption will make law enforcement and national security goals more
difficult to achieve. For example, terrorists could communicate information over
the Internet using encryption that law enforcement agencies could not decrypt.
Therefore some governments, such as the U.S., have regulated the export of
software containing encryption algorithms. This is a topic of debate, pitting
governments against the right to free speech. For example, U.S. export
regulations can prevent the publication of cryptographic research. In one court
case, in March 1996, Phil Karn filed suite over whether he could export some
source code from [SCHN96]. A District Court ruled that "export controls on
encryption software are constitutional under the First Amendment" to the U.S.
Constitution [DOJ97].

However, the following year a different District Court made an opposite ruling
in a different case. Daniel Bernstein, while a Ph.D. candidate at the University
of California, was told by the U.S. government that he had to register as an arms
dealer under the International Traffic in Arms Regulation in order to publish a
cryptographic program. Bernstein sued. In August 1997 the Federal District
Court in San Francisco ruled that export restrictions on encryption are "an
unconstitutional prior restraint in violation of the First Amendment" [EFFa,
EFFb]. According to the Justice department, the larger issue of exporting
cryptographic algorithms remains unresolved.

The current trend in society indicates that cryptography is gaining importance.


One day cryptography may be widely used throughout the Internet: for electronic
mail, for sending documents that are sold over the Web, and even perhaps for all
network communication between routers or switches in the Internet. The use and
debate on cryptography promises to be prominent for many more years.
-
THANK YOU.
Bibilography

1. Next Generation SSH2 Implementation. Dale Liu, Max Caceres, Tim


Robichaux, Dario V Forte, Eric S. Seagren, Devin L. Ganger, Brad Smith,
Wipul Jayawickrama, Christopher Stokes, Jan Kanclirz, Jr.
2. An Overview of Cryptography. Gary C. Kessler

You might also like