L16 · Cryptography Intro: History, Definitions, Keys

CS 161, Lesson 16, in 50 slides, opening the cryptography unit. It gives a brief history - the Caesar cipher, Enigma, and Shannon and DES - then explains why we need formal definitions, introduces the cast of Alice, Bob, Eve, and Mallory, and distinguishes symmetric from asymmetric keys. It is anchored to textbook sections 5.2 to 5.5.

Subject: Computer Security · 87 slides · applied lesson

Open the interactive version of this deck · Homework for this lesson

What this lesson covers

The lesson, slide by slide

1. Cryptography: Secret Writing

Title

CS 161 · Lesson 16 of 45 · Crypto Unit Begins

Caesar → Enigma → Shannon · Alice, Bob, Eve & Mallory · symmetric vs asymmetric keys

2. By the end of this lesson you can…

Objectives

  1. Trace cryptography's three eras — classical (Caesar), mechanical (Enigma), and modern (Shannon, DES) — and say what each era could and couldn't protect.
  2. Encrypt and decrypt with a Caesar cipher, and explain why brute-forcing all 25 shifts makes it trivially insecure.
  3. Explain why an 'obviously insecure' cipher still demands formal definitions to do crypto as a science.
  4. Name the cast — Alice, Bob, Eve, Mallory — and distinguish a passive eavesdropper from an active adversary.
  5. Contrast symmetric and asymmetric (public-key) keys: who holds what, what's shared, and what stays secret.

3. What survived from L15 · Subverting Canaries, Pointer Authentication, ASLR &…?

Warm-up

Discussion prompt

Before we open L16 · Cryptography Intro: History, Definitions, Keys: without looking back, what was the main idea of L15 · Subverting Canaries, Pointer Authentication, ASLR & Combining Mitigations, and what could you do by the end of it that you could not do before?

Hint: One sentence for the idea, one for the skill. If the second one is blank, that is the part to revisit.

Answer:

CS 161 Lesson 15 (50 slides, code mode): the three things canaries don't stop, guessing vs leaking a canary (24-bit vs 56-bit entropy), pointer authentication stuffing a PAC into unused address bits, subverting ASLR by guessing or leaking one absolute address (rip = sfp+4), and why combining ASLR + NX + canaries forces an attacker to find a leak AND a write. Toy/sandbox examples only.

4. Why a whole unit on cryptography?

Concept

Until now we reasoned about systems. Now we get a tool: cryptography lets two parties communicate securely even when the channel between them is fully exposed.

Cryptography — From the Greek krypt (secret) + graphia (writing): the science of secret writing — and, more broadly, of building schemes whose security can be reasoned about mathematically.

History
§5.2 Caesar · Enigma · Shannon & DES
Definitions & cast
§5.3 why rigor · §5.4 Alice/Bob/Eve/Mallory
Keys
§5.5 symmetric vs asymmetric — today's payoff

5. Which is which: Why a whole unit on cryptography?

Matching

Match the pairs

From Why a whole unit on cryptography? — match each one to what it actually does. The descriptions have been shuffled.

  • c1. History
  • c2. Definitions & cast
  • c3. Keys
  • b1. §5.2 Caesar · Enigma · Shannon & DES
  • b2. §5.3 why rigor · §5.4 Alice/Bob/Eve/Mallory
  • b3. §5.5 symmetric vs asymmetric — today's payoff

Why: History, Definitions & cast, Keys are easy to tell apart while they are sitting next to their descriptions and much harder afterwards, which is what this checks.

6. A Brief History

Section

Part 1 · §5.2

7. §5.2 Three eras of cryptography

Concept

Cryptography is old, but it changed shape three times — each era a response to a new kind of adversary and a new kind of machine.

EraToolsHallmark
Classical ('pen and ink')Paper, hand ciphersCaesar cipher; telegraph raises the stakes
MechanicalElectromechanical machinesEnigma — and the effort to break it
ModernMathematics + computersShannon, then DES standardized for banking

8. Fill in: Tools for §5.2 Three eras of cryptography

Comparison

Comparison matrix

From §5.2 Three eras of cryptography: refill the Tools column from what you know. The rest of the table is as it appeared.

EraToolsHallmark
Classical ('pen and ink')Paper, hand ciphersCaesar cipher; telegraph raises the stakes
MechanicalElectromechanical machinesEnigma — and the effort to break it
ModernMathematics + computersShannon, then DES standardized for banking

9. §5.2 Classical era: the Caesar cipher

Concept

The scenario: a Roman general must send orders by courier who could be captured. The 'pen and ink' answer — shift each letter of the message by a fixed amount.

Caesar cipher — A substitution cipher that shifts every letter by a fixed key amount (wrapping z back to a). With a shift of 3, 'cryptography' encodes to 'fubswrjudskb'.

Simple to use by hand — and, by modern standards, hopelessly insecure. The 1800s telegraph raised the stakes: military and diplomatic messages now traveled wires anyone could tap.

10. Take the definitions apart: Cryptography vs Caesar cipher

Definition probe

Sort into buckets

Every line below is part of the definition of Cryptography or of Caesar cipher — one or the other, never both. Put each where it belongs.

Cryptography
From the Greek krypt (secret) + graphia (writing); the science of secret writing; and, more broadly, of building schemes whose security can be reasoned about mathematically.
Caesar cipher
A substitution cipher that shifts every letter by a fixed key amount (wrapping z back to a).; With a shift of 3, 'cryptography' encodes to 'fubswrjudskb'.
b1
From the Greek krypt (secret) + graphia (writing): the science of secret writing — and, more broadly, of building schemes whose security can be reasoned about mathematically.
b2
A substitution cipher that shifts every letter by a fixed key amount (wrapping z back to a). With a shift of 3, 'cryptography' encodes to 'fubswrjudskb'.

11. §5.2 What a shift really does

Intuition

Picture two alphabet rings, one inside the other. Rotate the inner ring three notches. Now every outer letter points at a different inner letter — that pairing IS the cipher.

Encrypt by reading outer → inner; decrypt by reading inner → outer (shift back by 3). The 'secret' is just the one number you rotated by.

Ask yourself: if the secret is a single number from 1 to 25, how hard can it be for an attacker to simply try them all?

