5 - Cryptography

Lesson 5.1 Cryptography Basics

Overview

Cryptography—also referred to as cryptology—is the science of protecting data by transforming it into a format that cannot be understood by unauthorized users. At the core of secure communication, cryptography ensures that information remains confidential, unaltered, and verifiable. In this lesson, you’ll explore the fundamental concepts and components of cryptography, from ancient techniques like the Caesar Cipher to modern digital encryption and hashing systems.

Understanding these foundational ideas is essential for any cybersecurity professional responsible for safeguarding data in transit, at rest, and in use.


Key Terms / Concepts

  • Plaintext: Readable or recognizable information before encryption

  • Ciphertext: Unreadable or unrecognizable data after encryption

  • Encryption: The process of converting plaintext to ciphertext

  • Decryption: The process of converting ciphertext back to plaintext

  • Encryption Algorithm / Cipher: A mathematical formula used to perform encryption

  • Key: A secret value used in the encryption and decryption process

  • Hash: A one-way transformation that converts data into a fixed-size output

  • Message Digest: The resulting output from a hashing algorithm

  • Confusion: Complicates the relationship between plaintext and key

  • Diffusion: Spreads out the influence of plaintext over the ciphertext

  • Entropy: Measure of randomness used in key generation

  • Transparency: The practice of open-sourcing encryption algorithms for trustworthiness


Reflection Prompt

Think about the digital services you use daily—email, online banking, messaging apps. How does cryptography protect your private messages and transactions behind the scenes? What might happen if encryption didn’t exist?


Detailed Concepts

What is Cryptography?

Cryptography is the science and practice of securing information by converting it into an unreadable format (ciphertext) using mathematical algorithms and secret keys. Only those with the right key can reverse the process (decrypt) and read the original message (plaintext).

Goals of Cryptography
  • Confidentiality: Only intended parties can access the information

  • Integrity: Information has not been altered

  • Authentication: Verifies identities involved in communication

  • Non-Repudiation: Ensures that someone cannot deny their actions

These goals align with the CIA Triad: Confidentiality, Integrity, and Availability (with cryptography supporting the first two heavily).


Historical Perspective: Classical Ciphers

Caesar Cipher
  • Shifts each letter in a message a set number of positions in the alphabet

  • Example: Shift right by 2 → A becomes C

  • Key = 2; Algorithm = shift

  • Symmetric encryption – same key used to encrypt and decrypt

Substitution Cipher
  • Replaces each character with another (more complex than Caesar)

  • Vulnerable to frequency analysis

Polyalphabetic Cipher (Vigenère Cipher)
  • Uses multiple substitution alphabets to strengthen security

  • Enigma machine: WWII mechanical encryption

Other Methods
  • Vernam Cipher / One-Time Pad: Uses a random key the same length as the message

    • Unbreakable if: key is truly random, used only once, and kept secret

    • Practical issues: key distribution and management

  • Transposition & Book Ciphers: Rearranging letters or using shared book references


Digital Cryptography – Core Components

Method

Description

Symmetric Encryption

One key used for both encryption and decryption (e.g., AES)

Asymmetric Encryption

Uses a pair of keys: public and private (e.g., RSA)

Hashing

One-way transformation that ensures data integrity


Applications of Cryptography

  • Transport Encryption: Secures data as it travels across networks (e.g., HTTPS)

  • Storage Encryption: Protects data saved on disk or in the cloud

  • Memory Encryption: Shields active data in RAM from snooping

  • API Security: Ensures safe app-to-app communication

  • Software Obfuscation: Protects source code from reverse engineering

  • Non-Repudiation: Prevents users from denying they sent or received data

  • Key Exchange: Ensures secure transmission of encryption keys


Cryptographic Principles from Claude Shannon (1949)

  1. The secrecy should match the required effort

  2. Algorithms should not rely on obscurity

  3. Encryption process should be simple to implement

  4. Errors should not affect the rest of the message

  5. Ciphertext should not be larger than plaintext


Simplified Summary

  • Cryptography protects data by turning readable text into unreadable code

  • It uses keys and algorithms to encrypt and decrypt information

  • Classical techniques like Caesar Cipher laid the foundation for digital encryption

  • Hashing checks integrity, while encryption ensures confidentiality

  • Cryptographic methods are essential for secure communication, data protection, and authentication


Real-World Analogies

  • Encryption: Like locking a letter in a safe—only those with the key can open it

  • Hashing: Like fingerprinting a file—if the file changes, its fingerprint changes

  • Caesar Cipher: Like rotating the alphabet to hide your message

  • Symmetric vs Asymmetric: Like using one key for both locking and unlocking (symmetric), vs using a padlock (public key) and a private key only you hold

Lesson 5.2 Symmetric Key Cryptography

Overview

Symmetric key cryptography, also called secret-key or private-key cryptography, is one of the foundational methods for encrypting data. It uses the same key for both encryption and decryption, making it fast and efficient. However, secure key exchange and key management remain significant challenges. This lesson explores the core algorithms, operations modes, and applications of symmetric encryption, including block and stream cipher methods and message authentication codes (MACs).

Understanding symmetric cryptography is essential for professionals securing communications, files, and systems.


Key Terms / Concepts

  • Symmetric Encryption: Encryption using the same key to both encrypt and decrypt

  • Block Cipher: Encrypts fixed-size chunks of data (e.g., AES, 3DES)

  • Stream Cipher: Encrypts data one bit or byte at a time using a keystream

  • Initialization Vector (IV): A random value used with a key for added uniqueness

  • ECB/CBC/CTR/GCM: Block cipher operation modes

  • Message Authentication Code (MAC): Verifies message authenticity and integrity

  • HMAC/CMAC: Hash- or cipher-based MAC algorithms

  • Session Key: A symmetric key used for a single session

  • Key Exchange: Process of securely sharing encryption keys

  • XOR (Exclusive OR): Logical operator used in encryption processes


Reflection Prompt

Consider messaging apps like WhatsApp or Signal. They encrypt your messages using symmetric keys for speed. What challenges would arise if the encryption key were intercepted or reused?


Detailed Concepts

What Is Symmetric Key Cryptography?

