1/143
Looks like no tags are added yet.
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai | Chat |
|---|
No analytics yet
Send a link to your students to track their progress
Nobody but Us (NOBUS)
Allowing only the National Secuirty Agency (NSA) access to encrypted data
Cryptosystem
Combination of cryptographic algorithms and protocols
Stream cipher characteristic
Generates a continuous stream of key material
Why is lightweight cryptography designed for modern systems?
To provide efficient and secure encryption solutions for devices with limited resources
Which role does modular arithmetic play in cryptographic algorithms
Performing calculations within a finite set of numbers
how is lattice-based cryptography applied in modern encryption techniques
Using geometric structures for cryptographic algorithms
Which role do large prime numbers play in cryptographic algorithms
Ensures security and strength of encryption
A type of homomorphic encryption
Full Homomorphic encryption (FHE)
A term that refers to the blocks in a blockchain containing cryptographic proof of work
Proof of work
What is the purpose of the NIST selection of Ascon for lightweight cryptography
To secure data on IoT and small device with limited resources
Caesar Cipher
Shifts each letter 3 positions to the right of the letter in the alphabet
ROT13 cipher
Shifts each letter 13 positions to the right of the letter in the alphabet
Monoalphabetic substitution cipher
replaced a plaintexts letter by a fixed letter
Polyalphabetic substitution cipher
replaced a plaintexts letter by different letters in a ciphertext
Rail Fence cipher
a plaintexts letters are written diagonally downwards and upwards on successive rails of an imaginary fence
Permutation/transputation Cipher
Reorders or scrambles elements of plaintext in a ciphertext without adding or removing elements
Columnar cipher
plaintext letters are placed in rows of length equal to the cipher keyword length and then read in columns to generate ciphertext
Cryptographic hash function
provides the data integrity security service
Message authentication code (MAC)
Provides the data integrity and authenticity security services
Uses a cryptographic hash function and symmetric encryption
Digital signature
provides the data integrity, origin authentication, and non-repudiation security services
uses cryptographic hash function and asymmetric encryption
message authentication code (MAC) features
known as a tag
uses a symmetric key
Requires a MAC algorithm
provides data integrity and data origin authentication
does not provide non-repudiation
Hashed Message Authentication code (HMAC)
A cryptographic primitive used for verifying data integrity and authenticity
Requires a symmetric key and cryptographic hash function
Uses:
SHA512
SHA2
MD4 and MD5
HMAC-SHA256
uses 256 bits
What is a key
a string of bits
What is a key space
a set of all possible keys
Confusion
Hides the relationship between a ciphertext and the encryption key
secure encryption algorithm property that ensures that changing a single bit of an encryption key impacts most of the ciphertext bits
Diffusion
Hides the relationship between a plaintext and a ciphertext
Secure encryption algorithm property that ensures that changing a single plaintext bit changes about half of the ciphertext bits, and changing a single ciphertext bit changes about half of the plaintext bits
Kerchoffs principle
security of a cryptographic algorithm should depend on the secrecy of the key, not the secrecy of the algorithm
IDEA
A block cipher which encrypts a plaintext 64-bit blocks at a time
Block cipher
a symmetric algorithm which encrypts a data block of fixed size
Padding
the process of filling out a plaintexts lasts block iwht random bits to create a full block
Cipher Block Chaining (CBC)
Each plaintext block is XORed with the previous ciphertext block before being encrypted
The initialization vector is used in the encryption process of a plaintext’s first block to create a unique ciphertext every time the encryption is performed
Prevents duplicate blocks from producing the same ciphertext
Electronic Code Book (ECB)
each plaintext block is encrypted separately to generate a ciphertext block
Counter (CTR)
A ciphertext block depends on the position of the current plaintext block
Sender and receiver use a synchronized counter which computes a new shared value each time a ciphertext block is exchanged
Cipher Feedback (CFB)
Each plaintext block is encrypted and XORed with the previous cipher block text
An IV is used in the encryption process of the first plaintext block, and a plaintext block is XORed with the encryption of the previous block
Output Feedback (OFB)
Each block is created independently of plaintext and cipherblock texts
Each block is created independently of plaintext and ciphertext blocks with no chaining dependencies
Data Encryption Standard (DES)
symmetric block cipher which encrypts data in 64-blocks
uses 56-bit keys
not a secure encryption algorithm because a 56-bit key can be broken with modern cryptanalytic techniques
Triple Data Encryption Standard (TDES)/ 3DES
symmetric block cipher which applies DES three consecutive, or rounds, to each 64-bit block
is as secure as DES when used with keying option 3 (three identical 56-bit keys)
3DES
symmetric block cipher which consecutively applies another encryption algorithm three times to each 64-bit block
stream cipher
symmetric encryption algorithm that encrypts data one bit at a time
keystream
continuous bit stream that is generated based on an encryption key
Keystream generator
an algorithm that outputs a continuous bit stream given input key
RSA
assymetric encryption algorithm based on the mathematical properties of prime numbers
ElGamal
asymmetric encryption algorithm based on the mathematical properties of discrete logarithms
should not be used in a device with limited memory
ECC
asymmetric encryption algorithm based on the mathematical properties of elliptic curves
ideal for use in a IoT device
Ephemeral Key
a key generated for each execution of a key establishment process
Static key
long term key intended to be used over an extended time period
Session key
symmetric key that is only used for the duration of a single communication session
Certificate authority (CA)