12. Break it if you can: §5.2 What a shift really does

Counterexample

Discussion prompt

Picture two alphabet rings, one inside the other. Rotate the inner ring three notches. Now every outer letter points at a different inner letter — that pairing IS the cipher.

That is stated as though it always holds. Do one of two things: produce a case where it fails, or say precisely what rules such a case out. "It just does" is not on the menu.

Hint: Hunt at the extremes first — zero, one, negative, empty, equal. If every extreme survives, the reason they survive is the proof.

Answer:

Encrypt by reading outer → inner; decrypt by reading inner → outer (shift back by 3). The 'secret' is just the one number you rotated by.

13. Predict the next row: §5.2 Encrypt 'cab' with shift 3

Pattern

Predict first

The table runs: c | 2 | 5 | f · a | 0 | 3 | d

In §5.2 Encrypt 'cab' with shift 3, given the rows so far: what is the next one — the row where Plain letter is b?

Correct: b | 1 | 4 | e

Plain letterPosition+3 (mod 26)Cipher letter
c25f
a03d
b14e

Why: The relationship between the columns, not the individual numbers, is what generates the next row. Number the alphabet a=0, b=1, c=2, …; the cipher is arithmetic on these positions, mod 26.

14. §5.2 Encrypt 'cab' with shift 3

Worked example

Write the plaintext and its letter positions

Why: Number the alphabet a=0, b=1, c=2, …; the cipher is arithmetic on these positions, mod 26.

Plain letterPosition+3 (mod 26)Cipher letter
c25f
a03d
b14e

\[ E_3(\text{'cab'}) = \text{'fde'} \]

Verify by decrypting: shift 'fde' back by 3

Why: f→c, d→a, e→b recovers 'cab'. Encrypt then decrypt with the same key returns the original — exactly what a cipher must do.

15. What each one costs: §5.2 Encrypt 'cab' with shift 3

Trade off

Comparison matrix

From §5.2 Encrypt 'cab' with shift 3: every row here is a choice with a cost. Fill the Cipher letter column, then say which row you would actually pick and what you give up for it.

Plain letterPosition+3 (mod 26)Cipher letter
c25f
a03d
b14e

16. What has to happen first: §5.2 Break it: brute force all shifts

Ranking

Put in order

Put the moves of §5.2 Break it: brute force all shifts into the order they have to happen.

  1. Intercept the ciphertext 'fde' and assume you know it's a Caesar cipher
  2. Try every possible key in turn
  3. Verify the recovered key works on a longer message

Why: These are the moves of the worked example in the order it makes them, and each one is set up by the one before it. By Shannon's Maxim (Lesson 2) we assume the attacker knows the scheme — only the key (the shift) is secret.

17. §5.2 Break it: brute force all shifts

Worked example

Intercept the ciphertext 'fde' and assume you know it's a Caesar cipher

Why: By Shannon's Maxim (Lesson 2) we assume the attacker knows the scheme — only the key (the shift) is secret.

Try every possible key in turn

Why: There are only 25 non-trivial shifts. Decrypt under each and look for the one that yields readable English.

Shift triedDecrypts 'fde' toSensible?
1ecdno
2dbcno
3cabYES — readable
4bzano

\[ \text{keyspace} = 25 \text{ shifts} \;\Rightarrow\; \text{break by hand in seconds} \]

Verify the recovered key works on a longer message

Why: Shift 3 turns the full ciphertext into fluent text — confirming the key, not a coincidence. Tiny keyspace = no security.

18. Decode the notation: §5.2 Break it: brute force all shifts

Notation

Annotate

From §5.2 Break it: brute force all shifts — read this one piece at a time. What is each part doing?

On: \( \text{keyspace} = 25 \text{ shifts} \;\Rightarrow\; \text{break by hand in seconds} \)

  • By Shannon's Maxim (Lesson 2) we assume the attacker knows the scheme — only the key (the shift) is secret.
  • There are only 25 non-trivial shifts. Decrypt under each and look for the one that yields readable English.
  • Shift 3 turns the full ciphertext into fluent text — confirming the key, not a coincidence. Tiny keyspace = no security.

19. §5.2 Caesar as modular arithmetic

Concept

Once letters are numbers 0–25, encryption is just addition that wraps around — exactly the modular arithmetic you saw in CS 70. The key is the amount added.

\[ E_k(x) = (x + k) \bmod 26, \qquad D_k(y) = (y - k) \bmod 26 \]

Decryption undoes encryption because adding then subtracting the same k returns x. This 'lock and unlock with the same number' is the seed of the symmetric-key idea we reach in Part 4.

20. By analogy: §5.2 Caesar as modular arithmetic

Analogy

Discussion prompt

Explain §5.2 Caesar as modular arithmetic by analogy to something with no Computer Security in it at all — a queue, a recipe, a map, a bank balance, whatever fits. Then say where your analogy breaks.

Hint: An analogy that never breaks is not an analogy, it is the same idea wearing a hat. Find the seam — that is the part that is actually new.

Answer:

Once letters are numbers 0–25, encryption is just addition that wraps around — exactly the modular arithmetic you saw in CS 70. The key is the amount added.

21. §5.2 Why telegraphs raised the stakes

Intuition

Before the telegraph, a courier carried a sealed message; intercepting it meant physically catching the courier. The 1800s telegraph put messages on wires that ran for miles through territory anyone could reach.

Suddenly an adversary could copy every message silently without stealing anything physical. Military and diplomatic traffic NEEDED real ciphers — and the weakness of pen-and-ink schemes like Caesar became a strategic liability.

Ask yourself: the Internet is the same leap, larger. Your packets cross machines you'll never see. What does that demand of every message worth protecting?

22. Teach it back: §5.2 Why telegraphs raised the stakes

Explain it

Discussion prompt

Explain §5.2 Why telegraphs raised the stakes to a student a year behind you. No notation, no jargon they have not met — and it still has to be true.

Hint: If your explanation needs a symbol they have never seen, you are describing the notation rather than the idea.

Answer:

Ask yourself: the Internet is the same leap, larger. Your packets cross machines you'll never see. What does that demand of every message worth protecting?

23. Something is wrong here: 'a bigger shift is more secure'

Anomaly

Predict first

A student writes this, and it looks reasonable:

Caesar with shift 3 was broken instantly. 'So use shift 20 — a bigger secret must be harder!'

