1/157
EC-Council Certified Encryption Specialist
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai | Chat |
|---|
No analytics yet
Send a link to your students to track their progress
atbash cipher
substitute the first letter with the last, the second with the second to last and so on.
affine cipher
E(x)=(a*x+b) mod m
cryptography
the process or skill of communicating in or deciphering secret writings or ciphers
kryptos
hidden
grafo
write
symmetric cryptography
any algorithm where the key used to decrypt a message is the same key that was used to encrypt it.
entropy
the amount of info in a given message
hamming distance
the number of characters (or bits) that are different between two strings. This can be expressed mathematically as h(x,y)
diffusion
means having changes to one character in the plaintext affect multiple characters in the ciphertext
confusion
attempts to make the relationship between the statistical frequencies of the cipher text and the actual key as complex as possible.
Occurs by using a complex substitution algorithm.
avalanche
means a small change yields large effects in the output
kerckhoff’s principle
a cryptosystem should be secure even if everything about the system, except the key, is publicly known.
transposition
the swapping of blocks of ciphertext
block cipher
divides data into blocks (often 64 bit blocks, but newer algorithms sometimes use 128-bit blocks (AES-128)) and encrypts the data one block at a time.
stream cipher
encrypts the data as a stream of bits, one bit at a time.
key
the random bits used in encrypting a message
key space
refers to the number of possible keys, the set of possible keys for a given algorithm
EX: DES uses a 56-bit key so it has a ____ of 2^56k
key schedule
refers to the generation of subkeys from a single key
algorithm
the mathematical process used to alter a message and read it unintelligible by any but the intended party.
cipher
the algorithms needed to encrypt and decrypt a message
collision
refers to a situation where two different inputs yield the same result
salt
refers to random bits that are used as one of the inputs to the hash.
SHA-1
160-bit hash function which resembles the earlier MD5 algorithm
SHA-2
SHA512 — uses 64-byte (512 bit) words
SHA256 — uses 32-byte (256 bit) words
information theory
was developed by claude shannon in 1948 with the publication of his article “A mathematical theory of communication”
shannons source coding theorem
it is impossible to compress the data such that the code rate is less than the shannon entropy of the source, without it being virtually certain that information will be lost.
N (natural numbers)
1, 2, 3, etc
Z (integers)
whole numbers (-1, 0, 1, 2, 3, etc)
Q (rational numbers)
ratio of integers (3/2, 1/4, 1/2, etc)
R (real numbers)
includes rational numbers as well as numbers that cannot be expressed as a ratio of two integers
i (imaginary numbers)
numbers whose square is a negative
prime numbers
if a random number n is selected, the chance of it being ___ is approximately 1/ln(n) where ln(n) denotes the natural logarithm of n.
mersenne primes
Mn=2^n - 1 (not all prime)
fermat numbers
Fn = 2²n + 1 (not all prime)
co-prime numbers
a number that has no factors in common with another number (ex: 3 and 7)
eulers totient
the number of positive integers less than or equal to n that are co-prime to n.
group
an algebraic system consisting of a set, an identity element, one operation and its inverse operation
ring
an algebraic system consisting of a set, an identity element, two operations, and the inverse operation of the first operation.
field
an algebraic system system consisting of a set, an identity element for each operation, two operations, and their respective inverse operations.
Every ____ is a ring, but not every ring is a ____
birthday paradox
the probability that two or more people in a group of 23 share the same birthday is greater than ½
birthday attack
attempt to find a collision for a given hash.
PRNG (pseudo random number generator)
algorithms that create long runs of numbers with good random properties, but eventually the sequence repeats.
K1
a sequence of random numbers with a low probability of containing identical consecutive elements.
K2
a sequence of numbers which is indistinguishable from true random numbers according to specified statistical tests.
K3
it should be impossible for any attacker to calculate or otherwise guess from any given sub-sequence any previous or future values in the sequence
K4
it should be impossible for an attacker to guess or calculate from an inner state of the generator any previous numbers in the sequence or any previous inner generator states.
blum blum shub
proposed in 1986 by Lenore Blum, Manuel Blum, and Michael Shub, X n+1 = Xn²mod M
diffie hellman
cryptographic protocol that allows two parties to establish a shared key over an insecure channel.
Developed and published by whitfield diffie and martin hellman in 1976
first publicly described asymmetric algorithm
RSA (Rivest Shamir Adleman)
Perhaps the most widely used public key cryptography algorithm in existence
publicly described in 1977 by Ron Rivest, Adi Shamir, and Leonard Adleman at MIT
MQV (Menezes-Qu-Vanstone)
protocol for key agreement that is based on diffie-hellman
first proposed by menezes, qu, and vanstone in 1995, modified in 1998
incorporated in the public key standard IEEE P1363
DSA (Digital Signature Algorithm)
described in US patent 5,231,668 filed July, 26th 1991 and attributed to David W. Kravitz. It was adapted by the US govt in 1993 with FIPS 186
elliptic curve
first described by victor miller and neil koblitz
security is based on the fact that finding the discrete logarithm of a random _______ element with respect to a publicly known basepoint is difficult to do,
elgamal
based on diffie-hellman, invented in 1984 by Taher Elgamal
used in some pgp implementations and GNU privacy guard software
consists of 3 parts: key generator, encryption algorithm, and decryption algorithm.
cramer-shoup
Asymmetric key encryption algorithm
developed by ronald cramer and victor shoup in 1998
first efficient algorithm proven to be secure against adaptive chosen cipher text attack.
