CS 161, Lesson 16, in 50 slides, opening the cryptography unit. It gives a brief history - the Caesar cipher, Enigma, and Shannon and DES - then explains why we need formal definitions, introduces the cast of Alice, Bob, Eve, and Mallory, and distinguishes symmetric from asymmetric keys. It is anchored to textbook sections 5.2 to 5.5.
Subject: Computer Security · 87 slides · applied lesson
Open the interactive version of this deck · Homework for this lesson
Title
CS 161 · Lesson 16 of 45 · Crypto Unit Begins
Caesar → Enigma → Shannon · Alice, Bob, Eve & Mallory · symmetric vs asymmetric keys
Objectives
Warm-up
Discussion prompt
Before we open L16 · Cryptography Intro: History, Definitions, Keys: without looking back, what was the main idea of L15 · Subverting Canaries, Pointer Authentication, ASLR & Combining Mitigations, and what could you do by the end of it that you could not do before?
Hint: One sentence for the idea, one for the skill. If the second one is blank, that is the part to revisit.
Answer:
CS 161 Lesson 15 (50 slides, code mode): the three things canaries don't stop, guessing vs leaking a canary (24-bit vs 56-bit entropy), pointer authentication stuffing a PAC into unused address bits, subverting ASLR by guessing or leaking one absolute address (rip = sfp+4), and why combining ASLR + NX + canaries forces an attacker to find a leak AND a write. Toy/sandbox examples only.
Concept
Until now we reasoned about systems. Now we get a tool: cryptography lets two parties communicate securely even when the channel between them is fully exposed.
Cryptography — From the Greek krypt (secret) + graphia (writing): the science of secret writing — and, more broadly, of building schemes whose security can be reasoned about mathematically.
Matching
Match the pairs
From Why a whole unit on cryptography? — match each one to what it actually does. The descriptions have been shuffled.
Why: History, Definitions & cast, Keys are easy to tell apart while they are sitting next to their descriptions and much harder afterwards, which is what this checks.
Section
Part 1 · §5.2
Concept
Cryptography is old, but it changed shape three times — each era a response to a new kind of adversary and a new kind of machine.
| Era | Tools | Hallmark |
|---|---|---|
| Classical ('pen and ink') | Paper, hand ciphers | Caesar cipher; telegraph raises the stakes |
| Mechanical | Electromechanical machines | Enigma — and the effort to break it |
| Modern | Mathematics + computers | Shannon, then DES standardized for banking |
Comparison
Comparison matrix
From §5.2 Three eras of cryptography: refill the Tools column from what you know. The rest of the table is as it appeared.
| Era | Tools | Hallmark |
|---|---|---|
| Classical ('pen and ink') | Paper, hand ciphers | Caesar cipher; telegraph raises the stakes |
| Mechanical | Electromechanical machines | Enigma — and the effort to break it |
| Modern | Mathematics + computers | Shannon, then DES standardized for banking |
Concept
The scenario: a Roman general must send orders by courier who could be captured. The 'pen and ink' answer — shift each letter of the message by a fixed amount.
Caesar cipher — A substitution cipher that shifts every letter by a fixed key amount (wrapping z back to a). With a shift of 3, 'cryptography' encodes to 'fubswrjudskb'.
Simple to use by hand — and, by modern standards, hopelessly insecure. The 1800s telegraph raised the stakes: military and diplomatic messages now traveled wires anyone could tap.
Definition probe
Sort into buckets
Every line below is part of the definition of Cryptography or of Caesar cipher — one or the other, never both. Put each where it belongs.
Intuition
Picture two alphabet rings, one inside the other. Rotate the inner ring three notches. Now every outer letter points at a different inner letter — that pairing IS the cipher.
Encrypt by reading outer → inner; decrypt by reading inner → outer (shift back by 3). The 'secret' is just the one number you rotated by.
Ask yourself: if the secret is a single number from 1 to 25, how hard can it be for an attacker to simply try them all?
Counterexample
Discussion prompt
Picture two alphabet rings, one inside the other. Rotate the inner ring three notches. Now every outer letter points at a different inner letter — that pairing IS the cipher.
That is stated as though it always holds. Do one of two things: produce a case where it fails, or say precisely what rules such a case out. "It just does" is not on the menu.
Hint: Hunt at the extremes first — zero, one, negative, empty, equal. If every extreme survives, the reason they survive is the proof.
Answer:
Encrypt by reading outer → inner; decrypt by reading inner → outer (shift back by 3). The 'secret' is just the one number you rotated by.
