CPSC 4200 Midterm

0.0(0)
Studied by 0 people
call kaiCall Kai
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/82

encourage image

There's no tags or description

Looks like no tags are added yet.

Last updated 11:15 PM on 2/2/25
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai
Chat

No analytics yet

Send a link to your students to track their progress

83 Terms

1
New cards

Adversary

An intelligence that actively tries to cause a system to misbehave


aka the attacker or the bad guy

2
New cards

Security Mindset - Attacker

  • look for weakest links (easy to attack)

  • identity assumptions that security depends on (are they false, can they be made false)

  • think outside the box (not contained by system designer’s worldview)the


3
New cards

Security Mindset - Defender

security policy

  • what assets are we trying to protect

  • what properties are we trying to enforce

threat model

  • who’s the attacker? capabilities? motivations?

  • what kind of attack are we trying to protect?

risk assessment

  • what are the weaknesses of the system?

  • what will successful attacks cost us?

  • how likely?

countermeasures

  • cost vs benefits

  • technical vs non-technical


4
New cards

Security Policies

What asset are we trying to protect?

asset - any data/device/component that supports info-related activities


What properties are we trying to enforce?

CIA (Confidentiality, Integrity, Availability)

and other AAA

5
New cards

Confidentiality

ensure information has not been disclosed in an unauthorized way

problem: ensure only Bob can read the message from Alice

attack: eavesdropping (passively listening to communication)

countermeasure: encryption


keep this conversation confidential (between you and me)

6
New cards

Integrity

ensures information has not been altered in an unauthorized way

problem: ensure the message received by Bob is a message sent by Alice

attack: spoofing (altering original message)

countermeasure: message authentication code (MAC)


keep this conversation strong (no changes)

7
New cards

Availability

assures systems work promptly and service is not denied to authorized users

problem: Alice needs to access her email server at all times

attack: denial of service attack

countermeasure: intrusion detection system


keep this conversation available at all times

8
New cards

CIA

knowt flashcard image
9
New cards

Terminology: Threat

any potential occurrence, malicious or not that could harm an asset

  • can be a SW bug


10
New cards

Terminology: Vulnerability

A weakness that makes a threat possible is often due to poor design or insecure coding techniques

  • ex. poor design, config mistakes, insecure coding techniques


11
New cards

Terminology: Attack

An action that exploits a vulnerability or enacts a threat, implying intent.

  • implicit concept of intent (intentional threat)

  • server crash can also cause loss of availability, but not an attack


12
New cards

Terminology: Authenticity

The ability to determine that statements, policies, and permissions issued by persons or systems are genuine.

13
New cards

Terminology: Anonymity

The characteristic that ensures certain records or transactions cannot be attributed to any individual.

14
New cards

Terminology: Accountability

The requirement for actions of an entity to be traced uniquely to that individual.

15
New cards

Terminology: Passive vs Active Attack

passive - an attack that involves eavesdropping or monitoring messages without altering them


active - n attack that involves modification of messages

  • ex. masquerading, replaying, or spoofing.


16
New cards

Terminology: Inside vs Outside Attack

Inside - initiated by authorized entity inside security perimeter

Outside - initiated by unauthorized entity outside the perimeter

17
New cards

Terminology: Attack Surface

The different vectors through which an attack can occur

  • network (weak crypto for digital signature)

  • software (buffer overflow)

  • human components (social engineering)


18
New cards

Why are there security vulnerabilities?

lots of buggy software (programmers are unaware)


contributing factors

  • C is unsafe language (memory issue)

  • legacy software

  • consumers don’t care about security (not a selling point)

  • security is expensive


19
New cards

State of Security

never ending war between good and bad guys

every asset has at least one vulnerability

no such thing as bullet proof barrier

only a multi-layered approach has a change of success

20
New cards

Cryptography

core building block of cyber security (basis for security mechanisms)

  • CIA and AAA properties are provided using cryptography


cryptography is not:

  • solution to all security problems

  • reliable unless implemented/used properly

  • something you should invent yourself

  • bitcoin


21
New cards

Never do what with crypto?

