Unit1 Notes
Unit1 Notes
Security trends – Legal, Ethical and Professional Aspects of Security, Need for
Security at Multiple levels, Security Policies – Model of network security –
Security attacks, services mechanisms–OSIsecurityarchitecture–
Classicalencryptiontechniques:substitutiontechniques, transposition techniques,
steganography- Foundations of modern cryptography: perfect security –
information theory – product cryptosystem –cryptanalysis.
Definition
Cryptography is the science of using mathematics to encrypt and decrypt data.
Phil Zimmermann
Cryptography is the art and science of keeping messages secure.
Bruce Schneier
The art and science of concealing the messages to introduce secrecy in
information Security is recognized as cryptography.
It isthestudyandpracticeoftechniquesforsecure
communicationinthepresenceofthirdparties called adversaries. Data
Confidentiality, Data Integrity, Authentication and Non-repudiation are core
principles of modern-daycryptography.
Terminologies
Amessageisplaintext(sometimescalledcleartext).Theprocessofdisguisingamessagei
nsuch a way as to hide its substance is encryption. An encrypted message is
cipher text. The processof turning cipher text back into plaintext isdecryption.
[Link] Trends
Confidentiality
Dataconfidentiality
Assures that private or confidential information is not made available or disclosed to
unauthorized
Privacy
Assures that individuals control or influence what information related to them may
be collected and stored and by whom and to whom that information may be
disclosed.
Integrity
Dataintegrity
Assures that information and programs are changed only in a specified and authorized
manner.
Systemintegrity
Assuresthatasystemperformsitsintendedfunctioninanunimpairedmanner,freefromdel
iberate or inadvertent unauthorized manipulation of thesystem.
Availability
Assures that systems work promptly and service is not denied to authorizeusers.
CIA Triad
Confidentiality
Trade-Marks: A trademark is a word, name, symbol or expression which used to identify the
products or services in trade uniquely from others. Trade mark rights used to prevent others
from using a confusingly similar mark, but not to prevent others from making the same goods
or from selling the same goods or services under a clearly different mark.
• Intellectual Property Relevant to Network and Computer Security A number of forms of
intellectual property are relevant in the context of network and computer security.
• Software programs: software programs are protected by using copyright, perhaps patent.
• Digital content: audio / video / media / web protected by copy right Algorithms: algorithms
may be able to protect by patenting
• Privacy Law and Regulation: An issue with considerable overlap with computer security is
that of privacy. Concerns about the extent to which personal privacy has been and may be
compromised have led to a variety of legal and technical approaches to reinforcing privacy
rights. A number of international organizations and national governments have introduced laws
and regulations intended to protect individual privacy.
• European Union Data Protection Directive was adopted in 1998 to ensure member states
protect fundamental privacy rights when processing personal info and prevent member states
from restricting the free flow of personal info within EU organized around principles of notice,
consent, consistency, access, security, onward transfer and enforcement. US Privacy Law have
Privacy Act of 1974 which permits individuals to determine records kept, forbid records being
used for other purposes, obtain access to records, ensures agencies properly collect, maintain,
and use personal info and creates a private right of action for individuals. Cryptography and
Ethics
There are many potential misuses and abuses of information and electronic
communication that create privacy and security problems. Ethics refers to a system of moral
principles that relates to the benefits and harms of particular actions. An ethic an objectively
defined standard of right and wrong. Ethical standards are often idealistic principles because
they focus on one objective. Even though religious group and professional organization
promote certain standards of ethical behaviour, ultimately each person is responsible for
deciding what do in a specific situation.
ETHICAL ISSUES
The foundations of all secure systems are the moral principles and practices and the
professional standards of all employees of the organization, i.e., while people are part of the
solution, they are also most of the problem. The following issues are examples of security
problems that an organization may have to deal with:
A. Ethics and Responsible Decision-Making
The foundation of all security systems is formed by the moral principles and practices of those
people involved and the standards of the profession. That is, while people are part of the
solution, they are also most the problem. Security problems with which an organization may
have to deal include: responsible decision-making, confidentiality, privacy, piracy, fraud &
misuse, liability, copyright, trade secrets, and sabotage. It is easy to sensationalize these topics
with real horror stories; it is more difficult to deal with the underlying ethical issues involved.