It is wrong. Say what breaks — and say it before you turn the page.

Correct: Confuses the size of the key VALUE with the size of the keySPACE.

Caesar with shift 3 was broken instantly. The shift value doesn't matter to the attacker.

Why: Confuses the size of the key VALUE with the size of the keySPACE. There are still only 25 possible shifts to try.

24. Trap: 'a bigger shift is more secure'

Trap

The trap

Caesar with shift 3 was broken instantly. 'So use shift 20 — a bigger secret must be harder!'

Believe a larger shift value strengthens the cipher

Why: Confuses the size of the key VALUE with the size of the keySPACE. There are still only 25 possible shifts to try.

The fix

Caesar with shift 3 was broken instantly. The shift value doesn't matter to the attacker.

Recognize the keyspace is 25 regardless of which shift you pick

Why: Brute force tries all 25 either way and finds shift 20 just as fast as shift 3. Security comes from a large keyspace, not a large number.

25. §5.2 Mechanical era: the Enigma

Concept

Scenario: WWII. Germany needs to coordinate forces by radio — broadcasts anyone can hear — so it encrypts with the Enigma, an electromechanical rotor machine far beyond pen-and-ink ciphers.

Enigma — A German electromechanical cipher machine whose rotors changed the substitution with every keypress, producing an enormous, constantly shifting keyspace.

26. §5.2 Breaking Enigma

Intuition

A working replica reached the British via Poland — so the Allies knew the machine, and had to defeat it anyway. (Foreshadow: that's Shannon's Maxim and Kerckhoff's Principle — security can't depend on the design being secret.)

The British effort enlisted mathematicians, including Alan Turing, and at its peak employed more than 10,000 people running an electromechanical, parallel search over candidate keys.

The payoff was historic: breaking Enigma is estimated to have shortened the war by about a year. Cryptanalysis had become a strategic weapon.

27. Plan first: §5.2 Why Enigma fell despite a vast keyspace

Step zero

Discussion prompt

§5.2 Why Enigma fell despite a vast keyspace — before any calculation: what is the plan? Name the moves in order, in plain English, without doing the arithmetic.

Hint: It starts with: Note the keyspace was astronomically larger than Caesar's 25

Answer:

  1. Note the keyspace was astronomically larger than Caesar's 25
  2. But the Allies KNEW the machine (replica via Poland)
  3. Exploit structure: no letter ever encrypted to itself, plus guessable plaintext ('cribs')
  4. Run an electromechanical PARALLEL search with >10,000 people

28. §5.2 Why Enigma fell despite a vast keyspace

Worked example

Note the keyspace was astronomically larger than Caesar's 25

Why: Rotor order, ring settings, and plugboard wiring multiplied into a number no human could search by hand — brute force seemed hopeless.

But the Allies KNEW the machine (replica via Poland)

Why: Shannon's Maxim in action: assume the attacker has the design. Knowing the machine, the question became 'find today's settings,' not 'guess the scheme.'

Exploit structure: no letter ever encrypted to itself, plus guessable plaintext ('cribs')

Why: Design quirks and predictable message fragments shrank the effective search dramatically — a huge keyspace with exploitable structure isn't huge in practice.

Run an electromechanical PARALLEL search with >10,000 people

Why: Turing's machines mechanized the key search at scale. The lesson: secrecy of the design bought nothing; only the daily key mattered — and even that fell to structure.

29. Draw the shape of it: §5.2 Why Enigma fell despite a vast keyspace

Blank canvas

Draw it

Draw what §5.2 Why Enigma fell despite a vast keyspace just did — the shape of it, not the line-by-line working. One picture, labels only where you need them. Then check it against the steps: anything you could not draw is a step you followed rather than understood.

30. §5.2 Modern era: math meets computers

Concept

After WWII, cryptography became a mathematical science. Its modern roots trace to Claude Shannon, who put secrecy on a formal footing and analyzed the one-time pad.

In the 1970s NIST standardized DES (the Data Encryption Standard) for banking, and the late 1970s saw an explosion of computational crypto theory — public-key cryptography among it.

31. §5.2 What the one-time pad taught us

Concept

Shannon analyzed the one-time pad: XOR the message with a truly random key as long as the message, used exactly once. He proved it leaks NOTHING about the plaintext — perfect secrecy.

The catch is the key: it must be random, as long as the message, and never reused. That impracticality is precisely why modern crypto trades perfect secrecy for COMPUTATIONAL security with short, reusable keys (the rest of the unit).

32. §5.2 What changed across the eras

Intuition

Caesar's secret was a number you could guess. Enigma's was vast but still a finite machine state. The modern era's leap: design schemes whose security rests on problems we believe are computationally hard — and PROVE it.

Ask yourself: Enigma had a huge keyspace and was still broken. So 'big keyspace' is necessary but not sufficient — what else does a scheme need? That question is exactly why we now turn to definitions.

33. §5.2 Modern era: Shannon and DES

Concept

Claude Shannon, after WWII, gave secrecy a mathematical theory — including the proof that the one-time pad offers perfect secrecy (and why its impractical key length is the catch we revisit later).

In the 1970s NIST standardized DES so banks could encrypt transactions to a common, vetted spec. A government-blessed, public algorithm — the opposite of a secret design — became the workhorse of commercial crypto.

The late 1970s then opened computational crypto: public-key encryption, signatures, and security defined relative to an attacker's computing budget. That's the world the rest of this unit lives in.

34. Why We Need Definitions

Section

Part 2 · §5.3

35. §5.3 'Obviously insecure' isn't a proof

Concept

We just felt that Caesar is insecure — 25 shifts, try them all. But 'feels insecure' and 'feels secure' are not science. To build trustworthy systems we need to PROVE a scheme secure or insecure.

A proof needs a precise claim. What does 'secure' even mean? Against whom, with what powers, learning what? Until those are pinned down mathematically, we have intuition, not guarantees.

36. §5.3 The scenario that breaks intuition

Intuition

Imagine a cipher nobody can break by hand. Is it secure? An attacker with a supercomputer might still win. Or maybe the ciphertext leaks the message LENGTH, or whether two messages are equal. 'I couldn't break it' is not 'it's secure'.