Symmetric encryption uses one key to both encrypt and decrypt data. It’s efficient, making it ideal for large volumes of data and real-time applications. Two main types:

  • Block ciphers: Encrypt data in fixed-size chunks

  • Stream ciphers: Encrypt data one bit/byte at a time with a keystream


Key Algorithms in Symmetric Encryption

Algorithm

Description

DES

56-bit key, outdated, first cracked in 1997

3DES


AES

Most widely used today; 128, 192, or 256-bit keys

Blowfish / Twofish

Flexible, secure alternatives

RC5

Part of the Rivest Cipher family; variable block/key sizes

Salsa20

Modern, efficient stream cipher

IDEA

Known for strong encryption, less common today


AES Encryption Process (Simplified)

  1. Key Expansion: Original key expanded into multiple round keys

  2. Initial Round: XOR plaintext with initial key

  3. Main Rounds (9, 11, 13 rounds depending on key length):

    • SubBytes

    • ShiftRows

    • MixColumns

    • AddRoundKey

  4. Final Round: Like previous rounds, but skips MixColumns

AES processes a 4x4 matrix of bytes (the “state”) and uses the XOR operator to mix the key with data.


Block Cipher Modes of Operation

Semantically Secure Modes
  • ECB (Electronic Codebook): Same key on every block; insecure

  • CBC (Cipher Block Chaining): Chains blocks using IV and previous ciphertext

  • CTR (Counter Mode): Encrypts blocks using incrementing counter as IV

Authenticated Modes
  • GCM (Galois/Counter Mode): Combines CTR with integrity checks

  • CCM: Combines CTR and CBC-MAC

  • EtM (Encrypt-then-MAC): Encrypts then authenticates

  • AEAD (Authenticated Encryption with Associated Data): Encrypts while authenticating headers and payload

IVs must be unique per session. CBC improves security over ECB by chaining ciphertext.


Message Authentication Codes (MAC)

A MAC ensures data integrity and verifies the sender's identity.

  • Generation: Sender runs the message through a MAC algorithm (e.g., HMAC with SHA-256) using a shared key

  • Verification: Receiver does the same and compares the result

MAC Type

Description

HMAC

Uses hash functions (e.g., SHA-256)

CMAC

Uses block ciphers (e.g., AES)


Stream Ciphers

  • Encrypts data bit-by-bit using a pseudorandom keystream

  • Common in real-time applications (e.g., streaming, VoIP)

  • Examples: RC4 (deprecated), Salsa20

  • Fast and efficient, but key reuse leads to major vulnerabilities

Stream ciphers are symmetric, ideal for applications requiring speed but challenging for secure key management.


Block vs Stream Cipher Comparison

Feature

Block Cipher

Stream Cipher

Data Size

Fixed blocks

Bit or byte stream

Speed

Slightly slower

Faster

Security

More robust modes

Vulnerable to key reuse

Examples

AES, DES

RC4, Salsa20


Key Lifecycle and Exchange

  • Keys must be rotated frequently (session-based)

  • Two key exchange methods:

    • In-band (e.g., Diffie-Hellman)

    • Out-of-band (e.g., USB, secure meeting)

Secure key exchange is one of symmetric encryption’s biggest challenges.


Issues and Considerations

  • Storage: Where and how to keep keys secure

  • Exchange: How to share keys without interception

  • Algorithm Selection: Choose based on:

    • Supported protocols

    • Industry standards

    • Performance requirements

A 128-bit AES key has 3.4×10³⁸ combinations—strong, but useless if stored or transmitted insecurely.


Simplified Summary

  • Symmetric encryption uses the same key to encrypt and decrypt

  • It's fast and efficient, suitable for large volumes of data

  • Block ciphers work on chunks; stream ciphers on continuous bits

  • Secure key exchange and frequent rotation are essential

  • AES is the current gold standard in symmetric encryption


Real-World Analogies

  • Symmetric Encryption: Like using the same house key to lock and unlock your front door

  • AES Process: Like a complex recipe where steps repeat based on how spicy (secure) you want your dish

  • CBC Mode: Like a chain—each link depends on the last

  • Stream Cipher: Like a walkie-talkie where every word gets encrypted live

Lesson 5.3 Asymmetric Key Cryptography 

Overview

Asymmetric key cryptography, also known as public-key cryptography, revolutionized secure communication by removing the need for shared secrets. Introduced by Diffie and Hellman in 1976, it relies on two mathematically related keys: a public key for encryption and a private key for decryption. While computationally more intensive than symmetric cryptography, it solves critical problems like secure key exchange and digital signatures.

This lesson explores asymmetric cryptography, its algorithms, practical use cases, and emerging concerns like quantum threats.


Key Terms / Concepts

  • Asymmetric Encryption: Uses a pair of keys—one public, one private

  • Public Key: Shared freely, used to encrypt or verify

  • Private Key: Kept secret, used to decrypt or sign

  • RSA: A foundational asymmetric encryption algorithm

  • DSA/ECDSA: Digital signature algorithms

  • Elliptic Curve Cryptography (ECC): Efficient public-key algorithm

  • Diffie-Hellman (DH): A method for secure key exchange

  • FIPS 140-3: U.S. cryptographic module validation standard

  • Post-Quantum Cryptography (PQC): Encryption designed to resist quantum attacks


Reflection Prompt

When you visit a secure website (https), how do you know you're really talking to the right server and not an attacker? Think about how asymmetric cryptography might play a role in that trust.


Detailed Concepts

What Is Asymmetric Cryptography?

Asymmetric encryption uses two keys:

  • A public key that can be distributed to anyone

  • A private key that is kept secret by the owner

If someone encrypts data with your public key, only you can decrypt it using your private key.

Invented in 1976 by Diffie and Hellman for digital signatures


How It Works – Example Flow

  1. Bob generates a public/private key pair

  2. He shares his public key with Alice

  3. Alice encrypts a message using Bob’s public key

  4. Only Bob can decrypt it using his private key

  5. Secure communication without exchanging a shared key beforehand

ALICE

image.png

BOB

Limitation: While Alice knows only Bob can read the message, Bob cannot confirm Alice’s identity.


Why It Matters

  • Solves Key Exchange Problems

  • Enables Digital Signatures

  • Powers TLS/SSL (HTTPS), secure email, VPN authentication

Asymmetric encryption is slower than symmetric encryption and uses much longer keys to achieve similar security levels.


Major Asymmetric Algorithms

Algorithm

Purpose

Notes

RSA

Encryption & signatures

Based on two large primes

DSA

Digital signatures only

Government-backed standard

ECC

Encryption & signatures

Efficient with smaller keys

ECDSA

ECC-based signature algorithm

Used in cryptocurrency (e.g., Bitcoin)

Diffie-Hellman (DH)

Key exchange

Not for direct encryption


Cryptographic Modules

  • A cryptographic module is a validated component (software or hardware) that implements cryptographic functions

  • Must meet standards like FIPS 140-3, validated by NIST

  • Federal agencies are required to use validated modules

  • Enterprises often follow suit for compliance and assurance


Quantum Cryptography Threat

Quantum computers pose a threat to asymmetric encryption because:

  • They can solve problems (like factoring large primes) much faster

  • This could break algorithms like RSA and ECC

Symmetric encryption is less impacted by quantum computing.


