Asymmetric Algorithms (OBJ 1.4)
Asymmetric Algorithms
Definition and Overview
- Asymmetric algorithms, also known as public key cryptography, do not necessitate a shared secret key unlike symmetric algorithms.
- The public key is accessible to anyone, while the private key is kept secret by the owner.
- Asymmetric algorithms employ a key pair for encryption and decryption, comprising a public key and a private key.
Key Features of Asymmetric Algorithms
Confidentiality: Achieved by encrypting data with the recipient's public key, ensuring only the recipient can decrypt it using their private key.
- Example: Sending a document to Mary involves encrypting it with her public key, making it unreadable to everyone except Mary, who can decrypt it with her private key.
Non-repudiation: Established when a message is encrypted with the sender's private key.
- By encrypting a message with the private key, anyone can verify the sender's identity using the public key, but only the sender can sign it.
Integrity: Ensured by creating a hash digest from the message and encrypting this hash with the sender's private key (creating a digital signature).
Authentication: Offers proof of the sender's identity and ensures that the message has not been altered in transit.
Process of Using Asymmetric Algorithms
- Sender creates a hash of the original message.
- The hash is encrypted with the sender's private key (providing non-repudiation).
- The original message is encrypted using the receiver's public key (ensuring confidentiality).
- Together these components ensure integrity and non-repudiation while maintaining confidentiality.
Specific Asymmetric Algorithms
- The primary asymmetric algorithms to know are:
- Diffie-Hellman:
- Named after its inventors, used primarily for conducting key exchanges and secure key distribution.
- Commonly utilized for establishing VPN tunnels, allowing asymmetric algorithms to set up a shared secret for symmetric enciphering securely and at scale.
- Vulnerable to man-in-the-middle attacks; authentication mechanisms (e.g., passwords, digital certificates) are recommended during the exchange process.
- RSA (Rivest–Shamir–Adleman):
- A widely used algorithm for key exchange, encryption, and digital signatures, relying on the difficulty of factoring large prime numbers.
- Supports key sizes between 1024 to 4096 bits.
- Used in secure tokens for multifactor authentication, where a changing six-digit code is generated.
- ECC (Elliptic Curve Cryptography):
- Based on algebraic structures of elliptic curves over finite fields, providing efficient security, especially in mobile devices.
- An ECC 256-bit key is approximately equal in security to a 2048-bit RSA key, making ECC about six times more efficient.
- Commonly employed for low-power computing devices due to the reduced processing requirements.
Variants of ECC
- ECDH (Elliptic Curve Diffie-Hellman): ECC version of Diffie-Hellman for secure key exchange.
- ECDHE (Elliptic Curve Diffie-Hellman Ephemeral): Uses different keys for each segment of the key establishment in the Diffie-Hellman process.
- ECDSA (Elliptic Curve Digital Signature Algorithm): A public key encryption algorithm endorsed by the U.S. Government for digital signatures.
Conclusion
- Asymmetric algorithms, or Public Key Cryptography, utilize two distinct keys for data encryption and decryption.
- Understanding the nuances and applications of Diffie-Hellman, RSA, and ECC is crucial for roles in cybersecurity, particularly as they apply to encryption and secure communications across varying platforms and devices.