Pattern
Predict first
The table runs: c | 2 | 5 | f · a | 0 | 3 | d
In §5.2 Encrypt 'cab' with shift 3, given the rows so far: what is the next one — the row where Plain letter is b?
Correct: b | 1 | 4 | e
| Plain letter | Position | +3 (mod 26) | Cipher letter |
|---|---|---|---|
| c | 2 | 5 | f |
| a | 0 | 3 | d |
| b | 1 | 4 | e |
Why: The relationship between the columns, not the individual numbers, is what generates the next row. Number the alphabet a=0, b=1, c=2, …; the cipher is arithmetic on these positions, mod 26.
Worked example
Write the plaintext and its letter positions
Why: Number the alphabet a=0, b=1, c=2, …; the cipher is arithmetic on these positions, mod 26.
| Plain letter | Position | +3 (mod 26) | Cipher letter |
|---|---|---|---|
| c | 2 | 5 | f |
| a | 0 | 3 | d |
| b | 1 | 4 | e |
\[ E_3(\text{'cab'}) = \text{'fde'} \]
Verify by decrypting: shift 'fde' back by 3
Why: f→c, d→a, e→b recovers 'cab'. Encrypt then decrypt with the same key returns the original — exactly what a cipher must do.
Trade off
Comparison matrix
From §5.2 Encrypt 'cab' with shift 3: every row here is a choice with a cost. Fill the Cipher letter column, then say which row you would actually pick and what you give up for it.
| Plain letter | Position | +3 (mod 26) | Cipher letter |
|---|---|---|---|
| c | 2 | 5 | f |
| a | 0 | 3 | d |
| b | 1 | 4 | e |
Ranking
Put in order
Put the moves of §5.2 Break it: brute force all shifts into the order they have to happen.
Why: These are the moves of the worked example in the order it makes them, and each one is set up by the one before it. By Shannon's Maxim (Lesson 2) we assume the attacker knows the scheme — only the key (the shift) is secret.
Worked example
Intercept the ciphertext 'fde' and assume you know it's a Caesar cipher
Why: By Shannon's Maxim (Lesson 2) we assume the attacker knows the scheme — only the key (the shift) is secret.
Try every possible key in turn
Why: There are only 25 non-trivial shifts. Decrypt under each and look for the one that yields readable English.
| Shift tried | Decrypts 'fde' to | Sensible? |
|---|---|---|
| 1 | ecd | no |
| 2 | dbc | no |
| 3 | cab | YES — readable |
| 4 | bza | no |
\[ \text{keyspace} = 25 \text{ shifts} \;\Rightarrow\; \text{break by hand in seconds} \]
Verify the recovered key works on a longer message
Why: Shift 3 turns the full ciphertext into fluent text — confirming the key, not a coincidence. Tiny keyspace = no security.
Notation
Annotate
From §5.2 Break it: brute force all shifts — read this one piece at a time. What is each part doing?
On: \( \text{keyspace} = 25 \text{ shifts} \;\Rightarrow\; \text{break by hand in seconds} \)
Concept
Once letters are numbers 0–25, encryption is just addition that wraps around — exactly the modular arithmetic you saw in CS 70. The key is the amount added.
\[ E_k(x) = (x + k) \bmod 26, \qquad D_k(y) = (y - k) \bmod 26 \]
Decryption undoes encryption because adding then subtracting the same k returns x. This 'lock and unlock with the same number' is the seed of the symmetric-key idea we reach in Part 4.
Analogy
Discussion prompt
Explain §5.2 Caesar as modular arithmetic by analogy to something with no Computer Security in it at all — a queue, a recipe, a map, a bank balance, whatever fits. Then say where your analogy breaks.
Hint: An analogy that never breaks is not an analogy, it is the same idea wearing a hat. Find the seam — that is the part that is actually new.
Answer:
Once letters are numbers 0–25, encryption is just addition that wraps around — exactly the modular arithmetic you saw in CS 70. The key is the amount added.
Intuition
Before the telegraph, a courier carried a sealed message; intercepting it meant physically catching the courier. The 1800s telegraph put messages on wires that ran for miles through territory anyone could reach.
Suddenly an adversary could copy every message silently without stealing anything physical. Military and diplomatic traffic NEEDED real ciphers — and the weakness of pen-and-ink schemes like Caesar became a strategic liability.
Ask yourself: the Internet is the same leap, larger. Your packets cross machines you'll never see. What does that demand of every message worth protecting?
Explain it
Discussion prompt
Explain §5.2 Why telegraphs raised the stakes to a student a year behind you. No notation, no jargon they have not met — and it still has to be true.