So this unit will build security games: an attacker is given exact powers and a precise winning condition, and we measure their advantage. (Foreshadow: IND-CPA, the indistinguishability game, in Lesson 18.)

Ask yourself: why phrase security as a GAME the attacker plays, rather than a checklist the defender follows? Because only a game lets us say exactly what 'winning' means — and prove the attacker can't.

37. Plan first: §5.3 Pinning down what a definition must fix

Step zero

Discussion prompt

§5.3 Pinning down what a definition must fix — before any calculation: what is the plan? Name the moves in order, in plain English, without doing the arithmetic.

Hint: It starts with: Name the adversary's powers

Answer:

  1. Name the adversary's powers
  2. Name exactly what 'winning' means for the attacker
  3. Name the resource bound
  4. Verify: only now can 'secure' be a provable statement

38. §5.3 Pinning down what a definition must fix

Worked example

Name the adversary's powers

Why: Can the attacker only listen, or also inject messages? Can it ask for encryptions of chosen plaintexts? Different powers = different definitions.

Name exactly what 'winning' means for the attacker

Why: Recover the whole message? Learn one bit? Tell two messages apart? Security is the claim that even THIS weak win is out of reach.

Name the resource bound

Why: An attacker with unlimited time can brute-force almost anything. Modern definitions cap computation and allow a negligible success probability.

Verify: only now can 'secure' be a provable statement

Why: With adversary, win condition, and resources fixed, 'no efficient attacker wins with non-negligible advantage' becomes a theorem you can prove — the goal of §5.3.

39. Something is wrong here: 'no one has broken it, so it's secure'

Anomaly

Predict first

A student writes this, and it looks reasonable:

A startup ships a cipher: 'our team tried for months and couldn't break it.'

It is wrong. Say what breaks — and say it before you turn the page.

Correct: Absence of a known attack is not a proof.

A reviewer asks for the security claim, not the war story.

Why: Absence of a known attack is not a proof. A better-resourced adversary, or a subtle leak (length, equality of messages), may already defeat it.

40. Trap: 'no one has broken it, so it's secure'

Trap

The trap

A startup ships a cipher: 'our team tried for months and couldn't break it.'

Equate 'we failed to break it' with 'it is secure'

Why: Absence of a known attack is not a proof. A better-resourced adversary, or a subtle leak (length, equality of messages), may already defeat it.

The fix

A reviewer asks for the security claim, not the war story.

Demand a formal definition and a reduction/proof

Why: §5.3: state the adversary, the win condition, and the bound, then PROVE no efficient attacker wins. 'Nobody broke it yet' is a hope, not a guarantee.

41. §5.3 Kerckhoff, foreshadowed

Concept

Our definitions will always assume the attacker knows the entire SCHEME — every algorithm and parameter. The only thing secret is the key. That's Shannon's Maxim from Lesson 2, soon to be named Kerckhoff's Principle in Lesson 18.

Why bake this into the definition? Because a key is easy to rotate when it leaks; a secret algorithm, once reverse-engineered (Enigma!), can't be quietly replaced everywhere. Definitions that lean on a hidden design are definitions that lie.

42. The Cast

Section

Part 3 · §5.4

43. §5.4 Alice and Bob want to talk

Concept

Scenario: Alice in one city wants to send Bob a private message over the phone or the Internet — a channel that anyone in between can tap.

The goal of the whole unit, in one line: simulate an ideal untappable channel over an insecure one. Make the exposed wire behave, to an attacker, like a private one.

44. §5.4 Why we use names at all

Intuition

Naming the parties — Alice the sender, Bob the receiver — turns dense protocol prose into a story you can follow. 'A sends to B' is forgettable; 'Alice sends to Bob' sticks.

More importantly, naming the ADVERSARY forces you to state its powers. Saying 'Eve' commits you to a passive attacker; saying 'Mallory' commits you to an active one. The name is shorthand for a threat model.

Ask yourself: when a protocol claims to be 'secure,' your first question should be — against Eve, or against Mallory? The answer changes everything.

45. §5.4 Meet Eve and Mallory

Concept

Eve — the eavesdropper — A PASSIVE adversary. Eve can read everything on the channel but cannot change it. She listens; she does not touch.

Mallory — the malicious one — An ACTIVE adversary. Mallory can read AND tamper: modify, drop, inject, or reorder messages. Strictly more powerful than Eve.

46. Where does each piece belong: L16 · Cryptography Intro: History…

Sorting

Sort into buckets

These are the pieces of L16 · Cryptography Intro: History, Definitions, Keys, out of order. Put each one back under the part of the lesson it belongs to.

A Brief History
§5.2 Three eras of cryptography; §5.2 Classical era: the Caesar cipher; §5.2 What a shift really does
Why We Need Definitions
§5.3 'Obviously insecure' isn't a proof; §5.3 The scenario that breaks intuition; §5.3 Pinning down what a definition must fix
The Cast
§5.4 Alice and Bob want to talk; §5.4 Why we use names at all; §5.4 Meet Eve and Mallory
s1
A Brief History is where L16 · Cryptography Intro: History, Definitions, Keys puts §5.2 Three eras of cryptography, §5.2 Classical era: the Caesar cipher, §5.2 What a shift really does. Knowing which part of the lesson a problem belongs to is most of knowing which method to reach for.
s2
Why We Need Definitions is where L16 · Cryptography Intro: History, Definitions, Keys puts §5.3 'Obviously insecure' isn't a proof, §5.3 The scenario that breaks intuition, §5.3 Pinning down what a definition must fix. Knowing which part of the lesson a problem belongs to is most of knowing which method to reach for.
s3
The Cast is where L16 · Cryptography Intro: History, Definitions, Keys puts §5.4 Alice and Bob want to talk, §5.4 Why we use names at all, §5.4 Meet Eve and Mallory. Knowing which part of the lesson a problem belongs to is most of knowing which method to reach for.

47. §5.4 Postcard vs. tampered postcard

Intuition

Eve is the nosy mail carrier who reads your postcard but delivers it untouched. Mallory is the carrier who reads it, erases a word, writes a new one, and delivers the forgery — and you'd never know.

