Untitled

Cryptography for Secure Communication

Overview

  • Course Title: Cryptography for Secure Communication

  • Course Code: 6COSC019W - Cyber Security

  • Instructor: Usama Arusi

  • Preparation: Dr. Ayman El Hajjar

  • Date: March 16, 2026

  • Institution: University of Westminster

  • Topics Covered:

    1. Security Controls

    2. Application Layer Controls

    3. Host to Host/Transport Layer Controls

    4. Network Layer Controls

Security Control

  • Definition:

    • "Control is an action, device, procedure, or other measure that reduces risk by eliminating or preventing a security violation, minimizing the harm it can cause, or by discovering and reporting it to enable corrective action."

  • Purpose: To manage risks associated with security violations in IT and information systems.

Control Classifications

  • Major Types of Security Controls:

    1. Management Controls

    • Focus on security policies, planning, guidelines, and standards.

    • Aims to influence the selection of operational and technical controls.

    • Address issues that management needs to oversee to reduce risks and protect the organization's mission.

    1. Operational Controls

    • Ensure the proper implementation and use of security policies and standards.

    • Aim for consistency in security operations and corrective actions for identified operational deficiencies.

    • Primarily involve human mechanisms and procedures rather than systems.

    1. Technical Controls

    • Involve the appropriate use of hardware and software security capabilities.

    • Ranges from simple security measures to complex ones designed to protect sensitive data and information systems.

Control Classes

  • Types of Controls:

    • Supportive Controls:

    • Pervasive, generic technical IT security capabilities that support other controls.

    • Preventative Controls:

    • Focus on preventing security breaches by inhibiting attempts to violate security policies or exploit vulnerabilities.

    • Detection and Recovery Controls:

    • Focus on responses to security breaches by alerting violations and providing recovery means for lost resources.

Technical Controls

  • Example: TCP/IP Security Solutions

    • Various security protocols can be utilized for secure communication at different TCP/IP stack layers.

    • Often, multiple protocols are combined across layers to enhance communication protection.

Protocols by Layer
  1. Application Layer

    • Protocols:

      • SSH

      • DNSSEC

      • S/MIME

      • PGP

      • HTTP with Transport Layer Security (TLS)

  2. Transport Layer

    • Protocol: TLS

  3. Network Layer

    • Protocol: IPSec

  4. Physical Layer

Secure/Multipurpose Internet Mail Extension (S/MIME)

  • Description:

    • Security enhancement for the Multipurpose Internet Mail Extension (MIME) used in email.

    • Utilizes technology from RSA Data Security.

    • Provides capability to sign and/or encrypt email messages.

    • Based on centralized Public Key Infrastructure (PKI) with certificates from trusted Certificate Authorities (CAs).

    • Predominantly used in corporate email systems.

    • Supported by email clients like Outlook, Thunderbird, and Apple Mail.

S/MIME Functions
  1. Enveloped Data:

    • Contains encrypted content and keys for recipients.

  2. Signed Data:

    • Encoded message plus signed digest that is encrypted with the sender's private key and base64 encoded.

  3. Clear-Signed Data:

    • Allows readable content with a base64 encoded signature, enabling non-S/MIME recipients to read content, but not verify it.

  4. Signed & Enveloped:

    • Signed-only and encrypted-only entities can be nested, allowing for diverse configurations in signing and encryption.

S/MIME Functional Flow
  1. Message Signing:

    • Hash using RSA or SHA-256.

    • Encrypt using sender's private key.

  2. Message Encryption:

    • Encrypt with a symmetric key (e.g., AES128/CBC) which is encrypted using the receiver's public key.

  3. Decryption:

    • Receiver's private key decrypts the symmetric key then data using the symmetric key.

  4. Signature Verification:

    • The sender's public key validates the signature.

Pretty Good Privacy (PGP)

  • Description:

    • A popular program for encrypting and decrypting emails and files.

    • Operates on a web-of-trust model requiring users to manually verify and trust each other’s keys.

    • Implements a Public-Private Key (PPK) methodology.

