1/30
Midterm topic
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai | Chat |
|---|
No analytics yet
Send a link to your students to track their progress
Cryptology
Science of encryption; encompasses cryptography and cryptanalysis
Cryptography
Involves making and using codes to secure messages
Cryptanalysis
Involves cracking or breaking encrypted messages back into their unencrypted origins
Plain Text
Readable original data accessible to both humans and computers
Anyone intercepting this can read sensitive information
Cipher Text
This is encrypted unreadable data, appearing as random, unreadable characters
Accessible with the correct decryption key
Subsitution Cipher
Exchanges one value for another
Monoalphabetic substitution: Uses only 1 alphabet during encryption process
Polyalphabetic substitution: Uses 2 or more alphabets
Vigenere cipher: Uses simple polyalphabetic code; made up of 26 distinct cipher alphabets
Transposition Cipher
Simple to understand, but if properly used, produces ciphertext that is difficult to decipher
Rearranges values within a block to create ciphertext
Can be done at the bit level or at the byte (char) level
To make the encryption even stronger, the keys and block sizes can be increased to 128 bits or more
Exclusive OR (XOR)
Function of Boolean algebra; 2 bits are compared and binary result is generated.
- If two bits are identical, the result is binary 0
- If two bits are not identical, the result is binary 1
Very simple to implement and simple to break; should not be used by itself when organization is transmitting/storing sensitive data
Vernam Cipher
Uses a set of characters once per encryption process
Developed at AT&T Bell Labs
Book-Based Ciphers
Uses text in book as key to decrypt a message
Book Cipher
(Book-based ciphers)
Ciphertext consist of a list of codes representing page, line, and word numbers of plaintext word
Running Key Cipher
(Book-based ciphers)
Uses a book for passing key to cipher similar to Vigenere cipher;
sende provides encrypted message with sequence of numbers from predetermined book to be used as an indicator block
Template Cipher
(Book-based ciphers)
Involves use of hidden message in book, letter, or other message; requires page with specific number of holes cut into it
Hash Functions
Mathematical algorithms used to confirm specific message identity and that no content has changed
Hash Algorithms: Public functions that create hash value
Used in password verification systems to confirm the identity of the user
Symmetric Encryption
(Cryptographic Algorithms)
Requires same “secret key” to encipher and decipher message; known as private-key encryption
Both sender and receiver must possess secret key
If either copy of key is compromised, an intermediate can decrypt and read messages without sender/receiver knowledge
Advanced Encryption Standard (AES) > Triple DES (3DES) > Data Encryption Standard (DES)

Asymmetric Encryption
(Cryptographic Algorithms)
Also known as public-key encryption
Uses 2 different but related keys
Either key can encrypt or decrypt a message
If key A encrypts a message, only key B can decrypt

Public-Key Infrastructure (PKI)
Integrated system of software, encryption methodologies, protocols, legal agreements, and 3rd party services enabling users to communicate securely
Is based on public-key cryptosystems
Protects information and assets in several ways: Authentication, Integrity, Privacy, Authorization, Nonrepudiation
Digital Signatures
Created in response to rising the need to verify information transferred via electronic systems
Asymmetric encryption processes used to create digital signatures
Digital Certificates
Electronic document/container file containing key value and identifying information about entity that controls key
Digital signature attached to certificate’s container file certifies file’s origin and integrity
Different client-server applications use different types of digital certificates to accomplish their assigned functions
Distinguished name (DN): uniquely identifies a certificate entity
Hybrid Cryptography Systems
Except w/ digital certificates, pure asymmetric key encryption is not widely used
Asymmetric encryption is more often used with symmetric key encryption, as part of a hybrid system
Diffie-Hellman Key Exchange method

Steganography
“Art of secret writing”; has been used for centuries
Most popular modern version hides information within files that contain digital pictures or other images
Some apps hide messages in .bmp, .wav, .mp3, and .au files, as well as in unused space on CDs and DVDs
Secure Sockets Layer (SSL)
(Protocols for Secure Communications - Internet)
Uses public key encryption to secure channel over public internet
Hypertext Transfer Protocol Secure (HTTPS)
(Protocols for Secure Communications - Internet)
Provides encryption of individual messages between client and server across internet
Extension of HTTP
Secure Multipurpose Internet Mail Extensions (S/MIME)
(Protocols for Secure Communications - Email)
Builds on MIME encoding format and uses digital signatures based on public-key cryptosystems
Privacy Enhanced Mail (PEM)
(Protocols for Secure Communications - Email)
Proposed as standard to use 3DES symmetric key encryption and RSA for key exchanges and digital signatures
Pretty Good Privacy (PGP)
(Protocols for Secure Communications - Email)
Uses IDEA Cipher for message encoding
Secure Electronic Transactions (SET)
(Protocols for Secure Communications - Web Transactions)
Developed by MasterCard and VISA in 1997 to protect against electronic payment fraud
Uses DES to encrypt credit card info transfers
Provides security for both internet-based credit card transactions and credit card swipe systems in retail stores
WiFi Protected Access (WPA and WPA2)
(Protocols for Secure Communications - Wireless Networks)
Better and improved version of Wired Equivalent Privacy (WEP) and resolve its issues
Internet Protocol Security
An open-source protocol framework for security development within the TCP/IP family of protocol standards
TRUE
Strength of encryption tool is dependent on the key size but even more dependent on following good management practices.
TRUE
Cryptography is used to secure most aspects of Internet and Web uses that require it, drawing on extensive set of protocols and tools designed for that purpose.