Do NOT roll your own crypo

22
New cards

Message Integrity with Functions

goal: ensure the message received by Bob is a message sent by Alice (m = m’)

approach: send a message-dependent message along with the original message

  • v = f(m)

bob checks that f(m’) == v’, otherwise m’ untrusted


<p>goal: ensure the message received by Bob is a message sent by Alice <strong>(m = m’)</strong></p><p>approach: send a message-dependent message along with the original message</p><ul><li><p><strong>v = f(m)</strong></p></li></ul><p>bob checks that <strong>f(m’) == v’</strong>, otherwise m’ untrusted</p><p></p>
23
New cards

Function Properties

  • generate consistent output (with no collisions)

  • 1-to-1 mapping between m and f(m) (bijection)

  • unknown to Mallory


<ul><li><p>generate consistent output (with no collisions)</p></li><li><p>1-to-1 mapping between m and f(m) (bijection)</p></li><li><p>unknown to Mallory</p></li></ul><p></p>
24
New cards

Random Function

input: arbitrary size (up to huge max)

output: fixed size (256 bits)

  • defined by a large lookup table that’s filled with flipping coin

  • mapped each input independently at random at any of the possible outputs

  • idealization of a cryptographic hash function


<p>input: arbitrary size (up to huge max)</p><p>output: fixed size (256 bits)</p><ul><li><p>defined by a large lookup table that’s filled with flipping coin</p></li><li><p>mapped each input independently at random at any of the possible outputs</p></li><li><p>idealization of a cryptographic hash function</p></li></ul><p></p>
25
New cards

Random Function: is it secure?

Yes

  • mallory’s best chance is to guess

  • caveat: lookup table needs to be exchanged securely in advance


26
New cards

Random Function: is it practical?

No

  • both sides have other know entire table beforehand

  • table might be to large to conveniently share between parties


27
New cards

Pseudorandom Function (PRF)

set of functions that “look“ random but are practical

  • “looks“ random: two inputs that differ by 1, likely to produce different outputs

  • practical: computable (no need to pre-share all possible input to output pairing/lookup table)

properties

  • family of function can be public

  • k is a secret only known to Alice/Bob

    • randomly chosen (256 bits)

follows Kerckhoff’s Principles


<p>set of functions that “look“ <strong>random</strong> but are <strong>practical</strong></p><ul><li><p>“looks“ random: two inputs that differ by 1, likely to produce different outputs</p></li><li><p>practical: computable (no need to pre-share all possible input to output pairing/lookup table)</p></li></ul><p>properties</p><ul><li><p>family of function can be public</p></li><li><p><strong>k </strong>is a secret only known to Alice/Bob</p><ul><li><p>randomly chosen (256 bits)</p></li></ul></li></ul><p>follows Kerckhoff’s Principles</p><p></p>
28
New cards

Length of key k

the length of key k determines how many functions they have to check for the right one


ex. |k| = 8, f0 → f28(f256)

<p>the length of key <strong>k </strong>determines how many functions they have to check for the right one</p><p></p><p>ex. |k| = 8, f<sub>0</sub> → f<sub>2<sup>8</sup></sub>(f<sub>256</sub>)</p>
29
New cards

Function keys should be how long?

128 bits

at least 80

30
New cards

Kerckhoff’s Principles

  1. system must be practically, if not mathematically, indecipherable;

  2. it should not require secrecy, and I should not be a problem if it fall into enemy hands;

  3. must be possible to communicate and remember the key without using notes, and parties must be able to change/modify it at will;

  4. It must be applicable to telegraph communications;

  5. It must be portable, and should not require several persons to

    handle or operate;

  6. It must be easy to use and should not be stressful to use or

    require its users to know and comply with a long list of rules.


31
New cards

Advantage of PRFs

PRFs depend on secret of key, not knowledge of the system

  • system: random function f

  • advantage: good, secure functions f can be public

  • NO security of obscurity


key k must be exchanged between Alice and Bob

  • k us much smaller than f


32
New cards

Message Integrity Using PRFs

goal: message received by Bob is a message sent by Alice

PRF approach

  • let f be a secure PRF

  • in advance, choose a random k known only by Alice and Bob

  • let v = fk(m)

  • Bob checks that fk(m’) == v’


<p>goal:  message received by Bob is a message sent by Alice</p><p>PRF approach</p><ul><li><p>let <strong>f </strong>be a secure <strong>PRF</strong></p></li><li><p>in advance, choose a random k known only by Alice and Bob</p></li><li><p>let <strong>v = f<sub>k</sub>(m) </strong></p></li><li><p>Bob checks that<strong> f</strong><span><strong><sub>k</sub></strong></span><strong>(m’) == v’</strong></p></li></ul><p></p>
33
New cards

Message Integrity Using Multiple PRFs

goal: multiple messages received by Bob are messages sent by Alice

problem:

