Exhaustive Study Notes on Information Security, Cryptography, and Digital User Authentication

Information Security Foundations and Organizational Triad

  • CS 3002 Information Security Course Objectives:

    • Explain key concepts of information security such as design principles, cryptography, and risk management.

    • Discuss legal, ethical, and professional issues in information security.

    • Analyze real-world scenarios, model them using security measures, and apply various security and risk management tools for achieving information security and privacy.

    • Identify appropriate techniques to tackle and solve real-life problems in the discipline of information security.

    • Understand issues related to ethics in the field of information security.

  • ISO/IEC 27001:2013 Information Security Management Framework:

    • Information security relies on three core operational pillars: People, Process, and Technology.

    • People: Security awareness programs, security duties, third-party user management, and organizational responsibilities.

    • Process: Information Security Management System (ISMS), risk management frameworks, policies, and operational procedures.

    • Technology: Security controls implemented for physical facilities, technical infrastructure, systems, and network parameters.

ISO/IEC 27001:2013 Information Security Dimensions

Fundamentals of Message Authentication and Hash Functions

  • Passive vs. Active Attacks:

    • Encryption: Primarily protects against passive attacks such as eavesdropping by ensuring confidentiality.

    • Message Authentication: Protects against active attacks involving falsification of data, unauthorized modification, and fraudulent transactions.

  • Definition and Objectives of Message Authentication:

    • A message, file, document, or data block is authentic when it is genuine and originates from its alleged source.

    • Message (or Data) Authentication: A security procedure enabling communicating parties to verify that received or stored messages are authentic.

    • Two primary aspects of verification:

    1. Content Integrity: Verifying that the message contents have not been altered or tampered with.

    2. Source Authenticity: Verifying that the identity of the sender is genuine.

    • Secondary aspects of verification:

    • Timeliness: Confirming the message has not been artificially delayed and replayed by an adversary.

    • Sequence: Confirming the proper ordering relative to other messages flowing between two parties.

  • Authentication Using Symmetric Encryption:

    • Assuming only the legitimate sender and receiver share a secret key, symmetric encryption inherently provides authentication because only the key holder could encrypt a valid message.

    • Incorporating an error-detection code and a sequence number assures the receiver that no alterations occurred and that message sequencing is correct.

    • Incorporating a timestamp assures the receiver that the message was not delayed beyond standard network transit expectations.

    • Threat of Block Reordering in ECB Mode: In Electronic Codebook (ECB) mode, reordering ciphertext blocks results in successful decryption of individual blocks, but alters the structural sequence and meaning of the overall payload. Because separate sequence numbers are typically not assigned to individual bb-bit plaintext blocks, block reordering presents a significant security threat.

  • Message Authentication without Confidentiality (Plaintext Transmission):

    • Three operational scenarios where plaintext transmission with an attached message authentication tag is preferred over full encryption:

    1. Broadcast Applications: Broadcasting identical messages to multiple destination nodes (e.g., system unavailability notifications or control center alarms). Delegating authenticity monitoring to a single dedicated destination node is more cost-effective and reliable. If a security violation occurs, the monitoring system triggers a general alarm across the network.

    2. Heavy Computational Load: High-traffic communication links where a destination system cannot afford the processor overhead required to decrypt all incoming traffic. Selective authentication is applied by randomly sampling and checking received messages.

    3. Program Code Integrity: Authenticating computer software executable files in plaintext allows direct execution without repetitive decryption overhead. Attaching an authentication tag enables periodic integrity checks whenever software verification is required.

Message Authentication Code (MAC)

  • Mechanism of a Message Authentication Code:

    • Uses a shared secret key KABK_{AB} between sender A and receiver B to generate a small fixed-size block of data appended to the message.

    • Sender A calculates the MAC as a complex function of the message MM and shared key KABK_{AB}:

MACM=F(KAB,M)\text{MAC}_M = F(K_{AB}, M)

  • The combined package [M∥MACM][M \parallel \text{MAC}_M] is transmitted to recipient B.

  • Recipient B executes the identical function F(KAB,M)F(K_{AB}, M) on the received message using the shared secret key KABK_{AB} and compares the result against the received MAC tag.

Message Authentication Using a Message Authentication Code (MAC)
  • Cryptographic Characteristics and Properties:

    • Collision Resistance: Because messages MM may be of arbitrary size while the MAC tag is of a small fixed size, many distinct messages theoretically map to the same MAC tag. Collision resistance dictates that it must be computationally infeasible in practice to find two distinct messages that yield identical MAC values.