The student should be made aware of his individual responsibility in making ethical decisions
associated with information security.
B. Confidentiality & Privacy
Computers can be used symbolically to intimidate, deceive or defraud victims. Attorneys,
government agencies, and businesses increasingly use mounds of computer generated data
quite legally to confound their audiences. Criminals also find useful phony invoices, bills, and
checks generated by the computer. The computer lends an ideal cloak for carrying out criminal
acts by imparting a clean quality to the crime.
The computer has made the invasion of our privacy a great deal easier and potentially more
dangerous than before the advent of the computer. A wide range of data is collected and stored
in computerized files related to individuals. These files hold banking information, credit
information, organizational fundraising, opinion polls, shop at home services, driver license
data, arrest records, and medical records. The potential threats to privacy include the improper
commercial use of computerized data, breaches of confidentiality by releasing confidential data
to third parties, and the release of records to governmental agencies for investigative purposes.
The basic law that protects our privacy is the Fourth Amendment to the United States
Constitution, which mandates that people have a right to be secure in homes and against
unreasonable search and seizure. In addition, many laws have been enacted to protect the
individual from having damaging information stored in computerized databases.
C. Privacy
Microcomputer software presents a particular problem since many individuals are involved in
the use of this software. Section 117 of the copyright laws, specifically the 1980 amendment,
deals with a law that addresses the problem of backup copies of software. This section states
that users have the right to create backup copies of their software. That is, users may legally
create a backup copy of software if it is to be held in an archive. Many software companies
provide a free backup copy to users that preclude the need for to users purchase software
intended to defeat copy protection systems and subsequently create copies of their software. If
the software purchased is actually leased, you may in fact not even be able to make backup
copies of the software. The distinction between leasing and buying is contained within the
software documentation. The copyright statement is also contained in the software
documentation. The copyright laws regarding leased material state that the leasor may say what
the leaseholder can and cannot do with the software. So it is entirely up to the owner of the
software as to whether or not users may make backup copies of the software. At a time when
federal laws relating to copyright protection are evolving, several states are considering
legislation that would bar unauthorized duplication of software.
The software industry is prepared to do battle against software piracy. The courts are dealing
with an increasing number of lawsuits concerning the protection of software. Large software
publishers have established the Software Protection Fund to raise between $500,000 and $1
million to promote anti-piracy sentiment and to develop additional protection devices.
D. Fraud & Misuse
The computer can create a unique environment in which unauthorized activities can occur.
Crimes in this category have many traditional names including theft, fraud, embezzlement,
extortion, etc. Computer-related fraud includes the introduction of fraudulent records into a
computer system, theft of money by electronic means, theft of financial instruments, theft of
services, and theft of valuable data.
E. Liability
Under the UCC, an express warranty is an affirmation or promise of product quality to the
buyer and becomes a part of the basis of the bargain. Promises and affirmations made by the
software developer to the user about the nature and quality of the program can also be
classified as an express warranty. Programmers or retailers possess the right to define express
warranties. Thus, they have to be realistic when they state any claims and predictions about the
capabilities, quality, and nature of their software or hardware. They should consider the legal
aspects of their affirmative promises, their product demonstrations, and their product
description. Every word they say may be as legally effective as though stated in writing. Thus,
to protect against liability, all agreements should be in writing. A disclaimer of express
warranties can free a supplier from being held responsible for any informal, hypothetical state-
ments or predictions made during the negotiation stages.
Implied warranties are also defined in the United States by the UCC. These are warranties that
are provided automatically in every sale. These warranties need not be in writing nor do they
need to be verbally stated. They ensure that a good title will pass to the buyer, that the product
is fit for the purpose sold, and that it is fit for the ordinary purposes for which similar goods are
used (merchantability).
F. Patent and Copyright Law
A patent can protect the unique and secret aspects of an idea. It is very difficult to obtain a
patent compared to copyright (please see discussion below). With computer software, complete
disclosure is required; the patent holder must disclose the complete details of a program to
allow a skilled programmer to build the program. Moreover, a United States software patent
will be unenforceable in most other countries.