Hint: If your explanation needs a symbol they have never seen, you are describing the notation rather than the idea.
Answer:
Ask yourself: the Internet is the same leap, larger. Your packets cross machines you'll never see. What does that demand of every message worth protecting?
Anomaly
Predict first
A student writes this, and it looks reasonable:
Caesar with shift 3 was broken instantly. 'So use shift 20 — a bigger secret must be harder!'
It is wrong. Say what breaks — and say it before you turn the page.
Correct: Confuses the size of the key VALUE with the size of the keySPACE.
Caesar with shift 3 was broken instantly. The shift value doesn't matter to the attacker.
Why: Confuses the size of the key VALUE with the size of the keySPACE. There are still only 25 possible shifts to try.
Trap
Caesar with shift 3 was broken instantly. 'So use shift 20 — a bigger secret must be harder!'
Believe a larger shift value strengthens the cipher
Why: Confuses the size of the key VALUE with the size of the keySPACE. There are still only 25 possible shifts to try.
Caesar with shift 3 was broken instantly. The shift value doesn't matter to the attacker.
Recognize the keyspace is 25 regardless of which shift you pick
Why: Brute force tries all 25 either way and finds shift 20 just as fast as shift 3. Security comes from a large keyspace, not a large number.
Concept
Scenario: WWII. Germany needs to coordinate forces by radio — broadcasts anyone can hear — so it encrypts with the Enigma, an electromechanical rotor machine far beyond pen-and-ink ciphers.
Enigma — A German electromechanical cipher machine whose rotors changed the substitution with every keypress, producing an enormous, constantly shifting keyspace.
Intuition
A working replica reached the British via Poland — so the Allies knew the machine, and had to defeat it anyway. (Foreshadow: that's Shannon's Maxim and Kerckhoff's Principle — security can't depend on the design being secret.)
The British effort enlisted mathematicians, including Alan Turing, and at its peak employed more than 10,000 people running an electromechanical, parallel search over candidate keys.
The payoff was historic: breaking Enigma is estimated to have shortened the war by about a year. Cryptanalysis had become a strategic weapon.
Step zero
Discussion prompt
§5.2 Why Enigma fell despite a vast keyspace — before any calculation: what is the plan? Name the moves in order, in plain English, without doing the arithmetic.
Hint: It starts with: Note the keyspace was astronomically larger than Caesar's 25
Answer:
Worked example
Note the keyspace was astronomically larger than Caesar's 25
Why: Rotor order, ring settings, and plugboard wiring multiplied into a number no human could search by hand — brute force seemed hopeless.
But the Allies KNEW the machine (replica via Poland)
Why: Shannon's Maxim in action: assume the attacker has the design. Knowing the machine, the question became 'find today's settings,' not 'guess the scheme.'
Exploit structure: no letter ever encrypted to itself, plus guessable plaintext ('cribs')
Why: Design quirks and predictable message fragments shrank the effective search dramatically — a huge keyspace with exploitable structure isn't huge in practice.
Run an electromechanical PARALLEL search with >10,000 people
Why: Turing's machines mechanized the key search at scale. The lesson: secrecy of the design bought nothing; only the daily key mattered — and even that fell to structure.
Blank canvas
Draw it
Draw what §5.2 Why Enigma fell despite a vast keyspace just did — the shape of it, not the line-by-line working. One picture, labels only where you need them. Then check it against the steps: anything you could not draw is a step you followed rather than understood.
Concept
After WWII, cryptography became a mathematical science. Its modern roots trace to Claude Shannon, who put secrecy on a formal footing and analyzed the one-time pad.
In the 1970s NIST standardized DES (the Data Encryption Standard) for banking, and the late 1970s saw an explosion of computational crypto theory — public-key cryptography among it.
Concept
Shannon analyzed the one-time pad: XOR the message with a truly random key as long as the message, used exactly once. He proved it leaks NOTHING about the plaintext — perfect secrecy.
The catch is the key: it must be random, as long as the message, and never reused. That impracticality is precisely why modern crypto trades perfect secrecy for COMPUTATIONAL security with short, reusable keys (the rest of the unit).
Intuition
Caesar's secret was a number you could guess. Enigma's was vast but still a finite machine state. The modern era's leap: design schemes whose security rests on problems we believe are computationally hard — and PROVE it.
Ask yourself: Enigma had a huge keyspace and was still broken. So 'big keyspace' is necessary but not sufficient — what else does a scheme need? That question is exactly why we now turn to definitions.
