ECES

0.0(0)
Studied by 7 people
call kaiCall Kai
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/157

flashcard set

Earn XP

Description and Tags

EC-Council Certified Encryption Specialist

Last updated 6:50 PM on 10/1/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai
Chat

No analytics yet

Send a link to your students to track their progress

158 Terms

1
New cards

atbash cipher

substitute the first letter with the last, the second with the second to last and so on.

2
New cards

affine cipher

E(x)=(a*x+b) mod m

3
New cards

cryptography

the process or skill of communicating in or deciphering secret writings or ciphers

4
New cards

kryptos

hidden

5
New cards

grafo

write

6
New cards

symmetric cryptography

any algorithm where the key used to decrypt a message is the same key that was used to encrypt it.

7
New cards

entropy

the amount of info in a given message

8
New cards

hamming distance

the number of characters (or bits) that are different between two strings. This can be expressed mathematically as h(x,y)

9
New cards

diffusion

means having changes to one character in the plaintext affect multiple characters in the ciphertext

10
New cards

confusion

attempts to make the relationship between the statistical frequencies of the cipher text and the actual key as complex as possible.

  • Occurs by using a complex substitution algorithm.


11
New cards

avalanche

means a small change yields large effects in the output

12
New cards

kerckhoff’s principle

a cryptosystem should be secure even if everything about the system, except the key, is publicly known.

13
New cards

transposition

the swapping of blocks of ciphertext

14
New cards

block cipher

divides data into blocks (often 64 bit blocks, but newer algorithms sometimes use 128-bit blocks (AES-128)) and encrypts the data one block at a time.

15
New cards

stream cipher

encrypts the data as a stream of bits, one bit at a time.

16
New cards

key

the random bits used in encrypting a message

17
New cards

key space

refers to the number of possible keys, the set of possible keys for a given algorithm

  • EX: DES uses a 56-bit key so it has a ____ of 2^56k


18
New cards

key schedule

refers to the generation of subkeys from a single key

19
New cards

algorithm

the mathematical process used to alter a message and read it unintelligible by any but the intended party.

20
New cards

cipher

the algorithms needed to encrypt and decrypt a message

21
New cards

collision

refers to a situation where two different inputs yield the same result

22
New cards

salt

refers to random bits that are used as one of the inputs to the hash.

23
New cards

SHA-1

160-bit hash function which resembles the earlier MD5 algorithm

24
New cards

SHA-2

SHA512 — uses 64-byte (512 bit) words

SHA256 — uses 32-byte (256 bit) words

25
New cards

information theory

was developed by claude shannon in 1948 with the publication of his article “A mathematical theory of communication”

26
New cards

shannons source coding theorem

it is impossible to compress the data such that the code rate is less than the shannon entropy of the source, without it being virtually certain that information will be lost.

27
New cards

N (natural numbers)

1, 2, 3, etc

28
New cards

Z (integers)

whole numbers (-1, 0, 1, 2, 3, etc)

29
New cards

Q (rational numbers)

ratio of integers (3/2, 1/4, 1/2, etc)

30
New cards

R (real numbers)

includes rational numbers as well as numbers that cannot be expressed as a ratio of two integers

31
New cards

i (imaginary numbers)

numbers whose square is a negative

32
New cards

prime numbers

if a random number n is selected, the chance of it being ___ is approximately 1/ln(n) where ln(n) denotes the natural logarithm of n.

33
New cards

mersenne primes

Mn=2^n - 1 (not all prime)

34
New cards

fermat numbers

Fn = 2²n + 1 (not all prime)

35
New cards

co-prime numbers

a number that has no factors in common with another number (ex: 3 and 7)

36
New cards

eulers totient

the number of positive integers less than or equal to n that are co-prime to n.

37
New cards

group

an algebraic system consisting of a set, an identity element, one operation and its inverse operation

38
New cards

ring

an algebraic system consisting of a set, an identity element, two operations, and the inverse operation of the first operation.

39
New cards

field

an algebraic system system consisting of a set, an identity element for each operation, two operations, and their respective inverse operations.

