Exhaustive Study Notes on Information Security, Cryptography, and Digital User Authentication
Information Security Foundations and Organizational Triad
CS 3002 Information Security Course Objectives:
Explain key concepts of information security such as design principles, cryptography, and risk management.
Discuss legal, ethical, and professional issues in information security.
Analyze real-world scenarios, model them using security measures, and apply various security and risk management tools for achieving information security and privacy.
Identify appropriate techniques to tackle and solve real-life problems in the discipline of information security.
Understand issues related to ethics in the field of information security.
ISO/IEC 27001:2013 Information Security Management Framework:
Information security relies on three core operational pillars: People, Process, and Technology.
People: Security awareness programs, security duties, third-party user management, and organizational responsibilities.
Process: Information Security Management System (ISMS), risk management frameworks, policies, and operational procedures.
Technology: Security controls implemented for physical facilities, technical infrastructure, systems, and network parameters.

Fundamentals of Message Authentication and Hash Functions
Passive vs. Active Attacks:
Encryption: Primarily protects against passive attacks such as eavesdropping by ensuring confidentiality.
Message Authentication: Protects against active attacks involving falsification of data, unauthorized modification, and fraudulent transactions.
Definition and Objectives of Message Authentication:
A message, file, document, or data block is authentic when it is genuine and originates from its alleged source.
Message (or Data) Authentication: A security procedure enabling communicating parties to verify that received or stored messages are authentic.
Two primary aspects of verification:
Content Integrity: Verifying that the message contents have not been altered or tampered with.
Source Authenticity: Verifying that the identity of the sender is genuine.
Secondary aspects of verification:
Timeliness: Confirming the message has not been artificially delayed and replayed by an adversary.
Sequence: Confirming the proper ordering relative to other messages flowing between two parties.
Authentication Using Symmetric Encryption:
Assuming only the legitimate sender and receiver share a secret key, symmetric encryption inherently provides authentication because only the key holder could encrypt a valid message.
Incorporating an error-detection code and a sequence number assures the receiver that no alterations occurred and that message sequencing is correct.
Incorporating a timestamp assures the receiver that the message was not delayed beyond standard network transit expectations.
Threat of Block Reordering in ECB Mode: In Electronic Codebook (ECB) mode, reordering ciphertext blocks results in successful decryption of individual blocks, but alters the structural sequence and meaning of the overall payload. Because separate sequence numbers are typically not assigned to individual -bit plaintext blocks, block reordering presents a significant security threat.
Message Authentication without Confidentiality (Plaintext Transmission):
Three operational scenarios where plaintext transmission with an attached message authentication tag is preferred over full encryption:
Broadcast Applications: Broadcasting identical messages to multiple destination nodes (e.g., system unavailability notifications or control center alarms). Delegating authenticity monitoring to a single dedicated destination node is more cost-effective and reliable. If a security violation occurs, the monitoring system triggers a general alarm across the network.
Heavy Computational Load: High-traffic communication links where a destination system cannot afford the processor overhead required to decrypt all incoming traffic. Selective authentication is applied by randomly sampling and checking received messages.
Program Code Integrity: Authenticating computer software executable files in plaintext allows direct execution without repetitive decryption overhead. Attaching an authentication tag enables periodic integrity checks whenever software verification is required.
Message Authentication Code (MAC)
Mechanism of a Message Authentication Code:
Uses a shared secret key between sender A and receiver B to generate a small fixed-size block of data appended to the message.
Sender A calculates the MAC as a complex function of the message and shared key :
The combined package is transmitted to recipient B.
Recipient B executes the identical function on the received message using the shared secret key and compares the result against the received MAC tag.

Cryptographic Characteristics and Properties:
Collision Resistance: Because messages may be of arbitrary size while the MAC tag is of a small fixed size, many distinct messages theoretically map to the same MAC tag. Collision resistance dictates that it must be computationally infeasible in practice to find two distinct messages that yield identical MAC values.
Non-Reversibility: Unlike encryption algorithms, MAC algorithms do not require reversibility for decryption.
Block ciphers like Data Encryption Standard (DES) or Advanced Encryption Standard (AES) can generate MAC tags by selecting a subset of final ciphertext bits. Longer tags provide greater resistance to collision attacks.
One-Way Hash Functions and Cryptographic Requirements
One-Way Hash Function Principles:
Accepts a variable-size input message and produces a fixed-size output message digest .
Unlike a MAC, a standard cryptographic hash function does not accept a secret key as input.
Message Padding: Input messages are padded out to an integer multiple of a fixed length (e.g., ). Padding explicitly embeds a length field indicating the bit length of the original message , increasing computational difficulty for attackers attempting to forge alternate messages with matching hash values.