PGP Process Overview
  1. Key Generation:

    • Random key generated for encryption.

  2. Data Encryption:

    • Data is encrypted using the random key.

  3. Key Encryption:

    • The random key is encrypted with the recipient’s public key.

  4. Message Delivery:

    • The encrypted random key and message are concatenated for transmission.

  5. Decryption by Recipient:

    • Receiver decrypts the random key with their private key then uses it to decrypt data.

DNS Security

  • Threats and Prevention:

    • To combat DNS Hijacking and DNS Pharming, DNS Security (DNSSEC) is utilized.

    • Its objectives include:

    • Authenticating the DNS answer origin.

    • Ensuring integrity of replies.

    • Authenticating denial of existence.

    • Achieved through signing DNS replies and utilizing public-key cryptography.

Secure Shell (SSH)

  • Overview:

    • A secure network communications protocol, designed for easy implementation.

    • The original version (SSH1) focused on secure remote logon, while SSH2 expanded capabilities such as file transfer and secure shell tunneling.

    • Widely available across operating systems and fixes many security flaws that existed in earlier versions.

SSH Protocol Stack
  • Comprising the following protocols:

    • SSH User Authentication Protocol:

    • Authenticates the client-side user to the server.

    • SSH Connection Protocol:

    • Multiplexes the encrypted tunnel into several logical channels.

    • SSH Transport Layer Protocol:

    • Ensures server authentication, confidentiality, and integrity.

Steps of SSH Protocol Communication
  1. TCP Connection Establishment:

    • Begins with a TCP connection to the server prior to SSH Transport Layer Protocol initialization.

  2. Secure Connection Establishment:

    • SSH Transport Layer Protocol is applied to authenticate and secure data transfer.

SSH Handshake Phases
  1. Identification String Exchange Phase:

    • Both the client and server exchange their identification strings.

  2. Key Algorithm Negotiation Phase:

    • Client and server agree on cryptographic algorithms for the session.

  3. Key Exchange Phase:

    • Client generates a random key to be encrypted using the server's public key.

  4. Secure Communication Begin:

    • The client sends an encrypted message using the session key.

Transport Layer Security (TLS)

  • Description:

    • A prevalent security service utilizing public key infrastructure (PKI) and certificates.

TLS Components
  1. TLS Handshake Protocol:

    • Series of messages exchanged to set up secure communication parameters (most complex component).

  2. TLS Record Protocol:

    • Ensures confidentiality and integrity of transmitted data.

TLS Handshake Keys Exchange Sequence
  1. Exchange:

    • Client Hello, Server Hello, Certificate exchanges, Key exchanges, Change Cipher Spec, Finished messages.

HTTP Secure (HTTPS)

  • Definition:

    • HTTPS is the secure version of HTTP, incorporating TLS for encrypting data transport to prevent eavesdropping, tampering, and forgery.

IP Security (IPsec)

  • Rationale:

    • Protects IP traffic as it lacks inherent encryption, ensuring confidentiality, integrity, and authenticity during transmission.

Applications of IPsec
  • Secure communications across various networks.

  • Examples include establishing remote access, intranet connectivity, and e-commerce security.

Features of IPsec
  1. Authentication Mechanism:

    • Verifies received packet sources ensuring non-alteration.

  2. Confidentiality Facility:

    • Encrypts messages to avoid eavesdropping.

  3. Key Management Facility:

    • Secure exchange of cryptographic keys.

Modes of IPsec
  1. Transport Mode:

    • Extends to the payload of IP packets for end-to-end communication.

    • Encrypts IP payload but not the IP header.

  2. Tunnel Mode:

    • Protects entire IP packets, useful for secure gateways to shield multiple hosts.

Benefits of IPsec
  • Strong perimeter security, resistance to bypass, transparency, and ability to secure individual users.

References

  • Lecture notes compiled by Dr. Ayman El Hajjar from personal notes and various sources.

  • Recommended readings include Chapter 9 from Computer Security Fundamentals focusing on topics covered in the course.