Quantum-Safe Cryptography

  • Post-Quantum Cryptography (PQC) is the term for new algorithms designed to resist quantum attacks

  • NIST is standardizing quantum-resistant algorithms

  • As of December 2024, ~30.7% of Internet-based asymmetric cryptography was post-quantum

Term

Meaning

Quantum Safe

Algorithms immune to quantum computer attacks

PQC

May refer to algorithms or broader quantum-era cryptography

Lattice-based / Code-based Crypto

Types of quantum-safe systems being studied


Simplified Summary

  • Asymmetric encryption uses a public and private key pair

  • Enables secure key exchange and digital signatures

  • Algorithms include RSA, ECC, and DSA

  • Slower than symmetric encryption but ideal for authentication

  • Quantum computing threatens current algorithms, pushing us toward post-quantum cryptography


Real-World Analogies

  • Public Key: Like a locked mailbox—anyone can drop in a letter, but only you (with the key) can open it

  • Digital Signature: Like a notarized document—it proves you authored it

  • Quantum Threat: Like someone inventing a universal master key—forcing us to redesign locks

Lesson 5.4 Cryptographic Hashing 

Overview

Cryptographic hashing is the process of transforming data into a fixed-length output using a one-way mathematical function. Even a single-bit change in the input data results in a drastically different output. These hashes are crucial in cybersecurity for validating data integrity, securely storing passwords, and supporting encryption processes.

Unlike encryption, hashing is irreversible—there’s no way to recover the original input from the hash. This lesson covers how hashing works, key algorithms, and why it's fundamental to modern security systems.


Key Terms / Concepts

  • Hash Function: One-way function that converts data into a fixed-length output

  • Message Digest: The resulting value from a hash function

  • Checksum: A basic type of hash used for detecting errors

  • Avalanche Effect: A small change in input causes a large change in output

  • Deterministic: The same input always produces the same output

  • Collision Resistance: It is difficult to find two different inputs that result in the same hash

  • Cryptographic Hash Function: A secure form of hashing used in security applications

  • Non-Cryptographic Hash: Used in databases or indexing, not for security

  • Password Hashing: Converting passwords into irreversible hashes for storage


Reflection Prompt

If someone modifies a file on your system, how could you tell it’s been changed without checking every line of content? Think about how hashes might help verify file integrity.


Detailed Concepts

What Is Cryptographic Hashing?
  • A hash is a fixed-length representation of data

  • The process is one-way: you cannot go backward from the hash to the original data

  • Even a tiny change in the input drastically changes the hash output (avalanche effect)

Basic types:

  • Check Digit: 1-digit validation

  • Checksum: Simple integrity check

  • Message Digest: Secure hash output used in cryptography


Applications of Cryptographic Hashing

Application

Purpose

Data Integrity

Ensures a file or message wasn’t altered during transmission

Password Storage

Stores passwords as hashes instead of plaintext

Key Generation

Provides randomness for generating cryptographic keys

Digital Signatures

Uses hash of the message before signing

Blockchain

Each block includes a hash of its contents and the previous block

Hashes are used anywhere you want to detect tampering or verify identity without revealing the original data.


Popular Hash Algorithms

Algorithm

Notes

MD5

Fast but vulnerable to collisions; obsolete

SHA-1

Better than MD5, but also now considered insecure

SHA-2 (SHA-256, SHA-512)

Modern standard, used widely

SHA-3

Successor to SHA-2; not yet widely adopted

RIPEMD

Used in OpenSSL and some crypto systems; European standard


Key Benefits and Requirements

A cryptographic hash must be:

  • Deterministic: Same input → same output

  • Efficient: Fast to compute

  • Irreversible: Cannot derive original data from hash

  • Collision-Resistant: Hard to find two inputs that hash to same value

  • Avalanche-Prone: Small input changes → vastly different output


Avalanche Effect Example

Changing one bit in a document might change the entire hash:

Input

Hash Output (SHA-256)

"Password1"

5e884898da280...

"Password2"

6cb75f652a9b5...

This unpredictability is what makes hashing secure and effective for authentication and integrity checks.


Simplified Summary

  • A cryptographic hash transforms data into a secure fingerprint

  • Hashing is irreversible, unlike encryption

  • Widely used in data integrity, password protection, and digital signatures

  • Secure hashes exhibit the avalanche effect and resist collisions


Real-World Analogies

  • Hashing a file is like sealing it in a tamper-proof envelope; if anything inside changes, the seal no longer matches

  • Password hashing is like storing someone’s fingerprint rather than their face—you can verify them without knowing exactly what they look like

  • Avalanche effect is like dropping one grain of sand that causes a massive avalanche—small input, big impact

Lesson 5.5 Cryptographic Applications 

Overview

Now that you understand the core components of cryptography—symmetric encryption, asymmetric encryption, and hashing—this lesson ties those pieces together by showing how they are used in real-world security systems. Cryptographic applications power secure communications, user authentication, digital validation, and blockchain technology. These applications are foundational to digital trust, privacy, and integrity in today's interconnected systems.

By seeing how these methods work in practice, you’ll better appreciate the essential role cryptography plays in everything from signing into websites to securing international finance.


Key Terms / Concepts

  • Key Exchange: The secure transfer of cryptographic keys between parties

  • Authentication: Verifying the identity of a user or system

  • Digital Signature: Confirms the authenticity and integrity of a message

  • PKI (Public Key Infrastructure): A framework for managing digital certificates and public-key encryption

  • Blockchain: Distributed ledger secured by cryptographic hashes and consensus protocols

  • Checksum / Hash Validation: Verifies that a downloaded or transferred file has not been altered


Reflection Prompt

Think about the last time you downloaded a file or logged into a secure website. How did you know the file wasn’t altered or that the site was authentic? Which cryptographic tools might have been working behind the scenes?


Detailed Concepts

What We Know So Far

Concept

Key Properties

Symmetric Key Cryptography

Uses one shared key for both encryption and decryption. It's fast but key exchange is a challenge.

Asymmetric Key Cryptography

Uses a public/private key pair. Slower but ideal for authentication and key exchange.

Cryptographic Hashing

One-way transformation used for integrity verification; not reversible.


Key Cryptographic Applications

1. Secure Key Exchange

Cryptography enables two parties to securely exchange encryption keys over an insecure channel.

  • Diffie-Hellman and asymmetric encryption enable secure sharing without pre-established trust

  • Essential for establishing session keys in symmetric encryption

2. Identity and Access Management (IAM)

Cryptography helps verify users and control access to systems.