Keyed Hash MAC (Secret Value Approach):
Combines a cryptographic hash function with a shared secret key without relying on full symmetric encryption algorithms [TSUD92].
Sender A computes the message digest over the concatenation of the secret key and the message:
Sender A transmits the plaintext message concatenated with the digest: .
Receiver B possesses key , recomputes , and verifies . Because secret key is never transmitted, unauthorized modification or forgery is impossible as long as remains secure.

Motivations for Avoiding Full Encryption in Authentication [TSUD92]:
Encryption software introduces computational latency across high-volume message streams.
Hardware implementation costs for DES and AES add up across every network node.
Symmetric encryption hardware is optimized for large block sizes; small data payloads incur high initialization and invocation overhead.
Specific encryption algorithms may be subject to patent restrictions.
Six Fundamental Requirements for Cryptographic Hash Functions:
Arbitrary Input Size: can be applied to a block of data of any size.
Fixed Output Size: produces a fixed-length output (digest).
Computational Efficiency: is relatively easy to compute for any given input , making hardware and software implementations practical.
Preimage Resistance (One-Way Property): For any given code , it is computationally infeasible to find such that . Protects against attackers who possess only a hash value and attempt to recover the original input.
Second Preimage Resistance (Weak Collision Resistance): For any given input block , it is computationally infeasible to find such that . Protects against substitution attacks where an attacker attempts to substitute a legitimate message with a malicious alternative.
Collision Resistance (Strong Collision Resistance): It is computationally infeasible to find any pair such that . Makes it exceptionally difficult for an attacker to locate two arbitrary inputs that generate matching hash outputs.
Additional System Applications of Hash Functions:
Password Storage: Operating systems store cryptographic hashes of user passwords rather than plaintext. Upon login, the user-entered password is hashed and compared against the stored hash value. Requires preimage resistance and second preimage resistance.
File Intrusion Detection: Baseline hash values for system files are computed and stored on write-locked media or secure optical storage. System integrity is verified by recomputing . Requires weak second preimage resistance.
Public-Key Cryptography and Asymmetric Algorithms
Structure of Public-Key Cryptography:
First publicly proposed by Whitfield Diffie and Martin Hellman in 1976 [DIFF76].
Asymmetric design based on mathematical functions rather than bit-pattern manipulation operations.
Employs a paired set of asymmetric keys: a Public Key () and a Private Key ().
Common Misconceptions Regarding Public-Key Cryptography:
Misconception 1: Public-key encryption is inherently more secure against cryptanalysis than symmetric encryption. Reality: Security depends strictly on key length and the computational work required to break the algorithm. Neither symmetric nor asymmetric approach is inherently superior regarding cryptanalytic resistance.
Misconception 2: Public-key encryption renders symmetric encryption obsolete. Reality: Due to high computational overhead in asymmetric operations, public-key encryption is unsuited for bulk data; symmetric encryption remains essential.
Misconception 3: Key distribution is trivial in public-key systems. Reality: Key distribution requires structured protocols and central management agents (Certificate Authorities) that are no simpler than key distribution centers (KDCs) used in symmetric systems.
Dual Functional Modes of Public-Key Cryptography:
Confidentiality Mode: Sender encrypts plaintext using Receiver A's Public Key :
- Only Receiver A can decrypt ciphertext using Private Key :

Authentication / Data Integrity Mode: Sender encrypts data using Sender B's Private Key :
- Receiver decrypts ciphertext using Sender B's Public Key :
- Assures origin authenticity and integrity, serving as the basis for digital signatures.