Copyright law provides a very significant legal tool for use in protecting computer software,
both before a security breach and certainly after a security breach. This type of breach could
deal with the misappropriation of data, computer programs, documentation, or similar material.
For this reason, the information security specialist will want to be familiar with basic concepts
of copyright law.
The United States, United Kingdom, Australia, and other countries have now amended or
revised their copyright legislation to provide explicit laws to protect computer programs.
Copyright law in the United States is governed by the Copyright Act of 1976 that preempted
the field from the states. Formerly, the United States had a dual state and federal system. In
other countries, such as Canada, the courts have held that the un-revised Copyright Act is
broad enough to protect computer programs. In many of these countries, the reform of
copyright law is actively underway.
G. Trade Secrets
A trade secret protects something of value and usefulness. This law protects the unique and
secret aspects of ideas, known only to the discoverer of his/her confidants. Once disclosed the
trade secret is lost as such and can only be protected under one of the following laws. The
application of trade secret law is very important in the computer field, where even a slight head
start in the development of software or hardware can provide a significant competitive ad-
vantage.
H. Sabotage
The computer can be the object of attack in computer crimes such as the unauthorized use of
computer facilities, alternation or destruction of information, data file sabotage, and vandalism
against a computer system. Computers have been shot, stabbed, short-circuited, and bombed.
Professional Issues:
Maintain confidentiality
√ Maintain anonymity
√ Respect copyright and reference your work
√ Consent – consider whether it is appropriate for you to gain informed consent before you use
the incident for reflection.
The term multi-level arises from the defense community's security classifications:
Confidential, Secret, and Top Secret.
Individuals must be granted appropriate clearances before they can see classified
information. Those with Confidential clearance are only authorized to view
Confidential documents; they are not trusted to look at Secret or Top Secret
information. The rules that apply to data flow operate from lower levels to higher
levels, and never the reverse. This is illustrated below.
InformationSecurityLevels Available data flow using MLSsystem
Under such a system, users, computers, and networks use labels to indicate
security levels. Data can flow between like levels, for example between "Secret"
and "Secret", or from a lower level to a higher level. This means that users at
level "Secret" can share data with one another, and can also retrieve information
from Confidential-level (i.e., lower-level), users.
However, data cannot flow from a higher level to a lower level. This prevents
processes at the "Secret" level from viewing information classified as "Top Secret".
It also prevents processes ata higher level from accidentally writing information to
a lower level. This is referred to as the "no read up, no write down" model.
As discussed above, subjects and objects are labeled with Security Levels
(SLs), which are composed of two types of entities:
4. Security Polices
Following are some points which help in security policy of an organization.
Structure of a SecurityPolicy
When you compile a security policy you should have in mind a basic structure in
order to make something practical. Some of the main points which have to be
taken into consideration are −
Types of Policies
2. Sender and receiver must have obtained copies of the secret key in a secure fashion and
must keep the key secure. If someone can discover the key and knows the algorithm, all
communication using this key is readable.
Model of Conventional Cryptosystem
A source produces a message in plaintext, X = [X1, X2, ..., XM]. The M elements of X are
letters in some finite alphabet. Traditionally, the alphabet usually consisted of the 26 capital
letters. Nowadays, the binary alphabet {0, 1} is typically used. For encryption, a key of the form
K = [K1, K2, ..., KJ] is generated. If the key is generated at the message source, then it must also
be provided to the destination by means of some secure channel. Alternatively, a third party
could generate the key and securely deliver it to both source and destination.
With the message X and the encryption key K as input, the encryption algorithm forms the
ciphertext Y = [Y1, Y2, ..., YN]. We can write this as
Y = E(K, X)
This notation indicates that Y is produced by using encryption algorithm E as a function of the
plaintext X, with the specific function determined by the value of the key K.
The intended receiver, in possession of the key, is able to invert the transformation:
X = D(K, Y)
An opponent, observing Y but not having access to K or X, may attempt to recover X or K or
both X and K. It is assumed that the opponent knows the encryption (E) and decryption (D)
algorithms. If the opponent is interested in only this particular message, then the focus of the
effort is to recover X by generating a plaintext estimate.
SUBSTITUTION TECHNIQUES
The two basic building blocks of all encryption techniques are substitution and transposition.