  • Passwords are stored using hashing (e.g., bcrypt, SHA-256)

  • Digital certificates are used for multi-factor authentication

  • Public key encryption ensures credential confidentiality

3. File Integrity Verification

When downloading a file, cryptographic hash values are often provided.

  • Hashes like SHA-256 allow users to verify that the file hasn’t been modified

  • If the hash value matches, the file is confirmed to be authentic and unaltered

4. Digital Signatures

Digital signatures confirm both integrity and authenticity of data or communications.

  • The sender hashes the message and encrypts the hash with their private key

  • The recipient decrypts it with the sender’s public key and compares the hash

Used in secure emails, software signing, and contracts

5. Blockchain and Distributed Ledgers

Each block in a blockchain contains:

  • A hash of the previous block

  • A list of transactions and a timestamp

  • A new hash computed over the current block

This creates a chain of trust. Any tampering changes the hashes, invalidating the chain.

Bitcoin and Ethereum rely on cryptographic hashing and digital signatures

6. Public Key Infrastructure (PKI)

PKI supports the management of digital certificates and key pairs.

  • Maintains a trusted certificate authority (CA)

  • Verifies identities of users or systems

  • Underpins SSL/TLS, secure email, and more

Without PKI, the internet would not be trusted or secure


Simplified Summary

  • Key Exchange: Securely shares keys using asymmetric encryption

  • Authentication: Validates users with passwords, certificates, and hashes

  • Digital Signatures: Confirms who sent a message and that it hasn’t changed

  • File Integrity: Uses hashes to check if files have been tampered with

  • Blockchain: Uses chained hashes and cryptographic proofs to record data

  • PKI: Manages trust and encryption on the internet


Real-World Analogies

  • Digital Signature: Like notarizing a document—proves who signed it and that it wasn’t altered

  • Hash Validation: Like sealing a jar—if the seal is broken, you know it was tampered with

  • Blockchain: Like a tamper-evident ledger—each page includes a summary of the previous page

Lesson 5.6 Secure Key Exchange 

Overview

Secure key exchange is a foundational requirement in modern cryptographic systems. While symmetric encryption is fast and efficient, it requires both parties to share a secret key—posing a challenge when communicating over insecure networks. This is where asymmetric methods like the Diffie-Hellman Key Exchange come into play.

This lesson focuses on the key exchange problem and introduces you to one of the oldest and most enduring solutions: the Diffie-Hellman protocol. You'll learn how it works and why it's still vital in today's security protocols.


Key Terms / Concepts

  • Key Exchange: The secure sharing of cryptographic keys between parties

  • Symmetric Key: A single key used for both encryption and decryption

  • Diffie-Hellman Key Exchange (DHKE): Protocol for secure key exchange over a public channel

  • Public Parameters: Agreed-upon numbers used by both parties

  • Prime Number (p): A large prime number used in DH calculations

  • Generator (g): A base number used in key generation

  • Modulus Operation: A mathematical function used to limit the size of results


Reflection Prompt

If two people want to exchange a secret note across a public classroom, how could they agree on a code without everyone else overhearing? What if they each had a trick that allowed them to share a secret using only numbers and colors?


Detailed Concepts

The Key Exchange Problem
  • Symmetric encryption is fast but requires a shared key

  • Physically exchanging keys is not always possible or safe

  • Diffie-Hellman allows secure key exchange even over insecure networks


Diffie-Hellman Key Exchange

  • First proposed in 1976 by Whitfield Diffie and Martin Hellman

  • Allows two parties to establish a shared secret without sharing private values

  • Supports symmetric encryption by generating a shared key


Paint-Mixing Analogy

A simplified way to understand Diffie-Hellman:

  1. Alice and Bob agree on a base color (public value)

  2. Each chooses a secret color (private value)

  3. They mix their secret with the base color and share the mixture

  4. Each then mixes the received color with their own secret color

  5. Both end up with the same mixed color, which becomes their shared secret key

Even if an attacker sees the shared mixes, they can’t easily reverse-engineer the secret components.


Number Analogy – Step-by-Step

Step 1: Public Agreement
  • Choose a large prime number (p) and a base (g)

  • These values are publicly known

Step 2: Secret Selection
  • Alice chooses a secret number a

  • Bob chooses a secret number b

Step 3: Public Key Generation
  • Alice computes A = g^a mod p

  • Bob computes B = g^b mod p

  • They share A and B with each other

Step 4: Shared Secret Calculation
  • Alice computes S = B^a mod p

  • Bob computes S = A^b mod p

  • Both arrive at the same shared secret (S)


Why Is It Secure?

  • Even though g, p, A, and B are public, an attacker cannot easily compute S without knowing a or b

  • This problem is known as the Discrete Logarithm Problem—hard to reverse

The security of Diffie-Hellman relies on the difficulty of solving large modular exponentiation problems.


Visual Summary

Step

Alice

Bob

Choose Secret

a

b

Compute Public Key

A = g^a mod p

B = g^b mod p

Exchange Keys

← A →

← B →

Compute Shared Key

S = B^a mod p

S = A^b mod p


Simplified Summary

  • Key exchange is required for symmetric encryption to function securely

  • Diffie-Hellman enables this over public channels

  • It uses prime numbers and modular math to generate a shared secret

  • Attacks are difficult due to the complexity of reverse-engineering exponents


Real-World Analogies

  • Paint-Mixing: You and a friend each mix paint in secret, but end up with the same final color without revealing your ingredients

  • Number Locks: You both set a dial to a secret position, exchange dial readings, then apply your own secret again and get the same lock code

Lesson 5.7 Passwords and Hashing  

Overview

Passwords are the most common form of authentication, and securely storing them is a critical cybersecurity function. Storing passwords as plain text would be a massive security risk—so modern systems use hashing algorithms to store a secure representation of the password. This lesson covers how password hashing works, the role of salts and peppers, and modern password storage algorithms such as bcrypt and PBKDF2.

By the end of this lesson, you'll understand how operating systems store passwords securely and the techniques used to resist cracking attacks.


Key Terms / Concepts

  • Password Hashing: Irreversible process of converting a password into a hash

  • Salt: A unique value added to a password before hashing

  • Pepper: A hidden value added to strengthen password hashing

  • Rainbow Table: A precomputed list of hashes used to reverse simple hashed passwords

  • bcrypt / PBKDF2 / scrypt / Argon2: Modern password hashing algorithms

  • NTLM: Legacy Microsoft password hashing method


Reflection Prompt

Think about the passwords you’ve created online. What would happen if a site got hacked and stored your passwords in plain text? How does hashing protect you—and what risks still remain?