  • replay attack - Mallory resends message from earlier communication

  • reordering attack - Mallory sends a message out of order

countermeasure

  • add sequence number (“freshness value“/sequence number)

  • use a different key k each time


34
New cards

Do PRFs Exist?

we don’t know


best we can do: well studied function we havn’’t spotted issues with yet

  • HMAC-SHA256


35
New cards

Message Authentication Code (MAC)

essentially the same as PRF

currently popular PRF: HMAC-SHA256

  • hash-based message authentication code (HMAC)


<p>essentially the same as PRF</p><p>currently popular PRF: HMAC-SHA256</p><ul><li><p>hash-based message authentication code (HMAC)</p></li></ul><p></p>
36
New cards

Hash Functions

input: arbitrary length data

output: fixed size digest (n bits)

  • no key, fixed function

properties:

  • collision resistance (hard to find x ≠ y such that h(x) = h(y))

  • pre-image resistance (given y, hard to find x such that f(x) = y)

  • second pre-image resistance (given fixed x, should be hard to find x’ ≠ x such that h(x) = h(x’))


37
New cards

Hash Functions: Good vs. Broken

good functions:

  • SHA-2 (include SHA-256)

  • SHA - 3

  • SHA-5 (include SHA-512)


broke functions (DO NOT USE):

  • SHA-1

  • MD5


38
New cards

Hash Function Rule of Thumb

hash output should be at least 256 bits long

39
New cards

MAC vs Hash

use a MAC instead of a hash


message authentication code (MAC)

  • think of as synonymous with PRF

  • ex. HMAX-SHA256

cryptographic hash function

  • not a strong PRF

  • ex. SHA256

  • have a weakness


40
New cards

Hash Function Vulnerability

hash function vulnerable to length extension attacks

  • given z = H(m) for some unknown m, can construct H(m || padding || v) for v we choose.

  • aka HW1


41
New cards

Goal of Cryptography

approaching true randomness practically

42
New cards

Pseudo Randomness

true randomness

  • output of a physical process that is inherently random

  • scarce and hard to get

  • slow

pseudorandom generator (PRG)

  • takes small seek (key k) that is really random

  • generates long sequence of numbers that “appear random“

  • different from PRF


43
New cards

Source of Randomness

  • coin flip

  • human behavior

  • atomic decay

  • thermal noise

  • electromagnetic noise

  • physical variation

    • clock drift

    • DRAM decay

    • image sensor error

    • SRAM startup state

  • lava lamps


44
New cards

Where do we get true randomness?

key k needs to be truly random (with secure PRF f)

  • adversary can’t guess it

  • gather details about computer that’s hard for adversary to guess


modern OSs collar randomness and provide API to access it

  • /dev/random

  • /dev/urandom


45
New cards

Message Confidentiality with Encryption

knowt flashcard image
46
New cards

Ciphers

  • Caesar Cipher

  • Vigenère Cipher

  • One-Time Pad (OTP)

  • Stream Cipher

  • Block Ciphers


47
New cards

Caesar Cipher

replaces each plaintext letter with one a fixed number of places down the alphabet

<p>replaces each plaintext letter with one a fixed number of places down the alphabet</p>
48
New cards

Caesar Cipher Cryptanalysis

how to break it:

  • only 26 possible keys (“brute force“ every possible k)

how can a computer recognize the right one?

  • English has distinctive letter frequency distribution (use X2 test)


<p>how to break it:</p><ul><li><p>only 26 possible keys (“brute force“ every possible <strong>k</strong>)</p></li></ul><p>how can a computer recognize the right one?</p><ul><li><p>English has distinctive letter frequency distribution (use X<sup>2</sup> test)</p></li></ul><p></p>
49
New cards

Vigenère Cipher

encrypts successive letters using a sequence of Caesar ciphers determined by the letters of a keyword

<p>encrypts successive letters using a sequence of Caesar ciphers determined by the letters of a keyword</p>
50
New cards

Vigenère Cipher Cryptanalysis

how to break it:

  • simple if we know the keyword length, n

    • break cipher text into n slices

    • solve each slice as caesar cipher

  • distance between repeated strings in cipher tests (likely) a multiple of key length n

    • ex. distance 16 implies n is 16, 8, 4, 2, 1 (find multiple repeat to narrow down)

