Untitled
Cryptography for Secure Communication
Overview
Course Title: Cryptography for Secure Communication
Course Code: 6COSC019W - Cyber Security
Instructor: Usama Arusi
Preparation: Dr. Ayman El Hajjar
Date: March 16, 2026
Institution: University of Westminster
Topics Covered:
Security Controls
Application Layer Controls
Host to Host/Transport Layer Controls
Network Layer Controls
Security Control
Definition:
"Control is an action, device, procedure, or other measure that reduces risk by eliminating or preventing a security violation, minimizing the harm it can cause, or by discovering and reporting it to enable corrective action."
Purpose: To manage risks associated with security violations in IT and information systems.
Control Classifications
Major Types of Security Controls:
Management Controls
Focus on security policies, planning, guidelines, and standards.
Aims to influence the selection of operational and technical controls.
Address issues that management needs to oversee to reduce risks and protect the organization's mission.
Operational Controls
Ensure the proper implementation and use of security policies and standards.
Aim for consistency in security operations and corrective actions for identified operational deficiencies.
Primarily involve human mechanisms and procedures rather than systems.
Technical Controls
Involve the appropriate use of hardware and software security capabilities.
Ranges from simple security measures to complex ones designed to protect sensitive data and information systems.
Control Classes
Types of Controls:
Supportive Controls:
Pervasive, generic technical IT security capabilities that support other controls.
Preventative Controls:
Focus on preventing security breaches by inhibiting attempts to violate security policies or exploit vulnerabilities.
Detection and Recovery Controls:
Focus on responses to security breaches by alerting violations and providing recovery means for lost resources.
Technical Controls
Example: TCP/IP Security Solutions
Various security protocols can be utilized for secure communication at different TCP/IP stack layers.
Often, multiple protocols are combined across layers to enhance communication protection.
Protocols by Layer
Application Layer
Protocols:
SSH
DNSSEC
S/MIME
PGP
HTTP with Transport Layer Security (TLS)
Transport Layer
Protocol: TLS
Network Layer
Protocol: IPSec
Physical Layer
Secure/Multipurpose Internet Mail Extension (S/MIME)
Description:
Security enhancement for the Multipurpose Internet Mail Extension (MIME) used in email.
Utilizes technology from RSA Data Security.
Provides capability to sign and/or encrypt email messages.
Based on centralized Public Key Infrastructure (PKI) with certificates from trusted Certificate Authorities (CAs).
Predominantly used in corporate email systems.
Supported by email clients like Outlook, Thunderbird, and Apple Mail.
S/MIME Functions
Enveloped Data:
Contains encrypted content and keys for recipients.
Signed Data:
Encoded message plus signed digest that is encrypted with the sender's private key and base64 encoded.
Clear-Signed Data:
Allows readable content with a base64 encoded signature, enabling non-S/MIME recipients to read content, but not verify it.
Signed & Enveloped:
Signed-only and encrypted-only entities can be nested, allowing for diverse configurations in signing and encryption.
S/MIME Functional Flow
Message Signing:
Hash using RSA or SHA-256.
Encrypt using sender's private key.
Message Encryption:
Encrypt with a symmetric key (e.g., AES128/CBC) which is encrypted using the receiver's public key.
Decryption:
Receiver's private key decrypts the symmetric key then data using the symmetric key.
Signature Verification:
The sender's public key validates the signature.
Pretty Good Privacy (PGP)
Description:
A popular program for encrypting and decrypting emails and files.
Operates on a web-of-trust model requiring users to manually verify and trust each other’s keys.
Implements a Public-Private Key (PPK) methodology.
PGP Process Overview
Key Generation:
Random key generated for encryption.
Data Encryption:
Data is encrypted using the random key.
Key Encryption:
The random key is encrypted with the recipient’s public key.
Message Delivery:
The encrypted random key and message are concatenated for transmission.
Decryption by Recipient:
Receiver decrypts the random key with their private key then uses it to decrypt data.
DNS Security
Threats and Prevention:
To combat DNS Hijacking and DNS Pharming, DNS Security (DNSSEC) is utilized.
Its objectives include:
Authenticating the DNS answer origin.
Ensuring integrity of replies.
Authenticating denial of existence.
Achieved through signing DNS replies and utilizing public-key cryptography.
Secure Shell (SSH)
Overview:
A secure network communications protocol, designed for easy implementation.
The original version (SSH1) focused on secure remote logon, while SSH2 expanded capabilities such as file transfer and secure shell tunneling.
Widely available across operating systems and fixes many security flaws that existed in earlier versions.
SSH Protocol Stack
Comprising the following protocols:
SSH User Authentication Protocol:
Authenticates the client-side user to the server.
SSH Connection Protocol:
Multiplexes the encrypted tunnel into several logical channels.
SSH Transport Layer Protocol:
Ensures server authentication, confidentiality, and integrity.
Steps of SSH Protocol Communication
TCP Connection Establishment:
Begins with a TCP connection to the server prior to SSH Transport Layer Protocol initialization.
Secure Connection Establishment:
SSH Transport Layer Protocol is applied to authenticate and secure data transfer.
SSH Handshake Phases
Identification String Exchange Phase:
Both the client and server exchange their identification strings.
Key Algorithm Negotiation Phase:
Client and server agree on cryptographic algorithms for the session.
Key Exchange Phase:
Client generates a random key to be encrypted using the server's public key.
Secure Communication Begin:
The client sends an encrypted message using the session key.
Transport Layer Security (TLS)
Description:
A prevalent security service utilizing public key infrastructure (PKI) and certificates.
TLS Components
TLS Handshake Protocol:
Series of messages exchanged to set up secure communication parameters (most complex component).
TLS Record Protocol:
Ensures confidentiality and integrity of transmitted data.
TLS Handshake Keys Exchange Sequence
Exchange:
Client Hello, Server Hello, Certificate exchanges, Key exchanges, Change Cipher Spec, Finished messages.
HTTP Secure (HTTPS)
Definition:
HTTPS is the secure version of HTTP, incorporating TLS for encrypting data transport to prevent eavesdropping, tampering, and forgery.
IP Security (IPsec)
Rationale:
Protects IP traffic as it lacks inherent encryption, ensuring confidentiality, integrity, and authenticity during transmission.
Applications of IPsec
Secure communications across various networks.
Examples include establishing remote access, intranet connectivity, and e-commerce security.
Features of IPsec
Authentication Mechanism:
Verifies received packet sources ensuring non-alteration.
Confidentiality Facility:
Encrypts messages to avoid eavesdropping.
Key Management Facility:
Secure exchange of cryptographic keys.
Modes of IPsec
Transport Mode:
Extends to the payload of IP packets for end-to-end communication.
Encrypts IP payload but not the IP header.
Tunnel Mode:
Protects entire IP packets, useful for secure gateways to shield multiple hosts.
Benefits of IPsec
Strong perimeter security, resistance to bypass, transparency, and ability to secure individual users.
References
Lecture notes compiled by Dr. Ayman El Hajjar from personal notes and various sources.
Recommended readings include Chapter 9 from Computer Security Fundamentals focusing on topics covered in the course.