Detailed Concepts

How Password Hashing Works
  1. User enters password to log in

  2. The system hashes the password using a secure hash function

  3. It compares the resulting hash to the stored hash in the password database

  4. If they match, access is granted

Important: The system never stores or transmits the actual password—only its hash.


Example: Traditional UNIX Systems

  • Early Linux systems stored password hashes in /etc/passwd

  • These were readable by all users

  • Vulnerable to rainbow table attacks—a technique that compares known hash outputs to precomputed tables of password hashes

A line from a Linux Passwd file

mark:x:1001:1001:mark,,,:/home/mark:/bin/bash

[--] - [--] [--] [-----] [--------] [--------]

|    |   |    |     |         |        |

|    |   |    |     |         |        +-> 7. Login shell

|    |   |    |     |         +----------> 6. Home directory

|    |   |    |     +--------------------> 5. GECOS

|    |   |    +--------------------------> 4. GID

|    |   +-------------------------------> 3. UID

|    +-----------------------------------> 2. Password

+----------------------------------------> 1. Username

Salting and Peppering Passwords

Salt
  • A random, unique value added to each password before hashing

  • Stored alongside the hash in plaintext

  • Prevents the use of a single rainbow table against multiple passwords

Pepper
  • A secret value, not stored with the hash

  • Introduced in NIST's 2017 password guidelines

  • Makes it harder to reverse-engineer individual hashes, even if the salt is known


Modern Password Storage Algorithms

NTLM (NT LAN Manager)
  • Used by older Windows systems

  • Relies on MD5, which is now broken

  • No longer recommended; deprecated in Windows Server 2025

bcrypt
  • Built on the Blowfish algorithm

  • Uses a 128-bit salt and produces a 184-bit hash

  • Supports key stretching to slow brute-force attacks

PBKDF2 (Password-Based Key Derivation Function 2)
  • IETF standard created by RSA

  • Combines passwords with salt and HMAC

  • Slower and more customizable than bcrypt, but generally weaker

  • Still used in some enterprise applications


Other Secure Hashing Algorithms

Algorithm

Notes

scrypt

Builds on bcrypt with increased memory-hardness; good for defending against ASICs

Argon2

Winner of the Password Hashing Competition; supports multiple modes of resistance (time, memory, parallelism)

SHA-based Hashing

Avoid using SHA-1 or MD5 for password hashing due to known collisions

bcrypt, scrypt, and Argon2 are recommended for new systems requiring strong password protection.


Simplified Summary

  • Passwords are stored as hashes, not plaintext

  • Salt is used to make each hash unique and resist rainbow table attacks

  • Pepper adds a hidden security layer

  • Modern systems use bcrypt, PBKDF2, scrypt, or Argon2 for secure password storage

  • Legacy algorithms like NTLM should no longer be used


Real-World Analogies

  • Hashing a password is like shredding a document—you can verify what was shredded by its pieces, but you can’t put it back together easily

  • Salt is like adding a drop of unique ink to each paper before shredding—it ensures no two documents look the same

  • Pepper is a secret trick you never reveal—only you know how you shredded the document

Lesson 5.8 File Validation and Hashing

Overview

In cybersecurity, ensuring the integrity and authenticity of downloaded files is critical. A malicious actor could tamper with a file during transmission or replace it entirely. File validation through cryptographic hashing provides a reliable way to verify that a file is authentic and unmodified. This lesson explores how hash functions, checksums, and digital signatures help users and systems confirm file integrity, especially during downloads and software installations.


Key Terms / Concepts

  • File Validation: Verifying that a downloaded or transferred file has not been altered

  • Hash/Checksum: A fixed-length representation of a file’s contents

  • SHA-256 / MD5 / SHA-1: Common hashing algorithms used for file integrity

  • Digital Signature: A cryptographic mechanism used to verify the source and integrity of a file

  • PGP (Pretty Good Privacy): Encryption tool used to sign and verify files

  • Automated Verification: System-level processes that verify files automatically during download or installation


Reflection Prompt

When you download a software installer or update, how do you know it hasn’t been tampered with? Why might verifying the file’s hash or signature be important?


Detailed Concepts

Why File Validation Matters

Imagine downloading a program from a public website. Without file validation:

  • You could install malware instead of the intended software

  • A corrupted download might result in data loss or application failure

File validation ensures the file has not been modified or corrupted in transit.


How File Validation Works

  1. Publisher creates a hash of the original file (e.g., using SHA-256)

  2. The hash is posted alongside the download

  3. You download the file and then run the same hash algorithm on it

  4. Compare the two hashes

    • If they match → File is valid

    • If not → File may be corrupted or tampered with


Checksums & Hashes

  • Checksum is often used interchangeably with hash

  • Common formats: MD5, SHA-1, SHA-256, SHA-512

  • Example:

    • Publisher posts: SHA256: 3a5f8c...

    • You compute your own hash of the downloaded file

    • If it matches, the file hasn’t changed


Digital Signatures

  • Some files are digitally signed using tools like PGP

  • The signature confirms both:

    • The origin (it came from a trusted source)

    • The integrity (it hasn’t been altered)

  • Used in:

    • Secure software distribution

    • Open-source repositories (e.g., GitHub, SourceForge)

    • Operating system update files

Digital signatures go one step beyond hash comparison—they verify who created the file.


Automated File Verification

Modern systems often validate files without user intervention:

  • Package Managers (e.g., apt, yum, Homebrew) automatically verify software before installation

  • Web browsers check file headers and hashes

  • Operating systems block execution if a file fails integrity checks or lacks a trusted signature


Browser & OS Protections

  • Browsers may block or warn about:

    • Files with invalid or missing digital signatures

    • Files commonly flagged as malicious

  • OS-level protections include:

    • Windows SmartScreen

    • Gatekeeper (macOS)

    • Antivirus hash scanning before opening a file


Simplified Summary

  • File validation ensures downloaded files are safe and unchanged

  • Users verify hashes or digital signatures to confirm file authenticity

  • Automated systems often perform this verification silently in the background

  • Common algorithms include SHA-256 and MD5 (though MD5 is less secure)


Real-World Analogies

  • Hash Check: Like checking a barcode—you know the item is correct if the code matches

  • Digital Signature: Like a tamper-proof seal on a bottle—if it’s broken, the product may have been altered

  • Automated Validation: Like airport luggage scanners that check for contraband without you doing anything

Lesson 5.9 Digital Signatures and Public Key Infrastructure (PKI)

Overview

Digital signatures are essential for verifying the authenticity and integrity of digital communications. Paired with a trusted infrastructure for issuing and managing public keys—known as Public Key Infrastructure (PKI)—they help establish trust in digital environments. This lesson explores how digital signatures work, the role of digital certificates, and how PKI supports secure communications, user authentication, and system validation.