Concept
Claude Shannon, after WWII, gave secrecy a mathematical theory — including the proof that the one-time pad offers perfect secrecy (and why its impractical key length is the catch we revisit later).
In the 1970s NIST standardized DES so banks could encrypt transactions to a common, vetted spec. A government-blessed, public algorithm — the opposite of a secret design — became the workhorse of commercial crypto.
The late 1970s then opened computational crypto: public-key encryption, signatures, and security defined relative to an attacker's computing budget. That's the world the rest of this unit lives in.
Section
Part 2 · §5.3
Concept
We just felt that Caesar is insecure — 25 shifts, try them all. But 'feels insecure' and 'feels secure' are not science. To build trustworthy systems we need to PROVE a scheme secure or insecure.
A proof needs a precise claim. What does 'secure' even mean? Against whom, with what powers, learning what? Until those are pinned down mathematically, we have intuition, not guarantees.
Intuition
Imagine a cipher nobody can break by hand. Is it secure? An attacker with a supercomputer might still win. Or maybe the ciphertext leaks the message LENGTH, or whether two messages are equal. 'I couldn't break it' is not 'it's secure'.
So this unit will build security games: an attacker is given exact powers and a precise winning condition, and we measure their advantage. (Foreshadow: IND-CPA, the indistinguishability game, in Lesson 18.)
Ask yourself: why phrase security as a GAME the attacker plays, rather than a checklist the defender follows? Because only a game lets us say exactly what 'winning' means — and prove the attacker can't.
Step zero
Discussion prompt
§5.3 Pinning down what a definition must fix — before any calculation: what is the plan? Name the moves in order, in plain English, without doing the arithmetic.
Hint: It starts with: Name the adversary's powers
Answer:
Worked example
Name the adversary's powers
Why: Can the attacker only listen, or also inject messages? Can it ask for encryptions of chosen plaintexts? Different powers = different definitions.
Name exactly what 'winning' means for the attacker
Why: Recover the whole message? Learn one bit? Tell two messages apart? Security is the claim that even THIS weak win is out of reach.
Name the resource bound
Why: An attacker with unlimited time can brute-force almost anything. Modern definitions cap computation and allow a negligible success probability.
Verify: only now can 'secure' be a provable statement
Why: With adversary, win condition, and resources fixed, 'no efficient attacker wins with non-negligible advantage' becomes a theorem you can prove — the goal of §5.3.
Anomaly
Predict first
A student writes this, and it looks reasonable:
A startup ships a cipher: 'our team tried for months and couldn't break it.'
It is wrong. Say what breaks — and say it before you turn the page.
Correct: Absence of a known attack is not a proof.
A reviewer asks for the security claim, not the war story.
Why: Absence of a known attack is not a proof. A better-resourced adversary, or a subtle leak (length, equality of messages), may already defeat it.
Trap
A startup ships a cipher: 'our team tried for months and couldn't break it.'
Equate 'we failed to break it' with 'it is secure'
Why: Absence of a known attack is not a proof. A better-resourced adversary, or a subtle leak (length, equality of messages), may already defeat it.
A reviewer asks for the security claim, not the war story.
Demand a formal definition and a reduction/proof
Why: §5.3: state the adversary, the win condition, and the bound, then PROVE no efficient attacker wins. 'Nobody broke it yet' is a hope, not a guarantee.
Concept
Our definitions will always assume the attacker knows the entire SCHEME — every algorithm and parameter. The only thing secret is the key. That's Shannon's Maxim from Lesson 2, soon to be named Kerckhoff's Principle in Lesson 18.
Why bake this into the definition? Because a key is easy to rotate when it leaks; a secret algorithm, once reverse-engineered (Enigma!), can't be quietly replaced everywhere. Definitions that lean on a hidden design are definitions that lie.
Section
Part 3 · §5.4
Concept
Scenario: Alice in one city wants to send Bob a private message over the phone or the Internet — a channel that anyone in between can tap.
The goal of the whole unit, in one line: simulate an ideal untappable channel over an insecure one. Make the exposed wire behave, to an attacker, like a private one.
Intuition
Naming the parties — Alice the sender, Bob the receiver — turns dense protocol prose into a story you can follow. 'A sends to B' is forgettable; 'Alice sends to Bob' sticks.
More importantly, naming the ADVERSARY forces you to state its powers. Saying 'Eve' commits you to a passive attacker; saying 'Mallory' commits you to an active one. The name is shorthand for a threat model.