  • how to find n?: Kasiski method


<p>how to break it:</p><ul><li><p>simple if we know the keyword length, <strong>n</strong></p><ul><li><p>break cipher text into n slices</p></li><li><p>solve each slice as caesar cipher </p></li></ul></li><li><p>distance between repeated strings in cipher tests (likely) a multiple of key length <strong>n</strong></p><ul><li><p>ex. distance 16 implies <strong>n </strong>is 16, 8, 4, 2, 1 (find multiple repeat to narrow down)</p></li></ul></li><li><p>how to find <strong>n</strong>?: <strong>Kasiski method</strong></p></li></ul><p></p>
51
New cards

One-Time Pad (OTP)

Alice encrypts, and Bob decrypts using the same key k and uses OTP for E and D

  • both generate a secret, long string of truly random bits (the OTP k)

  • to encrypt: c = p XOR k

  • to decrypt: p = c xor k = p xor k xor k

theoretically secure since cipher text doesn’t reveal any info (besides length) about plain text


<p>Alice encrypts, and Bob decrypts using the same key <strong>k </strong>and uses OTP for E and D</p><ul><li><p>both generate a <strong>secret, long string of truly random bits (the OTP k)</strong></p></li><li><p>to encrypt: c = p XOR k</p></li><li><p>to decrypt: p = c xor k = p xor k xor k</p></li></ul><p>theoretically secure since cipher text doesn’t reveal any info (besides length) about plain text</p><p></p>
52
New cards

One-Time Pad (OTP) Reuse Problem

should never reuse any part of the pad

  • adversary can learn (a xor k) and (b for k)

  • adversary xors those to get (a xor b) which is useful



<p>should never reuse any part of the pad </p><ul><li><p>adversary can learn (a xor k) and (b for k)</p></li><li><p>adversary xors those to get (a xor b) which is useful</p></li></ul><p></p><p></p>
53
New cards

Stream Cipher

using pseudorandom generator

  • inputs seed k

  • outputs stream that is indistinguishable from true randomness unless know k


  1. start with shared secret key truly random number k

  2. Alice and Bob use k to seed the PRG

  3. to encrypt, Alice XORs next bit of her output with next bit of plaintext

  4. to decrypt, Bob XORs next bit of his output with next bit of ciphertext


<p><strong>using pseudorandom generator</strong></p><ul><li><p>inputs seed <strong>k</strong></p></li><li><p>outputs stream that is indistinguishable from true randomness unless know <strong>k</strong></p></li></ul><p></p><ol><li><p>start with shared secret key truly random number <strong>k</strong></p></li><li><p>Alice and Bob use k to seed the PRG</p></li><li><p>to encrypt, Alice XORs next bit of her output with next bit of plaintext</p></li><li><p>to decrypt, Bob XORs next bit of his output with next bit of ciphertext</p></li></ol><p></p>
54
New cards

Stream Cipher: Questions

what happens if you reuse the key?

  • Mallory can save sequences and look for repeats (like Vigenère cipher)

what happens if you reuse the output of the PRG?

  • Mallory can save sequences and look for repeats (like Vigenère cipher)

what is the tradeoff between OTP and Stream Cipher?

  • OTP: true randomness and random key = len(m)

  • Stream Cipher: pseudorandomness and random key = 256 bits

what are some examples of Stream Cipher?

  • Salsa20, RC2 (broken), RC4 (broken)

should I roll my own Stream Cipher instead?

  • NO


55
New cards

Block Cipher

functions that encrypt fixed-size blocks with a reusable key

  • inverse function decrypts when used with same key

  • most commonly used approach to encrypting for confidentiality

  • Block Cipher is a Pseudorandom Permutation (PRP)


<p>functions that encrypt fixed-size blocks with a reusable key</p><ul><li><p>inverse function decrypts when used with same key</p></li><li><p><strong>most commonly used</strong> approach to encrypting for confidentiality </p></li><li><p><strong>Block Cipher is a Pseudorandom Permutation (PRP)</strong></p></li></ul><p></p>
56
New cards

Pseudorandom Permutation

input: n-bit string (or block)

output: n-bit block

confusion

  • each bit of the cipher text should depend on several parts of the key

  • destroy features of the plaintext

diffusion

  • changing a single bit of plaintext, statistically changes 50% of the cipher text bits,

  • and similarly changing one bit of the cipher text causes 50% of the plaintext bits to change