These are different threats needing different defenses. Hiding the message (confidentiality) defeats Eve. Detecting changes (integrity/authenticity) is needed to defeat Mallory — and that takes a separate tool, the MAC, later in the unit.

Ask yourself: a scheme that perfectly hides the contents — does it stop Mallory? No. Mallory can still scramble the ciphertext; you decrypt to garbage and can't tell it was altered. Confidentiality ≠ integrity.

48. Something is wrong here: 'Eve can modify messages'

Anomaly

Predict first

A student writes this, and it looks reasonable:

A student designs a defense and assumes Eve might flip bits in transit.

It is wrong. Say what breaks — and say it before you turn the page.

Correct: Conflates the two adversaries. Eve is PASSIVE — read-only.

A student designs a defense and names the adversary precisely.

Why: Conflates the two adversaries. Eve is PASSIVE — read-only. Granting her tampering quietly turns her into Mallory and muddles the threat model.

49. Trap: 'Eve can modify messages'

Trap

The trap

A student designs a defense and assumes Eve might flip bits in transit.

Give Eve the power to tamper with the channel

Why: Conflates the two adversaries. Eve is PASSIVE — read-only. Granting her tampering quietly turns her into Mallory and muddles the threat model.

The fix

A student designs a defense and names the adversary precisely.

Eve reads only; tampering is Mallory's power

Why: §5.4: keep them distinct. Confidentiality is enough against Eve; defeating Mallory additionally requires integrity/authenticity. The distinction matters all unit.

50. Break it on purpose: 'Eve can modify messages'

Break the constraint

Discussion prompt

The rule this trap just fixed:

A student designs a defense and names the adversary precisely.

Now break it on purpose. Build a case that violates it and follow the consequences until something visibly fails. Where does the failure first show up — and would you have noticed it if you had not been looking?

Hint: The dangerous rules are the ones whose violation still produces an answer. If yours fails loudly, try to find one that fails quietly.

Answer:

Conflates the two adversaries. Eve is PASSIVE — read-only. Granting her tampering quietly turns her into Mallory and muddles the threat model.

51. What has to happen first: §5.4 Same wire, two different attacks

Ranking

Put in order

Put the moves of §5.4 Same wire, two different attacks into the order they have to happen.

  1. Alice sends 'transfer $50 to Bob' over the open channel
  2. Eve's attack: read and learn
  3. Mallory's attack: rewrite to 'transfer $5000 to Mallory'
  4. Verify the lesson: a tool that only hides bytes stops Eve, not Mallory

Why: These are the moves of the worked example in the order it makes them, and each one is set up by the one before it. Both adversaries see the bytes; the question is what each can DO with them.

52. §5.4 Same wire, two different attacks

Worked example

Alice sends 'transfer $50 to Bob' over the open channel

Why: Both adversaries see the bytes; the question is what each can DO with them.

Eve's attack: read and learn

Why: Passive. Eve records the amount and the recipient. She breaks confidentiality but the message Bob receives is unchanged.

Mallory's attack: rewrite to 'transfer $5000 to Mallory'

Why: Active. Mallory alters the message in flight, breaking integrity AND authenticity — Bob acts on a forgery believing it came from Alice.

AdversaryRead?Modify?Breaks
Eveyesnoconfidentiality
Malloryyesyesconfidentiality, integrity, authenticity

Verify the lesson: a tool that only hides bytes stops Eve, not Mallory

Why: Encryption alone leaves Mallory free to scramble or swap ciphertext. Defeating Mallory needs a separate integrity tool — motivating the next lessons.

53. Fill in: Read? for §5.4 Same wire, two different attacks

Comparison

Comparison matrix

From §5.4 Same wire, two different attacks: refill the Read? column from what you know. The rest of the table is as it appeared.

AdversaryRead?Modify?Breaks
Eveyesnoconfidentiality
Malloryyesyesconfidentiality, integrity, authenticity

54. Keys: Symmetric vs Asymmetric

Section

Part 4 · §5.5

55. §5.5 The key is the building block

Concept

Scenario: Alice has a locked box she wants Bob to open — but not Eve. The whole game now reduces to one question: who holds the key?

Key — A secret value that locks (encrypts) and unlocks (decrypts). Per Shannon's Maxim, the key — not the algorithm — is the secret that security rests on.

There are two key models, and almost every primitive in this unit is one or the other. Get this distinction crisp now.

56. Term to definition: L16 · Cryptography Intro: History, Definitions, Keys

Matching

Match the pairs

Match each term to the definition this lesson gave it — not the one you would guess from the word.

  • t1. Caesar cipher
  • t2. Enigma
  • t3. Eve — the eavesdropper
  • t4. Mallory — the malicious one
  • t5. Key
  • d1. A substitution cipher that shifts every letter by a fixed key amount (wrapping z back to a). With a shift of 3, 'cryptography' encodes to 'fubswrjudskb'.
  • d2. A German electromechanical cipher machine whose rotors changed the substitution with every keypress, producing an enormous, constantly shifting keyspace.
  • d3. A PASSIVE adversary. Eve can read everything on the channel but cannot change it. She listens; she does not touch.
  • d4. An ACTIVE adversary. Mallory can read AND tamper: modify, drop, inject, or reorder messages. Strictly more powerful than Eve.
  • d5. A secret value that locks (encrypts) and unlocks (decrypts). Per Shannon's Maxim, the key — not the algorithm — is the secret that security rests on.

Why: These are the working definitions of Caesar cipher, Enigma, Eve — the eavesdropper, Mallory — the malicious one, Key as L16 · Cryptography Intro: History, Definitions, Keys uses them. Pairing them correctly is the test of whether you could state each one with the slide switched off.

57. §5.5 Symmetric keys

Concept

Scenario: Alice and Bob met in person last week and agreed on one shared secret. Now, apart, they use that ONE key both to encrypt and to decrypt.

Symmetric-key cryptography — Alice and Bob share a single secret key K. Encryption and decryption both use K. Anyone with K can read and write messages.

\[ C = \text{Enc}(K, M), \qquad M = \text{Dec}(K, C) \]

58. §5.5 The shared-padlock picture

Intuition

Symmetric crypto is two people with identical copies of the same key to the same padlock. Either can lock the box, either can unlock it. Fast and simple — IF you could safely hand over that key.