A substitution technique is one in which the letters of plaintext are replaced by other letters or
by numbers or symbols.
If the plaintext is viewed as a sequence of bits, then substitution involves replacing plaintext
bit patterns with ciphertext bit patterns.
1. Caesar Cipher:
The earliest known, and the simplest, use of a substitution cipher was by Julius Caesar.
The Caesar cipher involves replacing each letter of the alphabet with the letter standing
three places further down the alphabet.
For example, plain: meet me after the toga party cipher:
PHHW PH DIWHU WKH WRJD SDUWB
Note that the alphabet is wrapped around, so that the letter following Z is A. We can define the
transformation by listing all possibilities, as follows:
plain: a b c d e f g h i j k l m n o p q r s t u v w x y z
cipher: D E F G H I J K L M N O P Q R S T U V W X Y Z A B C
Let us assign a numerical equivalent to each letter: When letters are involved, the following
conventions are used in this book. Plaintext is always in lowercase; ciphertext is in uppercase; key
values are in italicized lowercase.
Let us assign a numerical equivalent to each letter: Then the algorithm can be expressed as
follows. For each plaintext letter,
substitute the cipher text letter: C = E(3, p) = (p + 3) mod 26
A shift may be of any amount, so that the general Caesar algorithm is
C = E(k, p) = (p + k) mod 26 where takes on a value in the range 1 to 25.
The decryption algorithm is simply p = D(k, C) = (C - k) mod 26
If it is known that a given ciphertext is a Caesar cipher, then a brute-force cryptanalysis is
easily performed: simply try all the 25 possible keys.
Three important characteristics of this problem enabled us to use a bruteforce cryptanalysis:
1. The encryption and decryption algorithms are known.
2. There are only 25 keys to try.
3. The language of the plaintext is known and easily recognizable.
2. Monoalphabetic Ciphers
With only 25 possible keys, the Caesar cipher is far from secure.A dramatic increase in the key
space can be achieved by allowing an arbitrary substitution. A permutation of a finite set of elements
is an ordered sequence of all the elements of, with each element appearing exactlyonce.
For example, if S ={a,b,c} , there are six permutations of : abc, acb, bac, bca, cab, cba
In general, there are n! permutations of a set of elements, because the first element can be
chosen in one of n ways, the second in n-1 ways, the third in n-2 ways, and so on. Recall the
assignment for the Caesar cipher:
plain: a b c d e f g h I j kl m n o p q r s t u v w x y z
cipher: D E F G H I J K L M N O P Q R S T U V W X Y Z A B C
If, instead, the “cipher” line can be any permutation of the 26 alphabetic characters, then there
are 26! or greater than 4*1026 possible keys. This is 10 orders of magnitude greater than the key
space for DES and would seem to eliminate brute-force techniques for cryptanalysis. Such an
approach is referred to as a monoalphabetic substitution cipher, because a single cipher alphabet
(mapping from plain alphabetto cipher alphabet) is used per message.
The ciphertext to be solved is
UZQSOVUOHXMOPVGPOZPEVSGZWSZOPFPESXUDBMETSXAIZ
VUEPHZHMDZSHZOWSFPAPPDTSVPQUZWYMXUZUHSX
EPYEPOPDZSZUFPOMBZWPFUPZHMDJUDTMOHMQ
As a first step, the relative frequency of the letters can be determined and compared to a
standard frequency distribution for English, such as is shown in Figure 1.9. If the message were long
enough, this technique alone might be sufficient, but because this is a relatively short message, we
cannot expect an exact match.
Relative Frequencies of Letters in English Text That cipher letters P and Z are the equivalents
of plain letters e and t, but it is not certain which is which. The letters S, U, O, M, and H are all of
relatively high frequency and probably correspond to plain letters from the set {a, h, i, n, o, r, s}. The
letters with the lowest frequencies (namely A, B, G, Y, I, J) are likely included in the set {b, j, k, q, v,
x, z}.
A powerful tool is to look at the frequency of two-letter combinations, known as digrams. The
most common such digram is th. In our ciphertext, the most common digram is ZW, which appears
three times. So we make the correspondence of Z with t and W with h. Then, by our earlier
hypothesis, we can equate P with e. Now notice that the sequence ZWP appears in the ciphertext, and
we can translate that sequence as “the.” This is the most frequent trigram (threeletter combination).