PFS (perfect forward secrecy)
an encryption system has this property if plain-text (decrypted) inspection of the data exchange that occurs during the key agreement phase of session initiation does not reveal the key that was used to encrypt the remainder of the session.
coined by C.G. gunther in 1990
FIPS140
cryptographic modules, defines 4 security levels.
FIPS197
AES
FIPS186
digital signatures
FIPS201
identity verification
digital certificate
a digital document that contains a public key and some information to allow your system to verify where the key came from.
PKCS (Public Key Cryptography System)
are in place by RSA to ensure uniform certificate management throughout the internet
CA (Certificate Authority)
Is an entity trusted by one or more users to manage certificates
RA (Registration Authority)
Acts as a proxy between user and CA. ____ receives request, authenticates it and forwards it to the CA.
x.509
International standard for the format and information contained in a digital certificate.
Most common type of digital certificate.
First issued on July 3rd 1988
Relied on by S/MIME
.pem (privacy enhanced mail)
Base64 encoded DER certificate
.cer .crt .der
usually in binary DER form, but Base64 encoded certificates are common to see.
.p7b .p7c
PKCS#7 signedData structure without data, just certificates or CRLs
.p12
PKCS#12 may contain certificates public and private keys (password protected)
OCSP (Online Certificate Status Protocol)
Real time protocol for verifying certificates
PAP (Password Authentication Protocol)
Most basic form of authentication
transmissions of passwords are in clear text, unencrypted
S-PAP (Shiva Password Authentication Protocol)
Proprietary version of PAP
Username and password are sent encrypted
CHAP (Challenge-Handshake Authentication Protocol)
Calculates a hash after the user has logged in, then it shares that hash with the client system. Periodically, the server will ask the client to provide the hash (this is the challenge) if the client cannot, then its clear that communications have been compromised.
LEAP (Lightweight Extensible Authentication Protocol)
Developed by Cisco, supported by Microsoft, uses a modified version of MS-CHAP
EAP (Extensible Authentication Protocol)
Uses TLS in order to secure the authentication protocol
Most implementations utilize x.509 certificates to authenticate
PEAP (Protected Extensible Authentication Protocol)
Encrypts the authentication process with an authenticated TLS tunnel
principal
a server or client that kerberos can assign tickets to.
AS (Authentication Server)
A server that authorizes the principal and connects them to the ticket granting server.
TGS (Ticket Granting Service)
Provides tickets
KDC (Key Distribution Center)
A server that provides the initial ticket and handles TGS requests
Realm
Boundary within an organization, each has its own AS and TGS.
RTGS (Remote Ticket Granting Service)
A TGS in a remote realm
TGT (Ticket Granting Ticket)
The ticket that is granted during the authentication process.
Ticket
Used to authenticate to the server. Contains identity of the client, session key, timestamp, and checksum. Encrypted with servers key.
Session key
Temporary encryption key
Authenticator
Proves session key was recently created. Often expires within 5 minutes.
Kerberos uses symmetric cryptography
_____ is UDP port 88
PGP Certificates Include
____ version number
certificate holders public key
certificate holders information
digital signature of certificate owner
certificates validity period
preferred symmetric encryption algorithm for the key
WEP (Wired Equivalent Privacy)
Uses the stream cipher RC4 (64-bit or 128-bit)
WPA-PSK (WPA Personal)
Designed for SOHO networks, doesn’t require AS, authenticates with a 256-bit key
WPA-802.1x (WPA-Enterprise)
Requires a RADIUS server, EAP is used for authentication.
WPA2
Based on the 802.11i standard
uses AES, CBC (Cipher Block Chaining), MAC and CCMP
Optional use of pairwise master key (PMK)
Optional use of pre-authentication
SSL (Secure Sockets Layer)
Developed by Netscape and has since been supplanted by TLS.
TLS
Protocol for encrypting transmissions, client and server negotiate a connection by using a handshake procedure.
Handshake Protocol
Establishes all the features of the connection
TLS Record Protocol
Provides confidentiality and integrity
PPTP (Point to Point Tunneling Protocol)
Proposed as a standard in 1996, designed as a secure extension to PPP
Adds features of encrypting packets (EAP) and authenticating users (CHAP)
L2TP (Layer 2 Tunneling Protocol)
Offers 5 methods for authentication
Works over x.25 networks (phone system protocol) and ATM (High speed networking technology)
Uses IPsec for encryption
IPSec
Encrypts not only the packet data, but also the header information.
Provides transport and tunnel mode
AH (Authentication Header)
Provides a method for authentication only. IP port 51
ESP (Encapsulating Security Payload)
Provides data confidentiality and authentication, port 50.
SA (Security Associations)
Provide the parameters necessary for AH and/or ESP operations.