Five Cryptographic Requirements for Asymmetric Systems [DIFF76]:
Computationally easy for Party B to generate a key pair .
Computationally easy for Sender A, knowing and message , to generate ciphertext:
Computationally easy for Receiver B to decrypt ciphertext using :
Computationally infeasible for an adversary, knowing , to determine .
Computationally infeasible for an adversary, knowing and ciphertext , to recover message .
Applications of Public-Key Cryptosystems:
Algorithm | Digital Signature | Symmetric Key Distribution | Encryption of Secret Keys |
|---|---|---|---|
RSA | Yes | Yes | Yes |
Diffie-Hellman | No | Yes | No |
DSS | Yes | No | No |
Elliptic Curve (ECC) | Yes | Yes | Yes |
RSA Algorithm Foundations:
Developed in 1977 by Ron Rivest, Adi Shamir, and Len Adleman at MIT; published in 1978 [RIVE78].
Block cipher operating on integer values between and .
Mathematical foundation:
Fact 1: Prime generation is easy (selecting large random primes and ).
Fact 2: Multiplication is easy ().
Conjecture 3: Prime factorization is computationally hard (recovering and from ).
Key Size Evolution: Historical challenge solved a modulus (). Modern security standards require a key size (about ) or higher for robust protection.
Digital Signatures and Key Management Infrastructure
Three Key Management Applications of Public-Key Systems:
Secure distribution of public keys.
Distribution of symmetric secret keys using public-key encryption.
Creation of temporary session keys for message encryption.
Digital Signature Definition and Framework:
Defined by NIST FIPS PUB 186-4 (Digital Signature Standard / DSS):
The result of a cryptographic transformation of data that provides origin authentication, data integrity, and signatory non-repudiation.
A data-dependent bit pattern generated as a function of the underlying message or file.
Enables any verifying party to establish that:
The message was signed by the holder of the corresponding private key.
The message content has not been altered since signing.
The signer cannot repudiate the signature.
FIPS 186-4 Approved Signature Algorithms:
Digital Signature Algorithm (DSA): Original NIST standard based on discrete logarithm difficulty.
RSA Digital Signature Algorithm: Signature scheme leveraging the RSA algorithm.
Elliptic Curve Digital Signature Algorithm (ECDSA): Signature scheme based on elliptic-curve cryptography.
Digital Signature Process Steps:
Signing Phase (Bob): Message is passed into a hash function to produce digest . Digest and Bob's private key are processed by a signature generation algorithm to yield signature . Package is transmitted.
Verification Phase (Alice): Alice passes received message into the hash function to compute . Alice processes signature and Bob's public key through a signature verification algorithm. If the calculated digest matches the decrypted signature, the signature is valid.

Public-Key Certificates and Certificate Authorities (CA):
Public Announcement Threat: Unauthenticated public distribution allows an attacker to forge a public announcement, broadcasting a fake public key bound to Bob's identity. The attacker can decrypt messages intended for Bob or forge signatures under Bob's identity until detected.
Public-Key Certificate Construction: Binds a user's identity to their public key, verified and digitally signed by a trusted Certificate Authority (CA).
Step-by-Step Certificate Lifecycle Workflow:
Client software generates a key pair: Public Key () and Private Key ().
Client prepares an unsigned certificate containing User ID, Public Key, and CA info.
Client submits the unsigned certificate to a CA through a secure channel (face-to-face identity proofing, registered e-mail, or authenticated web form).
CA computes a cryptographic hash of the unsigned certificate (e.g., Secure Hash Algorithm / SHA family).
CA signs the hash using the CA's private key and a signature generation algorithm.
CA appends the digital signature to the certificate to produce a Signed Certificate.
CA transmits the signed certificate back to the client.
Client distributes the signed certificate to relying parties.
Verification by Recipient: a. Recipient computes the hash of the certificate body (excluding signature). b. Recipient decrypts and verifies the signature using the CA's public key and reports valid or invalid.

Digital User Authentication Principles and Architecture
Fundamental Definitions:
User Authentication: A core security building block that forms the foundation for access control and system user accountability.
Identification: Process where a user claims an identity to the system (e.g., presenting a user ID).
Verification: Process where the system validates the identity claim through authentication information exchange.
Distinction: User authentication verifies user identity claims to a local or network host, whereas message authentication verifies data payload integrity and source between communicating parties.
NIST SP 800-171 Identification and Authentication Security Requirements:
Basic Requirements:
Identify information system users, processes acting on behalf of users, or devices.
Authenticate (verify) identities of users, processes, or devices as a prerequisite to granting system access.
Derived Requirements:
Enforce multifactor authentication (MFA) for privileged and non-privileged account access.
Employ replay-resistant authentication mechanisms for network access.
Prevent reuse of identifiers for a defined period.
Disable identifiers after a defined period of inactivity.
Enforce minimum password complexity and character variance on password creation.
Prohibit password reuse across a specified generation threshold.
Mandate immediate change of temporary passwords upon initial logon.
Store and transmit cryptographically protected passwords exclusively.
Obscure visual or text feedback of authentication inputs.
NIST SP 800-63-3 E-Authentication Architectural Model:
Registration Authority (RA): Trusted entity conducting identity proofing and user registration.
Credential Service Provider (CSP): Issues electronic credentials binding a subscriber identity to a token.
Subscriber / Claimant: Individual asserting an identity claim.
Verifier: Entity conducting the protocol exchange to validate tokens and credentials.
Relying Party (RP): Entity relying on verifier identity assertions to execute authorization decisions.