Monoalphabetic ciphers are easy to break because they reflect the frequency data of the
original alphabet. A countermeasure is to provide multiple substitutes, known as homophones, for a
single letter.
[Link] Cipher The best-known multiple-letter encryption cipher is the Playfair, which treats
digrams in the plaintext as single units and translates these units into ciphertext digrams.
The Playfair algorithm is based on the use of a 5 × 5 matrix of letters constructed using a
keyword.
M O N A R
C H Y B D
E F G I/J K
L P Q S T
U V W X Z
In this case, the keyword is monarchy. The matrix is constructed by filling in the letters of the
keyword (minus duplicates) from left to right and from top to bottom, and then filling in the remainder
of the matrix with the remaining letters in alphabetic order.
The letters I and J count as one letter. Plaintext is encrypted two letters at a time, according to
the following rules:
1. Repeating plaintext letters that are in the same pair are separated with a filler letter, such as
x, so that balloon would be treated as ba lx lo on.
2. Two plaintext letters that fall in the same row of the matrix are each replaced by the letter to
the right, with the first element of the row circularly following the last. For example, ar is encrypted as
RM.
3. Two plaintext letters that fall in the same column are each replaced by the letter beneath,
with the top element of the column circularly following the last. For example, mu is encrypted as CM.
4. Otherwise, each plaintext letter in a pair is replaced by the letter that lies in its own row and the
column occupied by the other plaintext letter. Thus, hs becomes BP and ea becomes IM (or JM, as the
encipherer wishes).
. 3. Hill Cipher:
Another interesting multiletter cipher is the Hill cipher, developed by the mathematician Lester Hill in 1929.
ThisencryptionalgorithmtakessuccessiveMplaintextlettersandsubstitutesforthemMciphertextletters. The
substitution is determined by linear equations in which each character is assigned a numerical value (a=0,
b=1, c=2, , z=25). For M=3, the system can be describedas
C = PK mod 26
whereCandParerowvectors oflength3representingtheplaintextandciphertext,and Kisa3*3matrix representing the
encryption key. Operations are performed mod26.
Example:
15 15 375 11
0 then, K 0 = 879 mod26 = 13 = LNS
24 24 486 18
Eg:Encrypt the message “meet me at the usual place at ten rather than eight oclock” using the
Hill cipher with the key ( ). Show your calculations and the [Link] the calculations for the
corresponding decryption of the ciphertext to recover the original plaintext.
Hence the plain text is “me”
[Link]
Another way to improve on the simple monoalphabetic technique is to use different monoalphabetic
substitutions as one proceeds through the plaintext message. The general name for this approach is
polyalphabetic substitution cipher.
[Link]
Encryption and Decryption
Given a key letter X and plaintext letter Y, the ciphertext letter is at the intersection of the row labeled X
and the column labled Y.
Toencryptamessage,a [Link].
Decryption is simple. The key letter again identifies the row. The position of the ciphertext letter in that
row determines the column, and the plaintext letter is the top of thecolumn.
Example:
Key : deceptive
Plain Text : we are discoveredyourself
key: deceptivedeceptivedeceptive
plaintext:wearediscoveredsaveyourself
ciphertext: ZICVTWQNGRZGVTWAVZHCQYGLMGJ
Vigenere Table
keyword can be eliminated by using a nonrepeating keyword that is as long as the message [Link]ère
proposed what is referred to as an autokey system, in which a keyword is concatenated with the plaintext
itself to provide a running key. For our example,
key: deceptivewearediscoveredsav
plaintext: wearediscoveredsaveyourself
ciphertext: ZICVTWQNGKZEIIGASXSTSLVVWLA
VernamCipher
Theultimatedefenseagainstsuchacryptanalysisistochooseakeywordthatisas longastheplaintextand has no
statistical relationship to it. Such a system was introduced by an AT&T engineer named Gilbert Vernam
in1918.
[Link]-Time Pad
improvement to the Vernam cipher that yields the ultimate insecurity
using a random key that is as long as the message, so that the key need not berepeated
the key is to be used to encrypt and decrypt a single message, and then isdiscarded.