  • Every ____ is a ring, but not every ring is a ____


40
New cards

birthday paradox

the probability that two or more people in a group of 23 share the same birthday is greater than ½

41
New cards

birthday attack

attempt to find a collision for a given hash.

42
New cards

PRNG (pseudo random number generator)

algorithms that create long runs of numbers with good random properties, but eventually the sequence repeats.

43
New cards

K1

a sequence of random numbers with a low probability of containing identical consecutive elements.

44
New cards

K2

a sequence of numbers which is indistinguishable from true random numbers according to specified statistical tests.

45
New cards

K3

it should be impossible for any attacker to calculate or otherwise guess from any given sub-sequence any previous or future values in the sequence

46
New cards

K4

it should be impossible for an attacker to guess or calculate from an inner state of the generator any previous numbers in the sequence or any previous inner generator states.

47
New cards

blum blum shub

proposed in 1986 by Lenore Blum, Manuel Blum, and Michael Shub, X n+1 = Xn²mod M

48
New cards

diffie hellman

  • cryptographic protocol that allows two parties to establish a shared key over an insecure channel.

  • Developed and published by whitfield diffie and martin hellman in 1976

    • first publicly described asymmetric algorithm


49
New cards

RSA (Rivest Shamir Adleman)

  • Perhaps the most widely used public key cryptography algorithm in existence

    • publicly described in 1977 by Ron Rivest, Adi Shamir, and Leonard Adleman at MIT


50
New cards

MQV (Menezes-Qu-Vanstone)

  • protocol for key agreement that is based on diffie-hellman

  • first proposed by menezes, qu, and vanstone in 1995, modified in 1998

    • incorporated in the public key standard IEEE P1363


51
New cards

DSA (Digital Signature Algorithm)

described in US patent 5,231,668 filed July, 26th 1991 and attributed to David W. Kravitz. It was adapted by the US govt in 1993 with FIPS 186

52
New cards

elliptic curve

  • first described by victor miller and neil koblitz

    • security is based on the fact that finding the discrete logarithm of a random _______ element with respect to a publicly known basepoint is difficult to do,


53
New cards

elgamal

  • based on diffie-hellman, invented in 1984 by Taher Elgamal

  • used in some pgp implementations and GNU privacy guard software

    • consists of 3 parts: key generator, encryption algorithm, and decryption algorithm.


54
New cards

cramer-shoup

  • Asymmetric key encryption algorithm

  • developed by ronald cramer and victor shoup in 1998

    • first efficient algorithm proven to be secure against adaptive chosen cipher text attack.


55
New cards

PFS (perfect forward secrecy)

an encryption system has this property if plain-text (decrypted) inspection of the data exchange that occurs during the key agreement phase of session initiation does not reveal the key that was used to encrypt the remainder of the session.

  • coined by C.G. gunther in 1990


56
New cards

FIPS140

cryptographic modules, defines 4 security levels.

57
New cards

FIPS197

AES

58
New cards

FIPS186

digital signatures

59
New cards

FIPS201

identity verification

60
New cards

digital certificate

a digital document that contains a public key and some information to allow your system to verify where the key came from.

61
New cards

PKCS (Public Key Cryptography System)

are in place by RSA to ensure uniform certificate management throughout the internet

62
New cards

CA (Certificate Authority)

Is an entity trusted by one or more users to manage certificates

63
New cards

RA (Registration Authority)

Acts as a proxy between user and CA. ____ receives request, authenticates it and forwards it to the CA.

64
New cards

x.509

  • International standard for the format and information contained in a digital certificate.

  • Most common type of digital certificate.

  • First issued on July 3rd 1988

  • Relied on by S/MIME


65
New cards

.pem (privacy enhanced mail)

Base64 encoded DER certificate

66
New cards

.cer .crt .der

usually in binary DER form, but Base64 encoded certificates are common to see.