The catch you'll feel later: how do Alice and Bob agree on K over a channel Eve is already watching? That bootstrap problem is what motivates the next idea.

59. Teach it back: §5.5 The shared-padlock picture

Explain it

Discussion prompt

Explain §5.5 The shared-padlock picture to a student a year behind you. No notation, no jargon they have not met — and it still has to be true.

Hint: If your explanation needs a symbol they have never seen, you are describing the notation rather than the idea.

Answer:

Symmetric crypto is two people with identical copies of the same key to the same padlock. Either can lock the box, either can unlock it. Fast and simple — IF you could safely hand over that key.

60. Plan first: §5.5 A round trip with one shared key

Step zero

Discussion prompt

§5.5 A round trip with one shared key — before any calculation: what is the plan? Name the moves in order, in plain English, without doing the arithmetic.

Hint: It starts with: Alice and Bob share secret key K (arranged earlier, in person)

Answer:

  1. Alice and Bob share secret key K (arranged earlier, in person)
  2. Alice computes C = Enc(K, M) and sends C over the wire
  3. Bob computes Dec(K, C)
  4. Verify: only holders of K can read or produce valid messages

61. §5.5 A round trip with one shared key

Worked example

Alice and Bob share secret key K (arranged earlier, in person)

Why: Symmetric crypto's precondition: the same K is already in both hands and known to no one else.

Alice computes C = Enc(K, M) and sends C over the wire

Why: Eve sees C but, lacking K, cannot recover M — confidentiality holds against a passive eavesdropper.

Bob computes Dec(K, C)

Why: The SAME key that locked the message unlocks it. That single shared K is the defining feature of the symmetric model.

\[ \text{Dec}(K, \text{Enc}(K, M)) = M \]

Verify: only holders of K can read or produce valid messages

Why: Encrypt-then-decrypt under the same K returns M; anyone without K is locked out. The cost: K had to be shared securely first.

62. Decode the notation: §5.5 A round trip with one shared key

Notation

Annotate

From §5.5 A round trip with one shared key — read this one piece at a time. What is each part doing?

On: \( \text{Dec}(K, \text{Enc}(K, M)) = M \)

  • Symmetric crypto's precondition: the same K is already in both hands and known to no one else.
  • Eve sees C but, lacking K, cannot recover M — confidentiality holds against a passive eavesdropper.
  • The SAME key that locked the message unlocks it. That single shared K is the defining feature of the symmetric model.

63. §5.5 Asymmetric (public-key) keys

Concept

Scenario: Alice has never met Bob, yet wants to send him a secret today. With public-key crypto she can — no shared secret required in advance.

Asymmetric (public-key) cryptography — Each party has a key PAIR: a public key (shared with everyone) and a matching private key (kept secret). You met RSA in CS 70 — this is its security setting.

\[ C = \text{Enc}(\text{PK}_{\text{Bob}}, M), \qquad M = \text{Dec}(\text{SK}_{\text{Bob}}, C) \]

64. By analogy: §5.5 Asymmetric (public-key) keys

Analogy

Discussion prompt

Explain §5.5 Asymmetric (public-key) keys by analogy to something with no Computer Security in it at all — a queue, a recipe, a map, a bank balance, whatever fits. Then say where your analogy breaks.

Hint: An analogy that never breaks is not an analogy, it is the same idea wearing a hat. Find the seam — that is the part that is actually new.

Answer:

Scenario: Alice has never met Bob, yet wants to send him a secret today. With public-key crypto she can — no shared secret required in advance.

65. What has to happen first: §5.5 Who holds what?

Ranking

Put in order

Put the moves of §5.5 Who holds what? into the order they have to happen.

  1. Set the goal: Alice sends Bob a confidential message, no prior meeting
  2. Bob publishes his PUBLIC key; he keeps his PRIVATE key secret
  3. Alice encrypts under Bob's public key and sends the ciphertext
  4. Verify: Bob decrypts with his private key and recovers M

Why: These are the moves of the worked example in the order it makes them, and each one is set up by the one before it. This is the case symmetric crypto can't bootstrap on its own — we need a key Bob can publish safely.

66. §5.5 Who holds what?

Worked example

Set the goal: Alice sends Bob a confidential message, no prior meeting

Why: This is the case symmetric crypto can't bootstrap on its own — we need a key Bob can publish safely.

Bob publishes his PUBLIC key; he keeps his PRIVATE key secret

Why: Anyone — including Eve — may know the public key. Only Bob holds the matching private key.

Alice encrypts under Bob's public key and sends the ciphertext

Why: The public key locks; only the matching private key unlocks. Eve seeing the public key and ciphertext still can't read M.

ModelKeysShared openlyKept secret
Symmetricone shared key KnothingK (both Alice & Bob)
Asymmetricpublic key + private key per partythe public keythe private key only

Verify: Bob decrypts with his private key and recovers M

Why: Enc under PK then Dec under the matching SK returns M — and no one lacking SK can. The contrast with the symmetric row is the whole point.

67. Draw the shape of it: §5.5 Who holds what?

Blank canvas

Draw it

Draw what §5.5 Who holds what? just did — the shape of it, not the line-by-line working. One picture, labels only where you need them. Then check it against the steps: anything you could not draw is a step you followed rather than understood.

68. §5.5 The open-padlock picture

Intuition

Asymmetric crypto is a padlock Bob hands out OPEN, by the thousand. Anyone can snap a message shut inside it. But only Bob keeps the one key that reopens it — his private key.

This is what symmetric crypto couldn't do: it lets total strangers send Bob a secret with nothing arranged in advance, because the locking key being public is harmless.

Ask yourself: with the open-padlock model, what is the ONE thing Bob must never let leak? (His private key — the only thing that reopens the locks.)

69. Break it if you can: §5.5 The open-padlock picture

Counterexample

Discussion prompt

Asymmetric crypto is a padlock Bob hands out OPEN, by the thousand. Anyone can snap a message shut inside it. But only Bob keeps the one key that reopens it — his private key.

That is stated as though it always holds. Do one of two things: produce a case where it fails, or say precisely what rules such a case out. "It just does" is not on the menu.

Hint: Hunt at the extremes first — zero, one, negative, empty, equal. If every extreme survives, the reason they survive is the proof.