Each new message requires a new key of the same length as the new messageExample
ciphertext:ANKYODKYUREPFJBYOJDSPLREYIUNOFDOIUERFPLUYTSkey:
pxlmvmsydofuyrvzwc tnlebnecvgdupahfzzlmnyih plaintext: mr mustard with the
candlestick in the hall
ciphertext:ANKYODKYUREPFJBYOJDSPLREYIUNOFDOIUERFPLUYTSkey:
mfugpmiydgaxgoufhklllmhsqdqogtewbqfgyovuhwt plaintext: missscarlet
with the knife in the library two fundamentaldifficulties
problem of making large quantities of randomkeys
problem of key distribution andprotection
Transposition Techniques
A very different kind of mapping is achieved by performing some sort of permutation on the
plaintext letters
Rail Fence Technique
The simplest such cipher is the rail fence technique, in which the plaintext is written down as a
sequence of diagonals and then read off as a sequence of rows.
For example, to encipher the message "meet me after the toga party" with a rail fence of depth 2,
we write the following
mematrhtgpryetefeteoaat
The encrypted message is
MEMATRHTGPRYETEFETEOAAT
Pure Transposition Cipher
Write the message in a rectangle, row by row, and read the message off, column by column, but
permute the order of the columns.
The order of the columns then becomes the key to the algorithm
Example
Key: 4 3 1 256 7
Plaintext: a t t a c k p
ostponed
untiltwo
amxyz
Ciphertext: TTNAAPTMTSUOAODWCOIXKNLYPETZ
Double Transposition
performing more than one stage of transposition Example
if the foregoing message is reencrypted using the same algorithm
Key: 4 3 1 2 5 6 7
Input: t t na apt
mt su oao
d w c o ix k
n ly pet z
Output: NSCYAUOPTTWLTMDNAOIEPAXTTOKZ
This is a much less structured permutation and is much more difficult to cryptanalyze
Steganography
We conclude with a discussion of a technique that is, strictly speaking, not encryption, namely,
steganography
A plaintext message may be hidden in one of two ways.
The methods of steganography conceal the existence ofthe message
The methods of cryptography render the message unintelligible tooutsiders
o by various transformations of the text
Various ways to conceal the message
Arrangement of words or letters within an apparently innocuous text spells out the real
message
Character marking
Selected letters of printed or typewritten text are overwritten in pencil. The marks are ordinarily
not visible unless the paper is held at an angle to bright light.
Invisible ink
A number of substances can be used for writing but leave no visible trace until heat or some
chemical is applied
Pinpunctures
Small pin punctures on selected letters are ordinarily not visible unless the paper is held up in
front of alight.
Typewriter correctionribbon
Used between lines typed with a black ribbon, the results of typing with the correction tapeare
visible only under a stronglight
Hiding a message by using the least significant bits of frames on a CD
The Kodak Photo CD format's maximum resolution is 2048 by 3072 pixels, with each
pixel containing 24 bits of RGB colorinformation.
The least significant bit of each 24-bit pixel can be changed without greatly affecting the
quality of theimage
Thus you can hide a 2.3-megabyte message in a single digitalsnapshot
Number of drawbacks
lot of overhead to hide a relatively few bits ofinformation
once the system is discovered, it becomes virtuallyworthless
the insertion method depends on some sort ofkey
o Alternatively, a message can be first encrypted and then hidden usingsteganography
Advantage of steganography
can be employed by parties who have something to lose should the fact of their secret
communication bediscovered
Encryption flags traffic as important or secret or may identify the sender or receiveras
someone with something tohide
Cryptography
Cryptography is the art and science of making a cryptosystem that is capable of providing
information security. Cryptography deals with the actual securing of digital data. It refers to the
design of mechanisms based on mathematical algorithms that provide fundamental information
security services.
Cryptanalysis
The art and science of breaking the cipher text is known as cryptanalysis. Cryptanalysis is the
sister branch of cryptography and they both co-exist. The cryptographic process results in the
cipher text for transmission or storage. It involves the study of cryptographic mechanism with
the intention to break them. Cryptanalysis is also used during the design of the new
cryptographic techniques to test their security strengths.
