Asymmetric Algorithms (OBJ 1.4)

Asymmetric Algorithms

Definition and Overview

  • Asymmetric algorithms, also known as public key cryptography, do not necessitate a shared secret key unlike symmetric algorithms.
  • The public key is accessible to anyone, while the private key is kept secret by the owner.
  • Asymmetric algorithms employ a key pair for encryption and decryption, comprising a public key and a private key.

Key Features of Asymmetric Algorithms

  • Confidentiality: Achieved by encrypting data with the recipient's public key, ensuring only the recipient can decrypt it using their private key.

    • Example: Sending a document to Mary involves encrypting it with her public key, making it unreadable to everyone except Mary, who can decrypt it with her private key.
  • Non-repudiation: Established when a message is encrypted with the sender's private key.

    • By encrypting a message with the private key, anyone can verify the sender's identity using the public key, but only the sender can sign it.
  • Integrity: Ensured by creating a hash digest from the message and encrypting this hash with the sender's private key (creating a digital signature).

  • Authentication: Offers proof of the sender's identity and ensures that the message has not been altered in transit.

Process of Using Asymmetric Algorithms

  1. Sender creates a hash of the original message.
  2. The hash is encrypted with the sender's private key (providing non-repudiation).
  3. The original message is encrypted using the receiver's public key (ensuring confidentiality).
  4. Together these components ensure integrity and non-repudiation while maintaining confidentiality.

Specific Asymmetric Algorithms

  • The primary asymmetric algorithms to know are:
    • Diffie-Hellman:
    • Named after its inventors, used primarily for conducting key exchanges and secure key distribution.
    • Commonly utilized for establishing VPN tunnels, allowing asymmetric algorithms to set up a shared secret for symmetric enciphering securely and at scale.
    • Vulnerable to man-in-the-middle attacks; authentication mechanisms (e.g., passwords, digital certificates) are recommended during the exchange process.
    • RSA (Rivest–Shamir–Adleman):
    • A widely used algorithm for key exchange, encryption, and digital signatures, relying on the difficulty of factoring large prime numbers.
    • Supports key sizes between 1024 to 4096 bits.
    • Used in secure tokens for multifactor authentication, where a changing six-digit code is generated.
    • ECC (Elliptic Curve Cryptography):
    • Based on algebraic structures of elliptic curves over finite fields, providing efficient security, especially in mobile devices.
    • An ECC 256-bit key is approximately equal in security to a 2048-bit RSA key, making ECC about six times more efficient.
    • Commonly employed for low-power computing devices due to the reduced processing requirements.
Variants of ECC
  • ECDH (Elliptic Curve Diffie-Hellman): ECC version of Diffie-Hellman for secure key exchange.
  • ECDHE (Elliptic Curve Diffie-Hellman Ephemeral): Uses different keys for each segment of the key establishment in the Diffie-Hellman process.
  • ECDSA (Elliptic Curve Digital Signature Algorithm): A public key encryption algorithm endorsed by the U.S. Government for digital signatures.

Conclusion

  • Asymmetric algorithms, or Public Key Cryptography, utilize two distinct keys for data encryption and decryption.
  • Understanding the nuances and applications of Diffie-Hellman, RSA, and ECC is crucial for roles in cybersecurity, particularly as they apply to encryption and secure communications across varying platforms and devices.