Answer:

Ask yourself: with the open-padlock model, what is the ONE thing Bob must never let leak? (His private key — the only thing that reopens the locks.)

70. §5.5 Two key models, two cost profiles

Concept

Neither model is 'better' — they solve different problems. The unit uses both, often together: asymmetric crypto to agree on a key, then fast symmetric crypto for the bulk data.

QuestionSymmetricAsymmetric
Keys involvedone shared Kpublic + private pair
Prior arrangement?must share K firstnone — publish public key
Speedfastslow (heavy math)
Best forbulk encryptionkey setup, signatures

71. What each one costs: §5.5 Two key models, two cost profiles

Trade off

Comparison matrix

From §5.5 Two key models, two cost profiles: every row here is a choice with a cost. Fill the Symmetric column, then say which row you would actually pick and what you give up for it.

QuestionSymmetricAsymmetric
Keys involvedone shared Kpublic + private pair
Prior arrangement?must share K firstnone — publish public key
Speedfastslow (heavy math)
Best forbulk encryptionkey setup, signatures

72. Something is wrong here: 'keep the public key secret'

Anomaly

Predict first

A student writes this, and it looks reasonable:

Bob, being careful, hides his public key so attackers can't get it.

It is wrong. Say what breaks — and say it before you turn the page.

Correct: Misreads 'public.' If Bob hides his public key, Alice can't get it either — and nobody can send him anything.

Bob publishes his public key widely and guards only his private key.

Why: Misreads 'public.' If Bob hides his public key, Alice can't get it either — and nobody can send him anything. The name says it: it's meant to be shared.

73. Trap: 'keep the public key secret'

Trap

The trap

Bob, being careful, hides his public key so attackers can't get it.

Treat the public key as a secret to protect

Why: Misreads 'public.' If Bob hides his public key, Alice can't get it either — and nobody can send him anything. The name says it: it's meant to be shared.

The fix

Bob publishes his public key widely and guards only his private key.

Public key is shared; ONLY the private key is secret

Why: §5.5: security depends solely on keeping the private key secret. Eve may freely know the public key and still cannot decrypt.

74. Something is wrong here: 'symmetric and asymmetric are interchangeable'

Anomaly

Predict first

A student writes this, and it looks reasonable:

Alice and Bob never met. A student says: 'just use their shared symmetric key.'

It is wrong. Say what breaks — and say it before you turn the page.

Correct: Symmetric crypto presupposes a key already shared over a secure channel — the very thing Alice and Bob lack.

Alice and Bob never met, and Eve watches the channel.

Why: Symmetric crypto presupposes a key already shared over a secure channel — the very thing Alice and Bob lack. You can't bootstrap it from nothing over Eve's wire.

75. Trap: 'symmetric and asymmetric are interchangeable'

Trap

The trap

Alice and Bob never met. A student says: 'just use their shared symmetric key.'

Assume a shared symmetric key already exists between strangers

Why: Symmetric crypto presupposes a key already shared over a secure channel — the very thing Alice and Bob lack. You can't bootstrap it from nothing over Eve's wire.

The fix

Alice and Bob never met, and Eve watches the channel.

Use asymmetric crypto (or key exchange) to establish a secret, THEN switch to symmetric

Why: §5.5: the models aren't interchangeable. Asymmetric solves the no-prior-secret case; symmetric is the fast follow-up once a key exists.

76. Which of these survive contact with L16 · Cryptography Intro: History…?

Two truths and a lie

Sort into buckets

Some of these hold up and some are the exact mistakes this lesson is built to prevent. Sort them.

Holds up
Until now we reasoned about systems. Now we get a tool: cryptography lets two parties communicate securely even when the channel between them is fully exposed.; Cryptography is old, but it changed shape three times — each era a response to a new kind of adversary and a new kind of machine.; The scenario: a Roman general must send orders by courier who could be captured. The 'pen and ink' answer — shift each letter of the message by a fixed amount.
Breaks
Caesar with shift 3 was broken instantly. 'So use shift 20 — a bigger secret must be harder!'; A startup ships a cipher: 'our team tried for months and couldn't break it.'
sound
These are stated as this lesson states them — each one survives the edge cases L16 · Cryptography Intro: History, Definitions, Keys puts it through.
flawed
Each of these is lifted from a trap in this deck: reasonable-sounding, and wrong in a way that only shows up once you rely on it.

77. Where this unit is going

Concept

Today's vocabulary unlocks a toolbox. Each primitive ahead is symmetric or asymmetric, and each provides confidentiality, integrity/authenticity, or a supporting service.

PrimitiveKey modelProvides
Block ciphers & modessymmetricconfidentiality of bulk data
MACssymmetricintegrity / authenticity
Public-key encryptionasymmetricconfidentiality without a shared key
Digital signaturesasymmetricintegrity / authenticity, publicly verifiable
Hash functionskeylessintegrity, fingerprints, building block
PRNGskeyless/seededthe randomness everything else needs
Key exchangeasymmetricagree on a symmetric key over Eve's channel

78. Fill in: Key model for Where this unit is going

Comparison

Comparison matrix

From Where this unit is going: refill the Key model column from what you know. The rest of the table is as it appeared.

PrimitiveKey modelProvides
Block ciphers & modessymmetricconfidentiality of bulk data
MACssymmetricintegrity / authenticity
Public-key encryptionasymmetricconfidentiality without a shared key
Digital signaturesasymmetricintegrity / authenticity, publicly verifiable
Hash functionskeylessintegrity, fingerprints, building block
PRNGskeyless/seededthe randomness everything else needs
Key exchangeasymmetricagree on a symmetric key over Eve's channel

79. Without one step: The crypto-intro checklist

Constraint

Discussion prompt

Run The crypto-intro checklist with this step confiscated:

Cast (§5.4): Alice ↔ Bob; Eve reads only (passive); Mallory reads AND tampers (active).

Is it still possible? If it is, say what takes its place and what it costs you. If it is not, say exactly what that step was providing that nothing else does.

Hint: A step you can drop for free was never load-bearing. If you cannot drop it, name the thing that goes wrong the moment it is gone.