Key Terms / Concepts

  • Digital Signature: Encrypted hash proving message origin and integrity

  • Public Key Infrastructure (PKI): Framework for managing digital certificates

  • Certificate Authority (CA): Entity that issues and verifies digital certificates

  • Digital Certificate: Verifies a public key’s association with an entity

  • CSR (Certificate Signing Request): Request submitted to a CA to issue a certificate

  • CRL (Certificate Revocation List): List of revoked certificates

  • OCSP (Online Certificate Status Protocol): Checks certificate status in real time

  • S/MIME / Code Signing / SAN / Wildcard / EV Certificates: Specialized certificate types


Reflection Prompt

Think about secure websites, encrypted emails, or downloaded software. How do you know that what you're seeing is legitimate and came from a trusted source?


Detailed Concepts

 

Digital Signature Process

  1. Hashing the Message
    The sender creates a hash of the message (e.g., SHA-256)

  2. Signing the Hash
    The hash is encrypted with the sender’s private key, creating a digital signature

  3. Transmitting Message + Signature
    Both the message and signature are sent to the recipient

Verification

  • Recipient decrypts the signature using the sender’s public key

  • Recipient hashes the received message

  • If the two hashes match, the message is authentic and unaltered


image.png

The Trust Problem

How does the recipient know the public key really belongs to the sender?

  • What if someone is impersonating the sender?

  • That’s where digital certificates come in


Digital Certificates

A digital certificate is a signed file that proves:

  • The identity of the certificate holder

  • The authenticity of the public key

  • The certificate’s usage and expiration


Components Include:

  • Public Key

  • Owner’s identity

  • Hash of the key

  • Validity period

  • Intended key usage

  • CA’s digital signature(s)


Certificate Trust Models

Model

Description

Self-Signed

The owner signs their own certificate. Not inherently trustworthy

PKI-Based

A CA verifies and signs the certificate

Web of Trust

Others (peers) sign and vouch for your identity in a decentralized model


Certificate Authorities (CAs)

  • Issue, verify, and revoke certificates

  • Follow a Certificate Practice Statement (CPS) that outlines rules for verification, issuance, and revocation

  • Work with Registration Authorities (RAs) for identity validation


image.png

Root Certificates and Registration Authorities

  • Root Certificate: Self-signed and used to sign other certificates

  • RA: Confirms the identity of applicants and forwards info to CA

  • Public Certificate Authorities and internal enterprise CAs both play roles


Certificate Generation Process

  1. User generates a key pair

  2. Submits a CSR to the CA

  3. CA or RA verifies identity

  4. CA signs and issues the certificate

  5. Certificate is deployed for use


PKI Lifecycle Overview

Stage

Description

Request

Entity submits a CSR to the CA

Issuance

CA verifies and issues certificate

Deployment

Installed on servers, users, etc.

Monitoring

Track expiration and revocation status

Renewal

Issued again before expiration

Revocation

Marked as invalid due to compromise or retirement

Expiration

Certificate is removed from use

 


Certificate Revocation

Method

Description

CRL

Downloadable list of revoked certificates

OCSP

Real-time protocol to verify certificate status via CA


Types of Digital Certificates

Type

Purpose

Domain Validation (DV)

Validates ownership of a domain

User/Machine Auth

For identity and system validation

Email (S/MIME)

Encrypts/signs emails

Code Signing

Verifies software authenticity

SAN / Wildcard

Supports multiple domains/subdomains

EV

Extended validation for high-assurance identity

Qualified

Issued by a QTSP for legal compliance


Certificate Expiration

  • Applications may warn, allow manual override, or block expired certificates

  • Expired certificates must be renewed, often via a streamlined version of original request


Certificate Protection and Key Recovery

  • Trusted root certs don’t hold secrets but shouldn’t be modified without permission

  • Private keys should never be exposed—store them securely

  • Some systems support key recovery, separate backup, or hardware key storage modules


Simplified Summary

  • Digital signatures prove identity and integrity using public/private keys

  • PKI enables global trust with certificates issued by Certificate Authorities

  • Certificates validate public keys and can be revoked, renewed, or monitored

  • Trust models range from self-signed to enterprise-wide PKI

  • Certificate lifecycle includes creation, issuance, monitoring, and expiration


Real-World Analogies

  • Digital Signature: Like a handwritten signature and wax seal combined

  • CA: Like a notary public verifying your ID before letting you sign a legal document

  • CRL/OCSP: Like a background check database ensuring a license or credential hasn’t been revoked

Lesson 5.10 PKI Applications 

Overview

Public Key Infrastructure (PKI) is the backbone of modern digital trust. Its applications span from secure websites and encrypted emails to software validation and internal organizational security. This lesson highlights key PKI applications including the TLS handshake, digital certificates for software, and email security. You’ll also learn about the role of self-signed certificates and the differences between internal and public trust models.


Key Terms / Concepts

  • TLS (Transport Layer Security): Protocol securing internet communication

  • Certificate Authority (CA): Issues and validates digital certificates

  • Digital Certificate: Proves the identity of a server, user, or device

  • S/MIME: Email encryption and signature protocol

  • Code Signing: Verifies software authenticity and integrity

  • Self-Signed Certificate: Certificate not issued by a CA—trusted internally only

  • Wildcard / SAN / EV Certificates: Types of TLS certificates with varying scopes and validation levels


Reflection Prompt

When visiting a secure website or downloading an application, what tells your device or browser that it's safe to proceed? What role do certificates and PKI play in that decision?


Detailed Concepts

TLS Certificates and Applications

TLS certificates are used to encrypt communications between browsers and websites. These certificates:

  • Are issued to a domain, server, or device

  • Help authenticate identity and secure data

  • May contain organizational information, including:

    • Subject name

    • Validity period

    • Intended usage (e.g., encryption or authentication)

Types of TLS Certificates:

Type

Description

Domain Validation

Verifies domain ownership

Wildcard

Covers multiple subdomains

Subject Alternative Name (SAN)

Supports multiple domain names

Extended Validation (EV)

Highest level of identity verification


TLS Handshake Process

The TLS handshake sets up a secure communication channel between client and server.