Four Primary Means of User Identity Authentication:
Something the individual knows: Passwords, Personal Identification Numbers (PINs), prearranged security question answers.
Something the individual possesses (Token): Electronic keycards, smart cards, physical memory keys.
Something the individual is (Static Biometrics): Fingerprint recognition, retina scans, facial recognition.
Something the individual does (Dynamic Biometrics): Voice pattern recognition, handwriting dynamics, typing rhythm (keystroke dynamics).
Multifactor Authentication (MFA):
Sequentially combines two or more distinct authentication categories.
Combining two distinct factors provides significantly higher security than single-factor implementations; three-factor systems provide superior protection over two-factor approaches.

Risk Assessment and Assurance Levels (NIST SP 800-63-3 / SP 800-171):
Assesses maximum potential impact across six security categories: Inconvenience/reputation, Financial loss/liability, Harm to organization programs, Sensitive information release, Personal safety, and Civil/criminal violations.
Maps risk impact profiles across four progressive Assurance Levels (1 to 4: Low, Moderate, High impact profiles).
Password-Based Authentication, Attacks, and Security Mechanisms
Mechanics and Role of Password Systems:
User provides a User ID and password. The system compares the input against stored records in a system password file.
Security functions provided by User ID:
Authorization: Determines whether the user is permitted system entry.
Privilege Assignment: Differentiates permissions (administrator/superuser vs guest/anonymous).
Discretionary Access Control (DAC): Enables owners to specify access permissions for other user IDs.
Password Attack Strategies and Technical Countermeasures:
Offline Dictionary Attack: Attacker steals the password file and compares hashes against dictionary candidate hashes offline. Countermeasures: Password file access restrictions, intrusion detection, immediate password reissuance upon file compromise.
Specific Account Attack: Targeted password guessing against a single user account. Countermeasure: Account lockout after a specified number of failed attempts (typically ).
Popular Password Attack: Testing common passwords against many user IDs. Countermeasures: Inhibiting common password selection, client cookie tracking, and IP address submission pattern analysis.
Password Guessing Against Single User: Leveraging user personal data to guess passwords. Countermeasure: Password policies enforcing minimum length, complex character sets, secrecy, and periodic rotation.
Workstation Hijacking: Accessing unattended logged-in workstations. Countermeasures: Automatic session lockouts after inactivity timeouts and behavioral anomaly detection.
Exploiting User Mistakes: Social engineering, written passwords, or default administrator credentials. Countermeasures: User awareness training, changing preconfigured default credentials, and pairing simpler passwords with MFA.
Exploiting Multiple Password Use: Reusing identical passwords across multiple services. Countermeasure: Policy forbidding password reuse across devices and domains.
Electronic Monitoring: Eavesdropping password transmissions over network links. Countermeasure: Nonce-based dynamic authentication protocols (retransmitting static encrypted passwords remains vulnerable to replay attacks).
Hashed Password Storage with Salt (UNIX Mechanism):
Prevents plaintext password exposure in system password files.
Salt Value: A pseudorandom or random number (or system timestamp) generated during password creation.
Creation Process: The user-selected password is combined with the salt and processed by a slow computational hash function. The plaintext salt and resulting hash code are saved in the password file.

Verification Process: Upon login, the system indexes the User ID, retrieves the plaintext salt and stored hash, computes , and compares the result against the stored hash.

Three Technical Functions of Salt Values:
Prevents matching passwords from producing identical hashes in the password file.
Thwarts precomputed dictionary attacks (Rainbow Tables) by expanding search space sizes by a factor of for a -bit salt.
Prevents attackers from determining whether a user utilizes identical passwords across different systems.
Password Cracking Methodologies and Countermeasures:
Dictionary Attacks: Hashing dictionary words with every salt value in the password file to match stored hashes.
Rainbow Table Attacks: Precomputing massive tables of hash outputs across all possible salts. Example: of table storage allowed cracking of alphanumeric Windows hashes in [OECH03]. Countermeasure: Implementing large salt lengths and long hash digests (e.g., FreeBSD and OpenBSD mechanisms).
John the Ripper: Open-source password cracker (first developed in 1996) combining dictionary and brute-force techniques.
Password Selection Strategies:
User Education: Providing strong password guidelines (ineffective on its own as users often choose easy options).
Computer-Generated Passwords: System generates random passwords (difficult for users to memorize).
Reactive Password Checking: System periodically runs internal cracking tools to identify weak passwords (drawback: attackers may run faster crackers before system audits occur).
Proactive Complex Password Policy: System evaluates user-chosen passwords upon creation against dictionaries and complexity rules, rejecting weak options while permitting memorable choices.