    • Non-Reversibility: Unlike encryption algorithms, MAC algorithms do not require reversibility for decryption.

    • Block ciphers like Data Encryption Standard (DES) or Advanced Encryption Standard (AES) can generate MAC tags by selecting a subset of final ciphertext bits. Longer tags provide greater resistance to collision attacks.

One-Way Hash Functions and Cryptographic Requirements

  • One-Way Hash Function Principles:

    • Accepts a variable-size input message MM and produces a fixed-size output message digest H(M)H(M).

    • Unlike a MAC, a standard cryptographic hash function does not accept a secret key as input.

    • Message Padding: Input messages are padded out to an integer multiple of a fixed length (e.g., 1024 bits1024\,\text{bits}). Padding explicitly embeds a length field indicating the bit length of the original message MM, increasing computational difficulty for attackers attempting to forge alternate messages with matching hash values.

Cryptographic Hash Function Mechanism
  • Keyed Hash MAC (Secret Value Approach):

    • Combines a cryptographic hash function with a shared secret key KK without relying on full symmetric encryption algorithms [TSUD92].

    • Sender A computes the message digest over the concatenation of the secret key and the message:

MDM=H(K∥M∥K)MD_M = H(K \parallel M \parallel K)

  • Sender A transmits the plaintext message concatenated with the digest: [M∥MDM][M \parallel MD_M].

  • Receiver B possesses key KK, recomputes H(K∥M∥K)H(K \parallel M \parallel K), and verifies MDMMD_M. Because secret key KK is never transmitted, unauthorized modification or forgery is impossible as long as KK remains secure.

Message Authentication Using a One-Way Hash Function and Secret Value
  • Motivations for Avoiding Full Encryption in Authentication [TSUD92]:

    • Encryption software introduces computational latency across high-volume message streams.

    • Hardware implementation costs for DES and AES add up across every network node.

    • Symmetric encryption hardware is optimized for large block sizes; small data payloads incur high initialization and invocation overhead.

    • Specific encryption algorithms may be subject to patent restrictions.

  • Six Fundamental Requirements for Cryptographic Hash Functions:

    1. Arbitrary Input Size: HH can be applied to a block of data of any size.

    2. Fixed Output Size: HH produces a fixed-length output (digest).

    3. Computational Efficiency: H(x)H(x) is relatively easy to compute for any given input xx, making hardware and software implementations practical.

    4. Preimage Resistance (One-Way Property): For any given code hh, it is computationally infeasible to find xx such that H(x)=hH(x) = h. Protects against attackers who possess only a hash value and attempt to recover the original input.

    5. Second Preimage Resistance (Weak Collision Resistance): For any given input block xx, it is computationally infeasible to find yeqxy eq x such that H(y)=H(x)H(y) = H(x). Protects against substitution attacks where an attacker attempts to substitute a legitimate message with a malicious alternative.

    6. Collision Resistance (Strong Collision Resistance): It is computationally infeasible to find any pair (x,y)(x, y) such that H(x)=H(y)H(x) = H(y). Makes it exceptionally difficult for an attacker to locate two arbitrary inputs that generate matching hash outputs.

  • Additional System Applications of Hash Functions:

    • Password Storage: Operating systems store cryptographic hashes of user passwords rather than plaintext. Upon login, the user-entered password is hashed and compared against the stored hash value. Requires preimage resistance and second preimage resistance.

    • File Intrusion Detection: Baseline hash values H(F)H(F) for system files are computed and stored on write-locked media or secure optical storage. System integrity is verified by recomputing H(F)H(F). Requires weak second preimage resistance.

Public-Key Cryptography and Asymmetric Algorithms

  • Structure of Public-Key Cryptography:

    • First publicly proposed by Whitfield Diffie and Martin Hellman in 1976 [DIFF76].

    • Asymmetric design based on mathematical functions rather than bit-pattern manipulation operations.

    • Employs a paired set of asymmetric keys: a Public Key (PUPU) and a Private Key (PRPR).

  • Common Misconceptions Regarding Public-Key Cryptography:

    1. Misconception 1: Public-key encryption is inherently more secure against cryptanalysis than symmetric encryption. Reality: Security depends strictly on key length and the computational work required to break the algorithm. Neither symmetric nor asymmetric approach is inherently superior regarding cryptanalytic resistance.

