D830 - Introduction to Cryptography

0.0(0)
Studied by 1 person
call kaiCall Kai
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/143

encourage image

There's no tags or description

Looks like no tags are added yet.

Last updated 4:03 PM on 9/13/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai
Chat

No analytics yet

Send a link to your students to track their progress

144 Terms

1
New cards

Nobody but Us (NOBUS)

Allowing only the National Secuirty Agency (NSA) access to encrypted data

2
New cards

Cryptosystem

Combination of cryptographic algorithms and protocols

3
New cards

Stream cipher characteristic

Generates a continuous stream of key material

4
New cards

Why is lightweight cryptography designed for modern systems?

To provide efficient and secure encryption solutions for devices with limited resources

5
New cards

Which role does modular arithmetic play in cryptographic algorithms

Performing calculations within a finite set of numbers

6
New cards

how is lattice-based cryptography applied in modern encryption techniques

Using geometric structures for cryptographic algorithms

7
New cards

Which role do large prime numbers play in cryptographic algorithms

Ensures security and strength of encryption

8
New cards

A type of homomorphic encryption

Full Homomorphic encryption (FHE)

9
New cards

A term that refers to the blocks in a blockchain containing cryptographic proof of work

Proof of work

10
New cards

What is the purpose of the NIST selection of Ascon for lightweight cryptography

To secure data on IoT and small device with limited resources

11
New cards

Caesar Cipher

Shifts each letter 3 positions to the right of the letter in the alphabet

12
New cards

ROT13 cipher

Shifts each letter 13 positions to the right of the letter in the alphabet

13
New cards

Monoalphabetic substitution cipher

replaced a plaintexts letter by a fixed letter

14
New cards

Polyalphabetic substitution cipher

replaced a plaintexts letter by different letters in a ciphertext

15
New cards

Rail Fence cipher

a plaintexts letters are written diagonally downwards and upwards on successive rails of an imaginary fence

16
New cards

Permutation/transputation Cipher

Reorders or scrambles elements of plaintext in a ciphertext without adding or removing elements

17
New cards

Columnar cipher

plaintext letters are placed in rows of length equal to the cipher keyword length and then read in columns to generate ciphertext

18
New cards

Cryptographic hash function

provides the data integrity security service

19
New cards

Message authentication code (MAC)

Provides the data integrity and authenticity security services

Uses a cryptographic hash function and symmetric encryption

20
New cards

Digital signature

provides the data integrity, origin authentication, and non-repudiation security services

uses cryptographic hash function and asymmetric encryption

21
New cards

message authentication code (MAC) features

known as a tag

uses a symmetric key

Requires a MAC algorithm

provides data integrity and data origin authentication

does not provide non-repudiation

22
New cards

Hashed Message Authentication code (HMAC)

A cryptographic primitive used for verifying data integrity and authenticity

Requires a symmetric key and cryptographic hash function

Uses:

SHA512

SHA2

MD4 and MD5

23
New cards

HMAC-SHA256

uses 256 bits

24
New cards

What is a key

a string of bits

25
New cards

What is a key space

a set of all possible keys

26
New cards

Confusion

Hides the relationship between a ciphertext and the encryption key

secure encryption algorithm property that ensures that changing a single bit of an encryption key impacts most of the ciphertext bits

27
New cards

Diffusion

Hides the relationship between a plaintext and a ciphertext

Secure encryption algorithm property that ensures that changing a single plaintext bit changes about half of the ciphertext bits, and changing a single ciphertext bit changes about half of the plaintext bits

28
New cards

Kerchoffs principle

security of a cryptographic algorithm should depend on the secrecy of the key, not the secrecy of the algorithm

29
New cards

IDEA

A block cipher which encrypts a plaintext 64-bit blocks at a time

30
New cards

Block cipher

a symmetric algorithm which encrypts a data block of fixed size

31
New cards

Padding

the process of filling out a plaintexts lasts block iwht random bits to create a full block

32
New cards

Cipher Block Chaining (CBC)

Each plaintext block is XORed with the previous ciphertext block before being encrypted

