Public Key Infrastructure
Understanding Public Key Infrastructure (PKI)
The term Public Key Infrastructure (PKI) refers broadly to:
Policies and procedures related to cryptography.
Hardware and software involved in:
Creating digital certificates
Distributing certificates
Managing certificates
Storing certificates
Revoking certificates
Other associated processes.
Importance of PKI:
Involves considerable planning even for small organizations.
Decisions must be made regarding encryption methods and application within the organization.
PKI is often linked with a Certificate Authority (CA), which helps establish trust concerning individuals or devices.
Symmetric Encryption
Definition: Symmetric encryption uses the same key for both encrypting and decrypting data.
Metaphor: The symmetric key is often compared to a secret key kept in a suitcase, which is handcuffed to a deliverer, ensuring its security.
Key Characteristics:
If someone possesses the symmetric key, they can decrypt data encrypted with it.
Alternate Terms:
Secret Key Algorithm: Used to refer to the symmetric key’s role in encryption/decryption.
Shared Secret: Indicates that the same key is utilized for both processes.
Scalability Problem:
Distributing the symmetric key to multiple users becomes complex and unmanageable as the number of users increases.
Once there are more than 10 individuals or devices, sharing and managing keys becomes difficult.
Use Cases:
Still commonly used due to speed and low overhead compared to asymmetric encryption.
Asymmetric Encryption
Definition: Asymmetric encryption involves two mathematically related keys:
One key for encrypting (public key)
Another key for decrypting (private key).
Key Generation: Both keys are created simultaneously through a mathematical process.
Key Characteristics:
The private key is restricted to one person/device; it must remain secret.
The public key is openly available and can be shared with anyone.
Functionality:
Anyone can encrypt data using the public key.
Only the holder of the private key can decrypt the data encrypted with the corresponding public key.
Example:
Individuals such as Bob may encrypt messages using Alice's public key. Only Alice, possessing the private key, can decrypt it.
Mathematical Relationship:
No one can derive the private key from the public key due to complex mathematical algorithms, ensuring security.
Key Generation Process
Process: Key generation typically involves the use of:
Randomization techniques
A combination of large prime numbers.
One-Time Setup: Users usually need to generate their public-private key pair only once.
Example Case: Alice generates a key pair:
Outputs:
Public Key: Can be shared widely.
Private Key: Should be stored securely, often with an assigned password for protection.
Practical Example of Asymmetric Encryption
Bob wants to send Alice a secured message.
Plaintext Message: "Hello, Alice".
Bob uses Alice's public key to encrypt the plaintext, creating ciphertext.
Sending the Ciphertext:
The encrypted data can be shared without revealing the underlying message.
Even with access to the ciphertext and public key, no one can decrypt it without Alice's private key.
Decryption Process:
Alice receives the ciphertext and uses her private key to recover the original message.
Key Management Considerations
User Management:
Individuals typically manage their own public-private key pairs.
In larger environments, key management becomes crucial due to the number of keys.
Options for Key Management:
You might use a third-party service to maintain private keys.
Alternatively, you can implement key escrow for local storage and management of keys.
Need for Data Accessibility:
If a user leaves the organization, access to their encrypted data must still be maintained by retaining the associated private keys.
Possible scenarios include collaboration with external partners or managing sensitive organizational data across departments.
Ethical Considerations:
Handing over private keys may raise ethical concerns. However, it may be necessary to ensure continuous access to data and maintain operational integrity of the organization.