    2. Misconception 2: Public-key encryption renders symmetric encryption obsolete. Reality: Due to high computational overhead in asymmetric operations, public-key encryption is unsuited for bulk data; symmetric encryption remains essential.

    3. Misconception 3: Key distribution is trivial in public-key systems. Reality: Key distribution requires structured protocols and central management agents (Certificate Authorities) that are no simpler than key distribution centers (KDCs) used in symmetric systems.

  • Dual Functional Modes of Public-Key Cryptography:

    • Confidentiality Mode: Sender encrypts plaintext XX using Receiver A's Public Key PUaPU_a:

Y=E(PUa,X)Y = E(PU_a, X)

- Only Receiver A can decrypt ciphertext YY using Private Key PRaPR_a:

X=D(PRa,Y)X = D(PR_a, Y)

Public-Key Cryptography for Confidentiality
  • Authentication / Data Integrity Mode: Sender encrypts data XX using Sender B's Private Key PRbPR_b:

Y=E(PRb,X)Y = E(PR_b, X)

- Receiver decrypts ciphertext YY using Sender B's Public Key PUbPU_b:

X=D(PUb,Y)X = D(PU_b, Y)

- Assures origin authenticity and integrity, serving as the basis for digital signatures.
Public-Key Cryptography for Authentication
  • Five Cryptographic Requirements for Asymmetric Systems [DIFF76]:

    1. Computationally easy for Party B to generate a key pair (PUb,PRb)(PU_b, PR_b).

    2. Computationally easy for Sender A, knowing PUbPU_b and message MM, to generate ciphertext:

C=E(PUb,M)C = E(PU_b, M)

  1. Computationally easy for Receiver B to decrypt ciphertext using PRbPR_b:

M=D(PRb,C)=D[PRb,E(PUb,M)]M = D(PR_b, C) = D[PR_b, E(PU_b, M)]

  1. Computationally infeasible for an adversary, knowing PUbPU_b, to determine PRbPR_b.

  2. Computationally infeasible for an adversary, knowing PUbPU_b and ciphertext CC, to recover message MM.

  • Applications of Public-Key Cryptosystems:

Algorithm

Digital Signature

Symmetric Key Distribution

Encryption of Secret Keys

RSA

Yes

Yes

Yes

Diffie-Hellman

No

Yes

No

DSS

Yes

No

No

Elliptic Curve (ECC)

Yes

Yes

Yes

  • RSA Algorithm Foundations:

    • Developed in 1977 by Ron Rivest, Adi Shamir, and Len Adleman at MIT; published in 1978 [RIVE78].

    • Block cipher operating on integer values between 00 and n−1n - 1.

    • Mathematical foundation:

    • Fact 1: Prime generation is easy (selecting large random primes pp and qq).

    • Fact 2: Multiplication is easy (n=pqn = pq).

    • Conjecture 3: Prime factorization is computationally hard (recovering pp and qq from nn).

    • Key Size Evolution: Historical challenge solved a 129 decimal digit129\,\text{decimal digit} modulus (≈428 bits\approx 428\,\text{bits}). Modern security standards require a 1024 bit1024\,\text{bit} key size (about 300 decimal digits300\,\text{decimal digits}) or higher for robust protection.

Digital Signatures and Key Management Infrastructure

  • Three Key Management Applications of Public-Key Systems:

    1. Secure distribution of public keys.

    2. Distribution of symmetric secret keys using public-key encryption.

    3. Creation of temporary session keys for message encryption.

  • Digital Signature Definition and Framework:

    • Defined by NIST FIPS PUB 186-4 (Digital Signature Standard / DSS):

    • The result of a cryptographic transformation of data that provides origin authentication, data integrity, and signatory non-repudiation.

    • A data-dependent bit pattern generated as a function of the underlying message or file.

    • Enables any verifying party to establish that:

    1. The message was signed by the holder of the corresponding private key.

    2. The message content has not been altered since signing.

    3. The signer cannot repudiate the signature.

  • FIPS 186-4 Approved Signature Algorithms:

    • Digital Signature Algorithm (DSA): Original NIST standard based on discrete logarithm difficulty.

    • RSA Digital Signature Algorithm: Signature scheme leveraging the RSA algorithm.

    • Elliptic Curve Digital Signature Algorithm (ECDSA): Signature scheme based on elliptic-curve cryptography.

  • Digital Signature Process Steps:

    • Signing Phase (Bob): Message MM is passed into a hash function to produce digest hh. Digest hh and Bob's private key PRbPR_b are processed by a signature generation algorithm to yield signature SS. Package [M∥S][M \parallel S] is transmitted.