Key
It can be a number, word, phrase, or any code that will be used for encrypting as well as
decrypting any ciphertext information to plain text and vice versa.
Symmetric and asymmetric key cryptography is based on the number of keys and the way
these keys work. Let us know about both of them in details:
Symmetric key encryption
Symmetric key encryption technique uses a straight forward method of encryption.
Hence, this is the simpler among these two practices. In the case of symmetric key encryption,
the encryption is done through only one secret key, which is known as "Symmetric Key", and
this key remains to both the parties.
The same key is implemented for both encodings as well as decoding the information.
So, the key is used first by the sender prior to sending the message, and on the receiver side,
that key is used to decipher the encoded message.
One of the examples of this encryption technique is Caesar's Cipher, AES, DES,
Asymmetric Key Encryption
Asymmetric Encryption is another encryption method that uses two keys, which is a new
and sophisticated encryption technique. This is because it integrates two cryptographic keys for
implementing data security. These keys are termed as Public Key and Private Key.
The "public key", as the name implies, is accessible to all who want to send an encrypted
message. The other is the "private key" that is kept secure by the owner of that public key or
the one who is encrypting.
Encryption of information is done through public key first, with the help of a particular
algorithm. Then the private key, which the receiver possesses, will use to decrypt that
encrypted information. The same algorithm will be used in both encodings as well as decoding.
Examples of asymmetric key encryption algorithms are Diffie-Hellman and RSA algorithm.
Security Services of Cryptography
o Confidentiality of information.
o Data Integrity.
o Authentication.
o Message authentication.
o Entity authentication.
o Non-repudiation.
Cryptography Primitives
Cryptography primitives are nothing but the tools and techniques in Cryptography that can be
selectively used to provide a set of desired security services −
Encryption
Hash functions
Message Authentication codes (MAC)
[Link] Security:
Definition of Perfect Security
Let ε= (E,D) be a Shannon cipher defined over (K,M, C).
Consider a probabilistic experiment in which the random variable k is uniformly
distributed over
K. If for all m0,m1 Є M, and all c Є C, we have
Pr [ E(k,m0) = c ] = Pr [ E(k,m1) = c ], then we say that ε is a perfectly secure
Shannon cipher.
Eavesdropper
X Y
Y X
PlainText Encrypter Decrypter CipherTesxt
Z Z
Z
Secure Channel
RANDOM Z
SOURCE
Key SourcE
There are two dual and complementary security goals in
communication: Confidentiality (or secrecy) and authenticity.
Confidentiality means that an eavesdropper cannot obtain any useful
information about the plaintext, and authenticity means that 5 an active
eavesdropper cannot successfully insert a fraudulent message Y that will
be accepted by the receiver
Information-theoretic security
Information-theoretic security is a cryptosystem whose security derives
purely from information theory; the system cannot be broken even if the
adversary has unlimited computing power. The cryptosystem is
considered cryptanalytically unbreakable if the adversary does not have
enough information to break the encryption.
There are a variety of cryptographic tasks for which information-
theoretic security is a meaningful and useful requirement. A few
of these are:
[Link] Cryptosystem
Two of the first kinds of cryptosystems that we considered were
simple substitution ciphers and permutation ciphers. Each of them
quickly proved vulnerable to attack. We now consider a new kind of
cryptosystem that is based on them but which is considerably more
difficult to attack; so difficult, in fact, that most modern
cryptosystems are of the type we now consider. A product
cryptosystem is a block cipher that repeatedly performs
substitutions and permutations, one after the other, to produce
ciphertext.
Example : DES and AES
15. CRYPTANALYSIS
Cryptanalysis is the art of trying to decrypt the encrypted messages
without the use of the key that was used to encrypt the messages. Cryptanalysis
uses mathematical analysis & algorithms to decipher the ciphers.
The success of cryptanalysis attacks depends
Amount of time available
Computing power available
Storage capacity available
The following is a list of the commonly used Cryptanalysis attacks;
The attacker knows or can guess the plaintext for some parts of the
ciphertext. For example, maybe all secure login sessions begin with
the characters LOGIN, and the next transmission may be
PASSWORD. The task is to decrypt the rest of the ciphertext blocks
using this information.
.