Answer:

  1. History (§5.2): classical (Caesar) → mechanical (Enigma) → modern (Shannon, DES). Big keyspace is necessary, not sufficient.
  2. Caesar (§5.2): shift letters by a fixed key; only 25 keys ⇒ brute-force broken — the shift VALUE doesn't matter.
  3. Definitions (§5.3): 'I couldn't break it' isn't security; we need formal games to PROVE it (IND-CPA ahead).
  4. Cast (§5.4): Alice ↔ Bob; Eve reads only (passive); Mallory reads AND tampers (active).
  5. Goal (§5.4): simulate an untappable channel over an insecure one.
  6. Keys (§5.5): symmetric = one shared secret; asymmetric = public key (shared) + private key (secret).
  7. Properties: confidentiality (hide) ≠ integrity/authenticity (detect tampering).

80. The crypto-intro checklist

Pattern

  1. History (§5.2): classical (Caesar) → mechanical (Enigma) → modern (Shannon, DES). Big keyspace is necessary, not sufficient.
  2. Caesar (§5.2): shift letters by a fixed key; only 25 keys ⇒ brute-force broken — the shift VALUE doesn't matter.
  3. Definitions (§5.3): 'I couldn't break it' isn't security; we need formal games to PROVE it (IND-CPA ahead).
  4. Cast (§5.4): Alice ↔ Bob; Eve reads only (passive); Mallory reads AND tampers (active).
  5. Goal (§5.4): simulate an untappable channel over an insecure one.
  6. Keys (§5.5): symmetric = one shared secret; asymmetric = public key (shared) + private key (secret).
  7. Properties: confidentiality (hide) ≠ integrity/authenticity (detect tampering).

81. Where does it stop working: The crypto-intro checklist

Edge cases

Discussion prompt

The crypto-intro checklist works on the cases you have just seen. Push it to the edge: what is the most degenerate input it still handles — empty, zero, one item, everything equal — and what is the first case where it stops being true? Name the case, not just "it breaks".

Hint: Try the smallest legal input, then the largest, then the one where two things collide. Methods are specified at their edges; the middle takes care of itself.

Answer:

  1. History (§5.2): classical (Caesar) → mechanical (Enigma) → modern (Shannon, DES). Big keyspace is necessary, not sufficient.
  2. Caesar (§5.2): shift letters by a fixed key; only 25 keys ⇒ brute-force broken — the shift VALUE doesn't matter.
  3. Definitions (§5.3): 'I couldn't break it' isn't security; we need formal games to PROVE it (IND-CPA ahead).
  4. Cast (§5.4): Alice ↔ Bob; Eve reads only (passive); Mallory reads AND tampers (active).
  5. Goal (§5.4): simulate an untappable channel over an insecure one.
  6. Keys (§5.5): symmetric = one shared secret; asymmetric = public key (shared) + private key (secret).
  7. Properties: confidentiality (hide) ≠ integrity/authenticity (detect tampering).

82. Checkpoint — keys, adversaries, and shifts

Check

Alice wants to send Bob a confidential message using public-key cryptography. Bob has already published his public key, and Eve is listening on the wire.

Check your understanding

Which statement is correct?

  • A. Alice encrypts with Bob's public key; only Bob's private key can decrypt it, and Eve learning the public key doesn't help her. (correct)
  • B. Bob must keep his public key secret, or Eve will be able to decrypt the message.
  • C. Because Eve is an eavesdropper, she can modify the ciphertext in transit to forge a new message.
  • D. A Caesar cipher with a large shift would be just as secure here, since a bigger shift means a bigger secret.

Answer: A

Why: §5.5: in public-key crypto Alice encrypts under Bob's PUBLIC key and only the matching PRIVATE key decrypts. The public key is meant to be shared, so Eve knowing it gives her no advantage — and as a passive eavesdropper she only reads.

Why B tempts people
The public key is published on purpose; security rests on the PRIVATE key alone. Hiding the public key would only stop Alice from sending.
Why C tempts people
Eve is passive — read-only. Modifying messages is Mallory's (active) power, not Eve's.
Why D tempts people
A Caesar cipher has only 25 keys no matter how large the shift VALUE is, so it is brute-forced instantly — the shift size is irrelevant to security.

83. Misconceptions students bring to the crypto unit

Concept

84. Synthesis — how Lesson 16 frames the unit

Concept

85. Primary sources & where to read more

Concept

86. Connect it up: L16 · Cryptography Intro: History, Definitions, Keys

Connect it up

Draw it

One page, no notation unless you need it: draw how these connect — A Brief History · Why We Need Definitions · The Cast · Keys: Symmetric vs Asymmetric. Put an arrow wherever one of them is what makes another possible, and label the arrow with why.

87. Recap — Lesson 16

Recap

You can now trace cryptography's three eras, run and break a Caesar cipher, explain why we need formal definitions, name the cast and tell Eve from Mallory, and contrast symmetric and asymmetric keys.

Idea§Keep in mind
Caesar cipher5.225 keys — broken instantly; shift size is irrelevant
Enigma5.2Huge keyspace, still broken — assume the machine is known
Modern era5.2Math + computers; Shannon, then DES for banking
Formal definitions5.3Prove security with games, don't just feel it
Eve vs Mallory5.4Passive (reads) vs active (tampers)
Channel goal5.4Simulate an untappable channel over an insecure one
Symmetric key5.5One shared secret encrypts AND decrypts
Asymmetric keys5.5Public key shared; only the private key is secret

Sources

  1. CS 161 Computer Security Textbook §5.2–5.5 — Wagner, Weaver, Kao, Shakir, Law & Ngai, UC Berkeley — a brief history of cryptography, the need for formal definitions, the Alice/Bob/Eve/Mallory cast, and symmetric vs asymmetric keys
  2. Communication Theory of Secrecy Systems — C. E. Shannon, Bell System Technical Journal 28(4), 1949 — the modern-era foundation; analysis of the one-time pad
  3. The Codebreakers — D. Kahn, Macmillan, 1967 — the history of the Enigma machine and the WWII effort to break it
  4. FIPS PUB 46: Data Encryption Standard (DES) — U.S. National Bureau of Standards (NIST), 1977 — the symmetric cipher standardized for banking in the 1970s

Want this taught 1-on-1? Alexander tutors Computer Security — $55/session, free consultation.

Book on Wyzant · Text (657) 465-8108