  • hides features of the plaintext



57
New cards

Data Encryption Standard (DES)

key: 64-bit quantity = 8-but parity + 56-bit key

input/output: 46 bits

brute force key search

  • trying 1 key/microsecond would take 1000+ yrs (256)

no longer secure since 56-bit key vulnerable toe exhaustive search

<p>key: 64-bit quantity = 8-but parity + 56-bit  key</p><p>input/output: 46 bits</p><p>brute force key search</p><ul><li><p>trying 1 key/microsecond would take 1000+ yrs (2<sup>56</sup>)</p></li></ul><p><strong>no longer secure since 56-bit key vulnerable toe exhaustive search</strong></p>
58
New cards

Alternatives to DES

Triple DES (3DES)

  • 168-bit key

  • no brute force attacks

  • encryption is slower than DES

Advanced Encryption Standard (
AES)


59
New cards

Advanced Encryption Standard (AES)

most common block cipher

128-bit block size

variable key size (128, 192, or 256)

  • AES-128, AES-192, AES-256

designed to run fast in SW


60
New cards

How to encrypt longer message?

can only encrypt in units of cipher block size

  • cut message into multiple chunks

message might not be multiple of block size

  • add padding to end of message

  • add n bytes that have value n

  • must be able to recognize and remove padding after decryption

how to properly encrypt multi-block messages? (cipher modes)

  • ECB, CBC, CTR


61
New cards

Electronic Codebook (ECB) Mode

just encrypt each block individually

  • DON’T USE ECB


<p>just encrypt each block individually</p><ul><li><p>DON’T USE ECB</p></li></ul><p></p>
62
New cards

Cipher-Block Chaining (CBC) Mode

knowt flashcard image
63
New cards

Counter (CTR) Mode

XOR ith block of message with Ek(nonce || ctr)

  • effectively a stream cipher

blocks can be decrypted independently


<p>XOR i<sup>th</sup> block of message with E<sub>k</sub>(nonce || ctr)</p><ul><li><p>effectively a stream cipher</p></li></ul><p>blocks can be decrypted independently </p><p></p>
64
New cards

How to enforce confidentiality AND integrity?

Encrypt-then-MAC


“E then M” in the alphabet

<p>Encrypt-then-MAC</p><p></p><p>“E then M” in the alphabet</p>
65
New cards

Questions

we need two shared keys, but only have one?

  • use a PRG

we have a reverse channel (Bob to Alice), do we use the same key?

  • no, use separate keys

in networking applications, we cannot encrypt header. what do we do?

  • use authentication encryption with associated data (AEAD)


66
New cards

Secret Key (Symmetric) Cryptography

assumptions we’ve made so far: Alice and Bob shared a secret key in advance

limitation: sender/receiver must share the same key

  • needs secure channel of key distribution

  • impossible for two parties having no prior relationship

  • needs many keys for N partiers to communicate

Alice and Bob can have public conversation to derive a shared key


67
New cards

How to derive a shred secret key?: Diffie-Hellman (DH) Key Exchange


<p></p>
68
New cards

Diffie-Hellman (DH) Example

knowt flashcard image
69
New cards

Diffie-Hellman (DH): Passive Eavesdropping Attack

DH secure against passive eavesdropping attacks since no known efficient algorithm

<p>DH secure against passive eavesdropping attacks since no known efficient algorithm</p>
70
New cards

Diffie-Hellman (DH): Man-in-the-middle (MITM) Attack

DH not secure against MITM attack

  • DH gives shared secret, but you don’t know who's on the other end


<p>DH not secure against MITM attack</p><ul><li><p>DH gives shared secret, but you don’t know who's on the other end</p></li></ul><p></p>
71
New cards

Defending against MITM Attacks

  • rely on out-of-band communication between users (2FA)

  • rely on physical contact (smartcards)

  • use digital signuature


72
New cards

Key Management

key management is hard (protecting keys, communicating keys, etc)

each key should have 1 purpose

vulnerability of a ket increases:

  • the more you use

  • the more places you store it

  • the longer you have it


73
New cards

Forward Secrecy

protestation against old keys that have been compromised

  • learning old keys shouldn’t help adversary learn new keys

  • compromising an individual session should not compromise future sessions

  • compromising a long-term key should not enable decryption of recorded cypher text

use short-lived ephemeral keys or sessions keys


74
New cards

Secret Key (Symmetric) Cryptography

assumptions we’ve made so far: Alice and Bob shared a secret key in advance

limitation: sender/receiver must share the same key

  • needs secure channel of key distribution

  • impossible for two parties having no prior relationship

  • use Diffie-Hellman (DH) to determine shared secret key

problem: Scaling


<p>assumptions we’ve made so far: Alice and Bob shared a secret key in advance</p><p>limitation: sender/receiver must share the same key</p><ul><li><p>needs secure channel of key distribution</p></li><li><p>impossible for two parties having no prior relationship</p></li><li><p>use Diffie-Hellman (DH) to determine shared secret key</p></li></ul><p><strong>problem: Scaling</strong></p><p></p>
75
New cards

