Keep the content of information from all but those authorized
Data integrity
Addresses the unauthorized alteration of data
Authentication
Identification of both entities and information itself
Non-repudiation
Verified that the sender and the recipient were sent or received the message as claimed
Type
Classical cryptography
Sumerians
Cuneiform writing
Egyptians
Hieroglyphic writing
Phoenicians
Alphabets
Hebrew
Monoalphabetic substitution ciphers
Spartan
Scytale
Herodotus
Tatoo on shaved head
Notable Roman
Caeser cipher
India
Karma Sutra
China
Six Strategies
Modern cryptography
Cryptographic mathematics
Binary mathematics
Modulo function
Chinese remainder theorem
One-way functions
Easy to compute, hard to invert
e.g. MD5, SHA-1
Confusion
Relationship between the plaintext and the key is complicated
Diffusion
A change in the plaintext results in multiple changes spread out throughout the ciphertext
Components
Codes
Cryptographic systems of symbols that represent words or phrases
Ciphers
Hide the true meaning of a message
Type
Transposition
Substitution
One-time pad
Perfectly random
Secure generation and exchange
Careful treatment
Type
Symmetric
The way to encrypt and decrypt is the same
Algorithm
Data Encryption Standard
1973-74, Lucifer by IBM
1977, published by US gov
64-bit blocks of cipher text, 56 bits long key
Modes
ECB, CBC, CFB, OFB
Triple DES
168-bits (56x3)
IDEA
128-bit keys (8 rounds encryption)
Blowfish
Open source
Variable-length keys
32-bits
448-bits
Skipjack
Mainly use in ATM machine
64-bit blocks of cipher text, 80 bits long key
Advanced Encryption Standard (1997, aka Rijndael algorithm)
Announced by NIST
128-bit blocks of cipher text
128-bit keys (9 rounds encryption)
192-bit keys (11 rounds encryption)
256-bit keys (13 rounds encryption)
3 layers of transformation
Linear Mix
Nonlinear
Key addition
PGP
Use to secure email
CAST 128-bit encryption/ decryption algorithm
SHA-1 hash function
Asymmetric (aka Diffie-Hellman Key Exchange)
Two keys are used and work together in such a way that plain text encrypted with the one key can only be decrypted with the other
RSA (1977)
By Ron Rivest, Adi Shamir, and Leonard Adelman
768, 1024, 2048-bits of key
Key length
Considerations
Competitive advantage
Sensitivity of data
Moore's law
Governance
Overview
Cryptanalysis
Definition
Study of methods for obtaining the
meaning of encrypted information
Classical
Method: Frequency attack
Relies as much on linguistic knowledge as it does on statistics
Stages
Cipher text-only
Known-plaintext
Chosen-plaintext
Adaptive chosen-plaintext
Related-key attack
Modern
Mechanic
Enigma
Alan Turing
Analysis attack
Statistics attack
Bribery
Physical attack
Social engineering
Steganography
Definition
Hidden writing
Goals
Hide the secret information within the container file
Mask the secret information behind the container file
Types
Least Significant Byte
Injection
Printer steganography
Steganalysis
Definition
Detection of steganographically encoded packages
Detection
Benford's law
The values of real-world measurements are often distributed logarithmically, thus the logarithm of this set of measurements is generally distributed uniformly