issues, renews, revokes, and distributes digital certificates
Registration authority (RA)
verifies identity of a digital certificate applicant
Certificate repository (CR) or central directory
stores digital certificates issues by a CA
Certificate policy (CP)
defines structure of PKI, describes a PKIs entities and roles, and specifies a PKIs procedures and operational requirements
Certificate practice statement (CPS)
describes how a CA issues, renews, revokes, and distributes certificates
Digital Signature Algorithm (DSA)
based on the ElGamal public key cryptography
RSA digital signature algorithm
Based on the RSA public key cryptography
Elliptic curve digital signature algorithms (ECDSA)
based on the elliptic curve public cryptography
domain validation (DV) certificate
only verifies identity of a domains owner
domain extended validation (EV) certificate
verifies the identity of a domains owner, the domain owners exclusive control over the domain
wildcard
certifcate validates a domain and all domains subdomains
subject alternative name (SAN) certificate
used by multiple domains owned by the same domain owner
Root certificate
created and self signed by a certificate authority
code signing certificate
used by a software developer, or software publisher, to digitally sign software programse
email certifcate
used by an email user to digitally sign emails
machine certificate or computer certificate
issues to a hardware device such as a computer, router, or printer
TLS certificate
used by a web server and a web client to establish a secure connection over a network
privacy enhanced mail (PEM)
ASCII format
defines methods for encoding binary data using base64
Base 64
binary text-to-text encoding scheme that represents binary data in an ASCII string format
Distinguished encoding rules (DER)
binary format
subset of the abstract syntax notation one (ASN.1) which is a platform independent encoding format
personal information exchange (PFX)
binary format
password protected archive file format that contains the certificate and the corresponding private key
Key escrow
refers to the secure storage and managment of cryptographic keys by a trusted third party known as an escrow agent
Secure real time transport protocol (SRTP)
secure delivery of voice and video services over an IP network
provides integrity, authentication, and confidentiality
uses AES and HMAC-MD5
Lightweight Directory Access Protocol (LDAP)
protocol for accessing and maintaining distributed directory information services over an IP network
Uses port 636
LDAPS
protocol for accessing and maintaining distributed directory information services securely over an IP network that uses SSL/TLS
used for securely sharing information about a user
LDAP injection attack
attach in which an attacker exploits input validation vulnerabilities to construct and execute an LDAP query
Post Office Protocol (POP)
used by an email client to retrieve an email from a mail server
uses port 110
POPS
uses SSL/TLS to secure communications between a PAP client and a POP server
uses port 995
POP server
receives and stores emails in a users mailbox
POP client
retrieves an email from a POP server
Internet message access protocol (IMAP)
protocol used by an email client to retrieve an email from a mail server
uses TCP port 143
Multipurpose Internet Mail extensions (MIME)
Standard that extends the format of an email message to support non-ASCII character sets and multimedia attachemnts
Multipurpose internet Mail extensions (S/MIME)
internet standard for signing and encrypting MIME data
provides authentication, integrity, non-repudiation, and confidentiality security services for electronic messaging application
site to site VPN/ router-to-router VPN
a connection between two or more networks
used to connect different locations of the same organization
Client to site VPN/remote access VPN
connection between a client computer and a remote router
Full tunnel
routes and encrypts all network traffic through the VPN, regardless of where the VPN service is hosted
recommended and more secure
Split tunnel
routes and encrypts all non-internet network traffic over the VPN
Separates by both app and URL
IPSec
protocol suite for securing data communications over an IP network
Layer 2 tunneling protocol (L2TP)
mechanism for setting up a VPN tunnels at the data link layer
does not provide encrpytion by default and is typically used in conjuction with IPSec
Sender policy framework (SPF)
email authentication method that ensures the sending mail server is authorized to send emails from the senders domain
DomainKeys identified mail (DKIM)
an email authentication method that uses digital signatures to verify that an email was sent and authorized by the owner of the sending domain
Domain based message authentication, reporting, and conformance (DMARC)
email authentication protocol that secures email communications by verifying sender identities, specifying actions for authentication failures, and providing reports on email delivery and integritye
email gateway
server that processes an organization incoming and outgoing email to protect the organizations internal servers
Digital ledger
electronic system or database used to record and track transactions
Blockchain
decentralized and distributed digital ledger that records and links transactions across a network of computers
Chain of blocks linked by cryptographic hashes
Open public ledger
transparent record keeping system that is accessible to the public, enabling anyone to verify recorded transactions
Merkle tree
hierarchical data structure used for verifying the integrity of large data sets
Merkle path
the sequence of nodes connecting a data element to the root
Proof of work (POW)
blockchain consensus algorithm that requires network participants to perform a computationally intensive task, known as mining
Proof of Authority (POA)
blockchain consensus algorithm where validators are chosen based on the validators identity and reputation
Proof of stake (POS)
blockchain consensus algorithm that selects a network participant to create a new block based on the amount of assets the participant holds and is willing to stake
Authentication header (AH)
IPSec protocol that provides authentication and integrity for an IP packet