    • Verification Phase (Alice): Alice passes received message MM into the hash function to compute hh. Alice processes signature SS and Bob's public key PUbPU_b through a signature verification algorithm. If the calculated digest matches the decrypted signature, the signature is valid.

Essential Elements of Digital Signature Process
  • Public-Key Certificates and Certificate Authorities (CA):

    • Public Announcement Threat: Unauthenticated public distribution allows an attacker to forge a public announcement, broadcasting a fake public key bound to Bob's identity. The attacker can decrypt messages intended for Bob or forge signatures under Bob's identity until detected.

    • Public-Key Certificate Construction: Binds a user's identity to their public key, verified and digitally signed by a trusted Certificate Authority (CA).

  • Step-by-Step Certificate Lifecycle Workflow:

    1. Client software generates a key pair: Public Key (PUPU) and Private Key (PRPR).

    2. Client prepares an unsigned certificate containing User ID, Public Key, and CA info.

    3. Client submits the unsigned certificate to a CA through a secure channel (face-to-face identity proofing, registered e-mail, or authenticated web form).

    4. CA computes a cryptographic hash of the unsigned certificate (e.g., Secure Hash Algorithm / SHA family).

    5. CA signs the hash using the CA's private key and a signature generation algorithm.

    6. CA appends the digital signature to the certificate to produce a Signed Certificate.

    7. CA transmits the signed certificate back to the client.

    8. Client distributes the signed certificate to relying parties.

    9. Verification by Recipient:      a. Recipient computes the hash of the certificate body (excluding signature).      b. Recipient decrypts and verifies the signature using the CA's public key and reports valid or invalid.

Public-Key Certificate Creation and Verification Workflow

Digital User Authentication Principles and Architecture

  • Fundamental Definitions:

    • User Authentication: A core security building block that forms the foundation for access control and system user accountability.

    • Identification: Process where a user claims an identity to the system (e.g., presenting a user ID).

    • Verification: Process where the system validates the identity claim through authentication information exchange.

    • Distinction: User authentication verifies user identity claims to a local or network host, whereas message authentication verifies data payload integrity and source between communicating parties.

  • NIST SP 800-171 Identification and Authentication Security Requirements:

    • Basic Requirements:

    1. Identify information system users, processes acting on behalf of users, or devices.

    2. Authenticate (verify) identities of users, processes, or devices as a prerequisite to granting system access.

    • Derived Requirements:

    1. Enforce multifactor authentication (MFA) for privileged and non-privileged account access.

    2. Employ replay-resistant authentication mechanisms for network access.

    3. Prevent reuse of identifiers for a defined period.

    4. Disable identifiers after a defined period of inactivity.

    5. Enforce minimum password complexity and character variance on password creation.

    6. Prohibit password reuse across a specified generation threshold.

    7. Mandate immediate change of temporary passwords upon initial logon.

    8. Store and transmit cryptographically protected passwords exclusively.

    9. Obscure visual or text feedback of authentication inputs.

  • NIST SP 800-63-3 E-Authentication Architectural Model:

    • Registration Authority (RA): Trusted entity conducting identity proofing and user registration.

    • Credential Service Provider (CSP): Issues electronic credentials binding a subscriber identity to a token.

    • Subscriber / Claimant: Individual asserting an identity claim.

    • Verifier: Entity conducting the protocol exchange to validate tokens and credentials.

    • Relying Party (RP): Entity relying on verifier identity assertions to execute authorization decisions.

NIST SP 800-63-3 E-Authentication Architectural Model
  • Four Primary Means of User Identity Authentication:

    1. Something the individual knows: Passwords, Personal Identification Numbers (PINs), prearranged security question answers.

    2. Something the individual possesses (Token): Electronic keycards, smart cards, physical memory keys.

    3. Something the individual is (Static Biometrics): Fingerprint recognition, retina scans, facial recognition.

    4. Something the individual does (Dynamic Biometrics): Voice pattern recognition, handwriting dynamics, typing rhythm (keystroke dynamics).

  • Multifactor Authentication (MFA):

    • Sequentially combines two or more distinct authentication categories.

    • Combining two distinct factors provides significantly higher security than single-factor implementations; three-factor systems provide superior protection over two-factor approaches.