Step 1: Client Hello

  • Client sends supported TLS versions, cipher suites, and a random value

Step 2: Server Hello

  • Server responds with selected options, another random value, and its digital certificate

Step 3: Certificate Validation

  • Client checks if certificate is valid and trusted

Step 4: Server Hello Done

  • Indicates server is finished sending preliminary information

Step 5: Key Exchange

  • RSA: Client encrypts a pre-master secret with server’s public key

  • Diffie-Hellman: Both parties compute a shared key collaboratively

Step 6: Key Generation

  • Client and server generate symmetric session keys

Step 7: Cipher Exchange

  • Client and server exchange cipher specs and finalize encryption settings

Step 8: Secure Communication Begins

  • Data is encrypted with shared key

  • Messages include integrity mechanisms like HMAC

 


TLS Summary

  • Authentication: Server identity is verified

  • Encryption: Session key encrypts data

  • Integrity: HMAC prevents message tampering


Code Signing Certificates

Used by software developers to:

  • Sign apps, scripts, or installers

  • Prove code hasn’t been modified after signing

  • Provide users with confidence in software origin

Unsigned or self-signed downloads usually trigger security warnings.


Email Certificates – S/MIME

  • Encrypt and sign emails

  • Primarily used internally within organizations

  • Ensures:

    • Sender authenticity

    • Message confidentiality

    • Message integrity

Rarely used in public consumer email services.


Self-Signed Certificates

  • Created without a CA

  • Used for internal services or testing

  • Browsers and OSs do not trust them by default

Advantage

Risk

Free and easy

No external validation

Useful internally

Users may ignore warnings on real threats


Simplified Summary

  • PKI is used in web browsing (TLS/SSL), software distribution (code signing), and secure messaging (S/MIME)

  • TLS handshake securely negotiates a session between a client and server

  • Certificates can be publicly trusted or self-signed depending on usage

  • Without proper validation, data and identities are vulnerable to attack


Real-World Analogies

  • TLS Handshake: Like exchanging IDs and agreeing on a secret handshake before speaking in a secure room

  • Code Signing: Like sealing a document with a wax seal—if the seal’s intact, the document is authentic

  • Self-Signed Certs: Like writing your own ID badge—it works in your building, but not in public

Lesson 5.11 Symmetric Key Applications 

Overview

Symmetric key encryption is widely used for securing stored data—commonly referred to as data at rest. Operating systems, databases, and applications all leverage symmetric encryption to protect sensitive information from unauthorized access, especially in cases of theft or system compromise. In this lesson, we’ll explore real-world applications of symmetric encryption, including Windows BitLocker, the Encrypting File System (EFS), and database encryption techniques.


Key Terms / Concepts

  • Data at Rest Encryption: Protecting stored (inactive) data using encryption

  • BitLocker: Full-volume encryption in Windows

  • Encrypting File System (EFS): File- and folder-level encryption

  • FEK (File Encryption Key): Temporary key used to encrypt file contents

  • TPM (Trusted Platform Module): Secure hardware for storing keys

  • Transparent Encryption: Encrypts without user interaction

  • Column-Level Encryption: Secures specific fields within a database

  • Data Recovery Agent (DRA): Backup user account for decryption


Reflection Prompt

Consider your laptop getting lost or stolen—how could encryption prevent your sensitive data from falling into the wrong hands? What are the advantages and limitations of encrypting individual files versus the entire disk?


Detailed Concepts

Data at Rest Encryption

Symmetric encryption is commonly used to protect stored data. Key examples include:

1. Windows BitLocker
  • Encrypts the entire disk volume

  • Helps prevent unauthorized access when a system is lost or stolen

  • Prevents users from removing disks and reading them on other devices

  • Uses AES with CBC mode and stores the key on the TPM chip

  • Recovery options:

    • Offline recovery key

    • Data Recovery Agent (DRA)

Introduced in 2007, BitLocker is now available in Windows 11 Home (not supported in previous Home editions)

Linux Equivalents:

  • dm-crypt, LUKS (Linux Unified Key Setup)


2. Windows Encrypting File System (EFS)
  • Encrypts individual files or folders on NTFS volumes

  • Supported on all Windows editions except Home

  • Allows users to share encrypted files by adding other users’ public keys

Encryption Process:

Step

Action

1

System creates a File Encryption Key (FEK)

2

FEK encrypts file contents with AES

3

FEK is encrypted with user's public key

4

Encrypted FEK is stored with the file

Decryption Process:

Step

Action

1

User's private key decrypts the FEK

2

FEK decrypts the file

Linux Equivalents:

  • EncFS, Tomb, VeraCrypt


3. EFS Data Recovery Agent (DRA)
  • An alternate account that can decrypt files

  • Used to be the administrator by default

  • No longer set automatically—must be defined in:

    • Group Policy (local)

    • Active Directory (domain)

Good practice: configure a DRA for file recovery and backup key storage securely.


Database Encryption Techniques

Databases also use symmetric encryption for data at rest:

Type

Description

Transparent Encryption

Encrypts and decrypts data automatically without user interaction

Column-Level Encryption

Encrypts specific sensitive fields (e.g., SSNs or credit cards); complex to manage

Application-Level Encryption

Managed by the app itself; offers flexibility but shifts responsibility to developers


Simplified Summary

  • BitLocker encrypts entire disks to protect against physical theft

  • EFS encrypts individual files using a FEK + public key method

  • Databases use transparent or column-level encryption for sensitive data

  • Recovery methods include Data Recovery Agents and key backup

  • Linux and open-source equivalents exist for all major Windows encryption tools


Real-World Analogies

  • BitLocker: Like putting your entire laptop in a safe that only you can open

  • EFS: Like locking individual drawers in your file cabinet

  • Column-Level Encryption: Like redacting sensitive fields in a document while leaving the rest visible

  • TPM: Like a vault inside your computer that stores the encryption key

Lesson 5.12 Encryption Packages 

Overview

Encryption packages bundle together tools and protocols that support secure communication, file protection, and certificate management. This lesson focuses on three widely used encryption packages: Pretty Good Privacy (PGP), GNU Privacy Guard (GPG), and OpenSSL. Each serves a unique role in modern cybersecurity, from encrypting email to powering secure websites.

These tools demonstrate how encryption is implemented and maintained across platforms and applications, and they often form the foundation of real-world encryption strategies.


Key Terms / Concepts

  • PGP (Pretty Good Privacy): Early hybrid encryption tool for secure email and files

  • GPG (GNU Privacy Guard): Open-source replacement for PGP

  • OpenSSL: Software library supporting SSL/TLS and encryption protocols

  • Web of Trust: Peer-based trust model used by early PGP

  • Hybrid Cryptographic Model: Combines symmetric and asymmetric encryption

  • X.509 Certificates: Digital certificates used to verify identity and support encrypted communication


Reflection Prompt

Have you ever sent or received a secure email, or visited a website with a padlock icon? What tools or encryption packages made that possible?