67
New cards

.p7b .p7c

PKCS#7 signedData structure without data, just certificates or CRLs

68
New cards

.p12

PKCS#12 may contain certificates public and private keys (password protected)

69
New cards

OCSP (Online Certificate Status Protocol)

Real time protocol for verifying certificates

70
New cards

PAP (Password Authentication Protocol)

  • Most basic form of authentication

    • transmissions of passwords are in clear text, unencrypted


71
New cards

S-PAP (Shiva Password Authentication Protocol)

  • Proprietary version of PAP

  • Username and password are sent encrypted


72
New cards

CHAP (Challenge-Handshake Authentication Protocol)

Calculates a hash after the user has logged in, then it shares that hash with the client system. Periodically, the server will ask the client to provide the hash (this is the challenge) if the client cannot, then its clear that communications have been compromised.

73
New cards

LEAP (Lightweight Extensible Authentication Protocol)

Developed by Cisco, supported by Microsoft, uses a modified version of MS-CHAP

74
New cards

EAP (Extensible Authentication Protocol)

  • Uses TLS in order to secure the authentication protocol

  • Most implementations utilize x.509 certificates to authenticate


75
New cards

PEAP (Protected Extensible Authentication Protocol)

Encrypts the authentication process with an authenticated TLS tunnel

76
New cards

principal

a server or client that kerberos can assign tickets to.

77
New cards

AS (Authentication Server)

A server that authorizes the principal and connects them to the ticket granting server.

78
New cards

TGS (Ticket Granting Service)

Provides tickets

79
New cards

KDC (Key Distribution Center)

A server that provides the initial ticket and handles TGS requests

80
New cards

Realm

Boundary within an organization, each has its own AS and TGS.

81
New cards

RTGS (Remote Ticket Granting Service)

A TGS in a remote realm

82
New cards

TGT (Ticket Granting Ticket)

The ticket that is granted during the authentication process.

83
New cards

Ticket

Used to authenticate to the server. Contains identity of the client, session key, timestamp, and checksum. Encrypted with servers key.

84
New cards

Session key

Temporary encryption key

85
New cards

Authenticator

Proves session key was recently created. Often expires within 5 minutes.

  • Kerberos uses symmetric cryptography

  • _____ is UDP port 88


86
New cards

PGP Certificates Include

  • ____ version number

  • certificate holders public key

  • certificate holders information

  • digital signature of certificate owner

  • certificates validity period

  • preferred symmetric encryption algorithm for the key


87
New cards

WEP (Wired Equivalent Privacy)

Uses the stream cipher RC4 (64-bit or 128-bit)

88
New cards

WPA-PSK (WPA Personal)

Designed for SOHO networks, doesn’t require AS, authenticates with a 256-bit key

89
New cards

WPA-802.1x (WPA-Enterprise)

Requires a RADIUS server, EAP is used for authentication.

90
New cards

WPA2

  • Based on the 802.11i standard

  • uses AES, CBC (Cipher Block Chaining), MAC and CCMP

  • Optional use of pairwise master key (PMK)

  • Optional use of pre-authentication


91
New cards

SSL (Secure Sockets Layer)

Developed by Netscape and has since been supplanted by TLS.

92
New cards

TLS

Protocol for encrypting transmissions, client and server negotiate a connection by using a handshake procedure.

93
New cards

Handshake Protocol

Establishes all the features of the connection

94
New cards

TLS Record Protocol

Provides confidentiality and integrity

95
New cards

PPTP (Point to Point Tunneling Protocol)

Proposed as a standard in 1996, designed as a secure extension to PPP

  • Adds features of encrypting packets (EAP) and authenticating users (CHAP)


96
New cards

L2TP (Layer 2 Tunneling Protocol)

  • Offers 5 methods for authentication

  • Works over x.25 networks (phone system protocol) and ATM (High speed networking technology)

  • Uses IPsec for encryption


97
New cards

IPSec

Encrypts not only the packet data, but also the header information.

  • Provides transport and tunnel mode


98
New cards

AH (Authentication Header)

Provides a method for authentication only. IP port 51

99
New cards

ESP (Encapsulating Security Payload)

Provides data confidentiality and authentication, port 50.

100
New cards

SA (Security Associations)

Provide the parameters necessary for AH and/or ESP operations.