Multifactor Authentication Process Flow
  • Risk Assessment and Assurance Levels (NIST SP 800-63-3 / SP 800-171):

    • Assesses maximum potential impact across six security categories: Inconvenience/reputation, Financial loss/liability, Harm to organization programs, Sensitive information release, Personal safety, and Civil/criminal violations.

    • Maps risk impact profiles across four progressive Assurance Levels (1 to 4: Low, Moderate, High impact profiles).

Password-Based Authentication, Attacks, and Security Mechanisms

  • Mechanics and Role of Password Systems:

    • User provides a User ID and password. The system compares the input against stored records in a system password file.

    • Security functions provided by User ID:

    1. Authorization: Determines whether the user is permitted system entry.

    2. Privilege Assignment: Differentiates permissions (administrator/superuser vs guest/anonymous).

    3. Discretionary Access Control (DAC): Enables owners to specify access permissions for other user IDs.

  • Password Attack Strategies and Technical Countermeasures:

    • Offline Dictionary Attack: Attacker steals the password file and compares hashes against dictionary candidate hashes offline. Countermeasures: Password file access restrictions, intrusion detection, immediate password reissuance upon file compromise.

    • Specific Account Attack: Targeted password guessing against a single user account. Countermeasure: Account lockout after a specified number of failed attempts (typically ≤5\le 5).

    • Popular Password Attack: Testing common passwords against many user IDs. Countermeasures: Inhibiting common password selection, client cookie tracking, and IP address submission pattern analysis.

    • Password Guessing Against Single User: Leveraging user personal data to guess passwords. Countermeasure: Password policies enforcing minimum length, complex character sets, secrecy, and periodic rotation.

    • Workstation Hijacking: Accessing unattended logged-in workstations. Countermeasures: Automatic session lockouts after inactivity timeouts and behavioral anomaly detection.

    • Exploiting User Mistakes: Social engineering, written passwords, or default administrator credentials. Countermeasures: User awareness training, changing preconfigured default credentials, and pairing simpler passwords with MFA.

    • Exploiting Multiple Password Use: Reusing identical passwords across multiple services. Countermeasure: Policy forbidding password reuse across devices and domains.

    • Electronic Monitoring: Eavesdropping password transmissions over network links. Countermeasure: Nonce-based dynamic authentication protocols (retransmitting static encrypted passwords remains vulnerable to replay attacks).

  • Hashed Password Storage with Salt (UNIX Mechanism):

    • Prevents plaintext password exposure in system password files.

    • Salt Value: A pseudorandom or random number (or system timestamp) generated during password creation.

    • Creation Process: The user-selected password is combined with the salt and processed by a slow computational hash function. The plaintext salt and resulting hash code are saved in the password file.

Loading a New Password with Salt and Slow Hash
  • Verification Process: Upon login, the system indexes the User ID, retrieves the plaintext salt and stored hash, computes SlowHash(Salt+EnteredPassword)\text{SlowHash}(\text{Salt} + \text{EnteredPassword}), and compares the result against the stored hash.

Verifying User Password against Stored Hash
  • Three Technical Functions of Salt Values:

    1. Prevents matching passwords from producing identical hashes in the password file.

    2. Thwarts precomputed dictionary attacks (Rainbow Tables) by expanding search space sizes by a factor of 2b2^b for a bb-bit salt.

    3. Prevents attackers from determining whether a user utilizes identical passwords across different systems.

  • Password Cracking Methodologies and Countermeasures:

    • Dictionary Attacks: Hashing dictionary words with every salt value in the password file to match stored hashes.

    • Rainbow Table Attacks: Precomputing massive tables of hash outputs across all possible salts. Example: 1.4 GB1.4\,\text{GB} of table storage allowed cracking 99.9%99.9\% of alphanumeric Windows hashes in 13.8 seconds13.8\,\text{seconds} [OECH03]. Countermeasure: Implementing large salt lengths and long hash digests (e.g., FreeBSD and OpenBSD mechanisms).

    • John the Ripper: Open-source password cracker (first developed in 1996) combining dictionary and brute-force techniques.

  • Password Selection Strategies:

    1. User Education: Providing strong password guidelines (ineffective on its own as users often choose easy options).

    2. Computer-Generated Passwords: System generates random passwords (difficult for users to memorize).

    3. Reactive Password Checking: System periodically runs internal cracking tools to identify weak passwords (drawback: attackers may run faster crackers before system audits occur).

    4. Proactive Complex Password Policy: System evaluates user-chosen passwords upon creation against dictionaries and complexity rules, rejecting weak options while permitting memorable choices.