Detailed Concepts

Pretty Good Privacy (PGP)

  • Created in 1991, before encryption was built into most systems

  • Designed for email and file encryption

  • Uses a hybrid cryptographic model:

    • Encrypts the message with a symmetric key

    • Encrypts the symmetric key with the recipient’s public key

Original PGP Features:

  • Personal web of trust for public key validation

  • Used for:

    • Secure email communication

    • File encryption

    • Disk encryption

PGP became commercialized in 1997. While still used, its core ideas were adopted by modern systems.


GNU Privacy Guard (GPG)

  • Open-source implementation of PGP

  • Released in 1999

  • Command-line utility (but often used through graphical interfaces)

Key Features:

  • Free and open-source

  • Cross-platform (Linux, macOS, Windows)

  • Hybrid encryption

  • Compatible with email clients, file systems, and automation tools

GPG is widely used in open-source communities, DevOps workflows, and secure file sharing.


OpenSSL

  • A robust, open-source software library for implementing SSL/TLS and cryptographic functions

  • Powers HTTPS websites, VPNs, and secure application protocols

Common Use Cases:

  • Encrypting web traffic (TLS)

  • Creating and managing X.509 certificates

  • Performing encryption, decryption, hashing, and digital signatures

  • Generating and verifying CSRs (Certificate Signing Requests)

Why It’s Important:

  • Installed by default on many Linux systems

  • Widely adopted in secure web services and infrastructure

  • OpenSSL powers a large portion of the encrypted internet


OpenSSL Capabilities

Feature

Description

Cryptographic Functions

AES, RSA, SHA, and other encryption and hashing algorithms

Certificate Management

Create, sign, revoke, and validate digital certificates

Cross-Platform

Supports Windows, Linux, and macOS environments

Automation Ready

Easily scripted in DevOps, CI/CD, and security pipelines


Simplified Summary

  • PGP: Early secure messaging tool that used asymmetric encryption and web of trust

  • GPG: Free and open version of PGP used across platforms and tools

  • OpenSSL: The most widely used encryption library for securing network communication, particularly via TLS


Real-World Analogies

  • PGP: Like mailing a letter in a locked box and sharing the key with a friend

  • GPG: Like an open-source version of that locked box—available to anyone, but still secure

  • OpenSSL: Like the plumbing behind every secure website, email, and VPN—it’s hidden but critical

Lesson 5.13 Cryptanalytic Attacks 

Overview

Cryptanalytic attacks target the design or implementation of encryption systems in an attempt to reveal secret information—especially the encryption key—without authorized access. These attacks are essential to study because they highlight the potential weaknesses in even the strongest cryptographic systems. Understanding these methods is crucial for anticipating vulnerabilities and strengthening system security.

This lesson introduces the major types of cryptanalytic attacks, including brute force, side-channel, timing, and hash manipulation techniques.


Key Terms / Concepts

  • Brute Force Attack: Tries every possible key combination

  • Ciphertext-Only Attack: Relies solely on intercepted ciphertext

  • Known Plaintext Attack: Involves matching known plaintext and ciphertext

  • Side-Channel Attack: Uses physical observations (timing, light, etc.)

  • Fault Injection: Introduces errors to observe system behavior

  • Pass-the-Hash (PtH): Exploits hashed credentials instead of passwords

  • Rainbow Tables: Precomputed hashes used to reverse password hashes

  • Kerberos Exploitation: Targets weaknesses in SSO (Single Sign-On) systems


Reflection Prompt

If an attacker can’t crack the encryption directly, what other ways might they attempt to extract secret data? How might observing how a system behaves give them clues?


Detailed Concepts

What Are Cryptanalytic Attacks?

Cryptanalytic attacks aim to exploit:

  • Mathematical weaknesses in the encryption algorithm

  • Implementation flaws in how encryption is deployed

  • Human errors in key management or usage

These attacks do not necessarily require physical access to the system—they can often be performed remotely or with passive observation.


Common Cryptanalytic Attack Methods

Brute Force
  • Tries every possible key until the correct one is found

  • Effective only against weak encryption or short keys

  • Requires massive computational power and time


Ciphertext-Only Attack
  • Attacker only has intercepted ciphertext

  • Uses:

    • Frequency analysis

    • Statistical methods

    • Guesswork and brute force


Known Plaintext Attack
  • Attacker has both:

    • Plaintext (original message)

    • Corresponding ciphertext

  • Goal: Determine the encryption key


Implementation and Side-Channel Attacks

Implementation Attack
  • Exploits how the system is used—not the encryption itself

  • Example: Poor key storage, misconfigured crypto libraries

Side-Channel Attack
  • Observes physical or operational characteristics:

    • Power consumption

    • Electromagnetic leaks

    • Sound or timing


Chosen Ciphertext Attack
  • Attacker provides the victim with a crafted ciphertext

  • Observes the resulting plaintext

  • Goal: Infer key or decryption method


Fault Injection
  • A more active version of a side-channel attack

  • Techniques:

    • Power surges

    • Overclocking

    • Heating or cooling the system

  • Induces errors that reveal internal behavior or key bits


Timing Attack
  • Measures how long the system takes to encrypt/decrypt

  • Can reveal:

    • Key length

    • Algorithm type

    • Pattern of operation


Man-in-the-Middle (MITM) Attack

  • Attacker intercepts communication between sender and recipient

  • Modifies, captures, or relays data while both parties think they are talking directly

  • Can defeat:

    • Key exchanges (e.g., Diffie-Hellman without authentication)

    • SSL/TLS if not properly validated


Modern Cryptanalytic Techniques

Pass-the-Hash (PtH)
  • Exploits password hashes, not the passwords themselves

  • Used in Windows systems

  • Attacker obtains a stored NTLM or Kerberos hash and reuses it to authenticate


Kerberos Exploitation
  • In Single Sign-On (SSO) environments

  • If one system or token is compromised, all connected services may be accessible

  • Examples:

    • Ticket reuse

    • Session hijacking


Rainbow Table Attacks
  • Uses precomputed hashes of common passwords

  • Attacker compares hashes from a password file to the table

  • Fast and effective if passwords aren’t salted


Simplified Summary

  • Cryptanalytic attacks expose flaws in encryption systems or their use

  • They include brute force, side-channel, timing, and hash-based attacks

  • Attackers don’t need the password—they may use hashes or environmental cues

  • Defense depends on strong algorithms, secure key handling, and updated systems


Real-World Analogies

  • Brute Force: Like trying every combination on a padlock

  • Side-Channel: Like guessing a PIN based on which buttons are worn out

  • Pass-the-Hash: Like using a photo of a signature to forge a check

  • Rainbow Table: Like using a cheat sheet of known answers instead of guessing