1/47
Looks like no tags are added yet.
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai | Chat |
|---|
No analytics yet
Send a link to your students to track their progress
What is cryptography?
The act or art of writing in secret characters.
What is cryptanalysis?
The analysis and deciphering of secret writings.
What is cryptology?
The scientific study of cryptography and cryptanalysis.
What is encryption?
A method for encoding messages.
What is decryption?
A method for decoding messages.
What is plaintext?
An unencrypted message; data in the clear.
What is ciphertext?
An encrypted message.
What does c = e_k(m) mean?
Plaintext m is encrypted by encryption function e under secret key k to produce ciphertext c.
What does m = d_k(c) mean?
Ciphertext c is decrypted by decryption function d under key k to recover plaintext m.
In the basic symmetric encryption model, what must both communicating parties know?
The secret key k.
Who are Alice and Bob in cryptography examples?
Two parties who want to communicate securely.
Who is Eve in cryptography examples?
An eavesdropper/adversary who wants to listen to or modify communication.
Why must a cryptographic keyspace be large?
To make exhaustive or brute-force key search impractical.
What worst-case knowledge should we assume an attacker may have?
Full knowledge of the cipher algorithm and some plaintext/ciphertext pairs associated with the target key.
State Kerckhoff's Principle.
A cryptosystem should remain secure even if the algorithm is known, as long as the key remains secret.
What is a passive attack?
An attack where information is accessed but not modified.
What is an active attack?
An attack where information or the system is modified.
What is a ciphertext-only attack?
An attack where the adversary knows only ciphertext.
What is a known-plaintext attack?
An attack where the adversary knows some plaintext and its corresponding ciphertext.
What is a chosen-plaintext attack?
An attack where the adversary can choose plaintext and obtain its encryption.
What is a chosen-ciphertext attack?
An attack where the adversary can choose ciphertext and obtain its decryption.
What is a dictionary attack?
An attack where the adversary builds a dictionary of ciphertexts and corresponding plaintexts.
What is a brute-force attack?
Trying all possible keys in an attempt to determine the correct key.
What is a security mechanism?
A mechanism that detects, prevents, or recovers from an attack.
What is a secure system, according to the notes?
A system in which known threats have been considered and suitable security mechanisms have been incorporated to prevent successful attacks.
What is a trusted component?
A component assumed to behave correctly.
What general rule should be followed for trusted components?
Keep the number of trusted components as small as possible.
What does privacy concern?
The appropriate collection, use, sharing, and control of information about individuals.
What does encryption hide in a privacy context?
The content of data, but not necessarily who is communicating, when, or how often.
What does access control do?
Restricts who may use data.
What is pseudonymisation?
Replacing real identities with substitute identifiers.
Why can cryptography alone not guarantee privacy?
Because authorised parties may still misuse information.
What is a security policy?
The set of rules and decisions defining threats, trusted components, security mechanisms, procedures, review, and audit for a system.
A system is secure relative to what?
The security policy it enforces.
What does the CIA triad stand for?
Confidentiality, Integrity, Availability.
What is confidentiality?
Keeping information secret from those not entitled to see it.
What is integrity?
Ensuring that information has not been altered.
What is availability?
Ensuring that information can be accessed in an appropriate time-frame.
What kind of attack is closely related to availability?
Denial of Service (DoS).
What is entity authentication?
Ensuring that the purported identity of an entity is correct.
What is message authentication?
Ensuring that the purported source of information is correct.
What is non-repudiation?
Ensuring that an entity cannot deny a previous action.
How does privacy differ from confidentiality?
Confidentiality protects content from unauthorised access; privacy is wider and concerns what can be linked about a person over time.
How does trust differ from integrity?
Integrity concerns whether data was altered; trust concerns the expectation that an entity behaves correctly.
Name the five types of security listed in the notes.
Physical security, secrecy, personnel security, IT security, and cryptographic security.
Why is perfect security generally impossible for real systems?
Security mechanisms have limited applicability and costs, threats evolve, and absolute security usually cannot be demonstrated.
What is a security protocol?
A description of how legitimate entities should interact to achieve stated security objectives despite attacks.
Is cryptography alone sufficient for network security?
No. Cryptography is necessary, but other forms of security are also required.