Scaling Problem

suppose Alice publishes data to lots of people, and they all want to verify integrity

  • can’t share integrity let with everyone, or else anybody could forge messages

suppose Bob wants to receive data from lots of people confidentially

  • schemes we’ve discusses would need separate encryption key shared with each person

Solution: Public-Key Crypto


76
New cards

Public-key (Asymmetric) Cryptography

so far: encryption key EK = Decryption key Dk

  • Symmetric-Key Cryptography

  • require a separate key shared with each person

new idea: each party has a pair (K, K-1) of keys

  • K is the public key (can be shared with any other party)

  • K-1 is the private key (kept secret)

private key K-1 to pubic key K (impossible)

pubic key K to private key K-1 (possible)


77
New cards

Rivest-Shamir-Adleman (RSA)

best known public-key cryptosystem

  • secure based on difficulty of factoring large numbers

uses for encryption AND asymmetric cryptography

drawback: factor of +1000 slower than AES

78
New cards

How Rivest-Shamir-Adleman (RSA) Works

knowt flashcard image
79
New cards

Asymmetric Encryption

Alice wants to send encrypted message to Bob

  • they know each other’s public keys

Alice encrypts with KB, now only Bob can decrypt with KB-1

  • D(E(m, KB), KB-1) = m

many can encrypt a message for Bob, but only Bob can decrypt

solves message confidentiality


<p>Alice wants to send encrypted message to Bob</p><ul><li><p>they know each other’s public keys</p></li></ul><p>Alice encrypts with <strong>K<sub>B</sub></strong>, now only Bob can decrypt with <strong>K<sub>B</sub><sup>-1</sup></strong></p><ul><li><p>D(E(m, <strong>K<sub>B</sub></strong>), <strong>K<sub>B</sub><sup>-1</sup></strong>) = m</p></li></ul><p>many can encrypt a message for Bob, but only Bob can decrypt</p><p><strong>solves message confidentiality </strong></p><p></p>
80
New cards

Digital Signiture

Bob needs to know if the message is coming from Alice

  • they know each other’s public key

Alice encrypts (signs) with KA-1, Bob decypts (verifies) decrypts with KA

  • only Alice has her own private key (so message must be from her)

  • Bob receives Alices’s digital signature d

solves message integrity AND sender authenticity


<p>Bob needs to know if the message is coming from Alice</p><ul><li><p>they know each other’s public key</p></li></ul><p>Alice encrypts (<strong>signs</strong>) with <strong>K<sub>A</sub><sup>-1</sup></strong>, Bob decypts (<strong>verifies</strong>) decrypts with <strong>K<sub>A</sub></strong></p><ul><li><p>only Alice has her own private key (so message must be from her)</p></li><li><p>Bob receives Alices’s <strong>digital signature d</strong></p></li></ul><p><strong>solves message integrity AND sender authenticity</strong></p><p></p>
81
New cards

Question

since RSA encryption is much slower than AES and message lengths are constrained, why bother?

  • AES requires symmetric key, needs to be derived first

  • DH fails under the presence of Mallory (MITM attack), so RSA needs to be used to distribute the symmetric (secret) key

how do we distribute the symmetric key using RSA?

  • RSA with DH

  • RSA without DH


82
New cards

RSA with Diffie-Hellman (DH)

  1. establish shared secret k using DH (even with Mallory is there)

  2. make sure they’re really talking to each other by exchanging/verifying RSA signatures on k (if Mallory were there, this would fail)

  3. split k into four distinct keys (integrity and confidentiality in both ways)

  4. to encrypt: encrypt with symmetric cipher, then add MACs for integrity (Encrypt-then-MAC)


83
New cards

RSA without Diffie-Hellman (DH)

  1. Alice generates secret key k and encrypts with Bob’s public key KB. Cipher text is sent to Bob who decrypts with his private key KB-1

  2. Use RSA signatures on ciphertext to avoid Mallory from tampering

  3. with the message

  4. Decrypted plaintext is k, now both Alice and Bob can use k for symmetric encryption ( AES).

  5. Split k into four distinct keys (integrity and confidentiality in both ways)

  6. To encrypt: Encrypt with symmetric cipher, then add MACs for integrity (Encrypt-then-MAC)