The initialization vector is used in the encryption process of a plaintext’s first block to create a unique ciphertext every time the encryption is performed


Prevents duplicate blocks from producing the same ciphertext

33
New cards

Electronic Code Book (ECB)

each plaintext block is encrypted separately to generate a ciphertext block

34
New cards

Counter (CTR)

A ciphertext block depends on the position of the current plaintext block

Sender and receiver use a synchronized counter which computes a new shared value each time a ciphertext block is exchanged

35
New cards

Cipher Feedback (CFB)

Each plaintext block is encrypted and XORed with the previous cipher block text

An IV is used in the encryption process of the first plaintext block, and a plaintext block is XORed with the encryption of the previous block

36
New cards

Output Feedback (OFB)

Each block is created independently of plaintext and cipherblock texts

Each block is created independently of plaintext and ciphertext blocks with no chaining dependencies

37
New cards

Data Encryption Standard (DES)

symmetric block cipher which encrypts data in 64-blocks

uses 56-bit keys

not a secure encryption algorithm because a 56-bit key can be broken with modern cryptanalytic techniques

38
New cards

Triple Data Encryption Standard (TDES)/ 3DES

symmetric block cipher which applies DES three consecutive, or rounds, to each 64-bit block

is as secure as DES when used with keying option 3 (three identical 56-bit keys)

39
New cards

3DES

symmetric block cipher which consecutively applies another encryption algorithm three times to each 64-bit block

40
New cards

stream cipher

symmetric encryption algorithm that encrypts data one bit at a time

41
New cards

keystream

continuous bit stream that is generated based on an encryption key

42
New cards

Keystream generator

an algorithm that outputs a continuous bit stream given input key

43
New cards

RSA

assymetric encryption algorithm based on the mathematical properties of prime numbers

44
New cards

ElGamal

asymmetric encryption algorithm based on the mathematical properties of discrete logarithms

should not be used in a device with limited memory

45
New cards

ECC

asymmetric encryption algorithm based on the mathematical properties of elliptic curves

ideal for use in a IoT device

46
New cards

Ephemeral Key

a key generated for each execution of a key establishment process

47
New cards

Static key

long term key intended to be used over an extended time period

48
New cards

Session key

symmetric key that is only used for the duration of a single communication session

49
New cards

Certificate authority (CA)

issues, renews, revokes, and distributes digital certificates

50
New cards

Registration authority (RA)

verifies identity of a digital certificate applicant

51
New cards

Certificate repository (CR) or central directory

stores digital certificates issues by a CA

52
New cards

Certificate policy (CP)

defines structure of PKI, describes a PKIs entities and roles, and specifies a PKIs procedures and operational requirements

53
New cards

Certificate practice statement (CPS)

describes how a CA issues, renews, revokes, and distributes certificates

54
New cards

Digital Signature Algorithm (DSA)

based on the ElGamal public key cryptography

55
New cards

RSA digital signature algorithm

Based on the RSA public key cryptography

56
New cards

Elliptic curve digital signature algorithms (ECDSA)

based on the elliptic curve public cryptography

57
New cards

domain validation (DV) certificate

only verifies identity of a domains owner

58
New cards

domain extended validation (EV) certificate

verifies the identity of a domains owner, the domain owners exclusive control over the domain

59
New cards

wildcard

certifcate validates a domain and all domains subdomains

60
New cards

subject alternative name (SAN) certificate

used by multiple domains owned by the same domain owner

61
New cards

Root certificate

created and self signed by a certificate authority

62
New cards

code signing certificate

used by a software developer, or software publisher, to digitally sign software programse

63
New cards

email certifcate

used by an email user to digitally sign emails

64
New cards

machine certificate or computer certificate

issues to a hardware device such as a computer, router, or printer

65
New cards

TLS certificate

used by a web server and a web client to establish a secure connection over a network

66
New cards

privacy enhanced mail (PEM)

ASCII format

defines methods for encoding binary data using base64

67
New cards

Base 64

binary text-to-text encoding scheme that represents binary data in an ASCII string format

68
New cards

Distinguished encoding rules (DER)

binary format

subset of the abstract syntax notation one (ASN.1) which is a platform independent encoding format

69
New cards

personal information exchange (PFX)

binary format

password protected archive file format that contains the certificate and the corresponding private key

70
New cards

Key escrow

refers to the secure storage and managment of cryptographic keys by a trusted third party known as an escrow agent

71
New cards

Secure real time transport protocol (SRTP)

secure delivery of voice and video services over an IP network

provides integrity, authentication, and confidentiality

uses AES and HMAC-MD5

72
New cards

Lightweight Directory Access Protocol (LDAP)

protocol for accessing and maintaining distributed directory information services over an IP network

Uses port 636

73
New cards

LDAPS

protocol for accessing and maintaining distributed directory information services securely over an IP network that uses SSL/TLS

used for securely sharing information about a user

74
New cards

LDAP injection attack

attach in which an attacker exploits input validation vulnerabilities to construct and execute an LDAP query

75
New cards

Post Office Protocol (POP)

used by an email client to retrieve an email from a mail server

uses port 110

76
New cards

POPS

uses SSL/TLS to secure communications between a PAP client and a POP server

uses port 995

77
New cards

POP server

receives and stores emails in a users mailbox

78
New cards

POP client

retrieves an email from a POP server

79
New cards

Internet message access protocol (IMAP)

protocol used by an email client to retrieve an email from a mail server

uses TCP port 143

80
New cards

Multipurpose Internet Mail extensions (MIME)

Standard that extends the format of an email message to support non-ASCII character sets and multimedia attachemnts

81
New cards

Multipurpose internet Mail extensions (S/MIME)

internet standard for signing and encrypting MIME data

provides authentication, integrity, non-repudiation, and confidentiality security services for electronic messaging application

82
New cards

site to site VPN/ router-to-router VPN

a connection between two or more networks

used to connect different locations of the same organization

83
New cards

Client to site VPN/remote access VPN

connection between a client computer and a remote router

84
New cards

Full tunnel

routes and encrypts all network traffic through the VPN, regardless of where the VPN service is hosted

recommended and more secure

85
New cards

Split tunnel

routes and encrypts all non-internet network traffic over the VPN

Separates by both app and URL

86
New cards

IPSec

protocol suite for securing data communications over an IP network

87
New cards

Layer 2 tunneling protocol (L2TP)

mechanism for setting up a VPN tunnels at the data link layer

does not provide encrpytion by default and is typically used in conjuction with IPSec

88
New cards

Sender policy framework (SPF)

email authentication method that ensures the sending mail server is authorized to send emails from the senders domain

89
New cards

DomainKeys identified mail (DKIM)

an email authentication method that uses digital signatures to verify that an email was sent and authorized by the owner of the sending domain

90
New cards

Domain based message authentication, reporting, and conformance (DMARC)

email authentication protocol that secures email communications by verifying sender identities, specifying actions for authentication failures, and providing reports on email delivery and integritye

91
New cards

email gateway

server that processes an organization incoming and outgoing email to protect the organizations internal servers

92
New cards

Digital ledger

electronic system or database used to record and track transactions

93
New cards

Blockchain

decentralized and distributed digital ledger that records and links transactions across a network of computers


Chain of blocks linked by cryptographic hashes

94
New cards

Open public ledger

transparent record keeping system that is accessible to the public, enabling anyone to verify recorded transactions

95
New cards

Merkle tree

hierarchical data structure used for verifying the integrity of large data sets

96
New cards

Merkle path

the sequence of nodes connecting a data element to the root

97
New cards

Proof of work (POW)

blockchain consensus algorithm that requires network participants to perform a computationally intensive task, known as mining

98
New cards

Proof of Authority (POA)

blockchain consensus algorithm where validators are chosen based on the validators identity and reputation

99
New cards

Proof of stake (POS)

blockchain consensus algorithm that selects a network participant to create a new block based on the amount of assets the participant holds and is willing to stake

100
New cards

Authentication header (AH)

IPSec protocol that provides authentication and integrity for an IP packet