Ask yourself: when a protocol claims to be 'secure,' your first question should be — against Eve, or against Mallory? The answer changes everything.
Concept
Eve — the eavesdropper — A PASSIVE adversary. Eve can read everything on the channel but cannot change it. She listens; she does not touch.
Mallory — the malicious one — An ACTIVE adversary. Mallory can read AND tamper: modify, drop, inject, or reorder messages. Strictly more powerful than Eve.
Sorting
Sort into buckets
These are the pieces of L16 · Cryptography Intro: History, Definitions, Keys, out of order. Put each one back under the part of the lesson it belongs to.
Intuition
Eve is the nosy mail carrier who reads your postcard but delivers it untouched. Mallory is the carrier who reads it, erases a word, writes a new one, and delivers the forgery — and you'd never know.
These are different threats needing different defenses. Hiding the message (confidentiality) defeats Eve. Detecting changes (integrity/authenticity) is needed to defeat Mallory — and that takes a separate tool, the MAC, later in the unit.
Ask yourself: a scheme that perfectly hides the contents — does it stop Mallory? No. Mallory can still scramble the ciphertext; you decrypt to garbage and can't tell it was altered. Confidentiality ≠ integrity.
Anomaly
Predict first
A student writes this, and it looks reasonable:
A student designs a defense and assumes Eve might flip bits in transit.
It is wrong. Say what breaks — and say it before you turn the page.
Correct: Conflates the two adversaries. Eve is PASSIVE — read-only.
A student designs a defense and names the adversary precisely.
Why: Conflates the two adversaries. Eve is PASSIVE — read-only. Granting her tampering quietly turns her into Mallory and muddles the threat model.
Trap
A student designs a defense and assumes Eve might flip bits in transit.
Give Eve the power to tamper with the channel
Why: Conflates the two adversaries. Eve is PASSIVE — read-only. Granting her tampering quietly turns her into Mallory and muddles the threat model.
A student designs a defense and names the adversary precisely.
Eve reads only; tampering is Mallory's power
Why: §5.4: keep them distinct. Confidentiality is enough against Eve; defeating Mallory additionally requires integrity/authenticity. The distinction matters all unit.
Break the constraint
Discussion prompt
The rule this trap just fixed:
A student designs a defense and names the adversary precisely.
Now break it on purpose. Build a case that violates it and follow the consequences until something visibly fails. Where does the failure first show up — and would you have noticed it if you had not been looking?
Hint: The dangerous rules are the ones whose violation still produces an answer. If yours fails loudly, try to find one that fails quietly.
Answer:
Conflates the two adversaries. Eve is PASSIVE — read-only. Granting her tampering quietly turns her into Mallory and muddles the threat model.
Ranking
Put in order
Put the moves of §5.4 Same wire, two different attacks into the order they have to happen.
Why: These are the moves of the worked example in the order it makes them, and each one is set up by the one before it. Both adversaries see the bytes; the question is what each can DO with them.
Worked example
Alice sends 'transfer $50 to Bob' over the open channel
Why: Both adversaries see the bytes; the question is what each can DO with them.
Eve's attack: read and learn
Why: Passive. Eve records the amount and the recipient. She breaks confidentiality but the message Bob receives is unchanged.
Mallory's attack: rewrite to 'transfer $5000 to Mallory'
Why: Active. Mallory alters the message in flight, breaking integrity AND authenticity — Bob acts on a forgery believing it came from Alice.
| Adversary | Read? | Modify? | Breaks |
|---|---|---|---|
| Eve | yes | no | confidentiality |
| Mallory | yes | yes | confidentiality, integrity, authenticity |
Verify the lesson: a tool that only hides bytes stops Eve, not Mallory
Why: Encryption alone leaves Mallory free to scramble or swap ciphertext. Defeating Mallory needs a separate integrity tool — motivating the next lessons.
Comparison
Comparison matrix
From §5.4 Same wire, two different attacks: refill the Read? column from what you know. The rest of the table is as it appeared.
| Adversary | Read? | Modify? | Breaks |
|---|---|---|---|
| Eve | yes | no | confidentiality |
| Mallory | yes | yes | confidentiality, integrity, authenticity |
Section
Part 4 · §5.5
Concept
Scenario: Alice has a locked box she wants Bob to open — but not Eve. The whole game now reduces to one question: who holds the key?
Key — A secret value that locks (encrypts) and unlocks (decrypts). Per Shannon's Maxim, the key — not the algorithm — is the secret that security rests on.
There are two key models, and almost every primitive in this unit is one or the other. Get this distinction crisp now.
Matching
Match the pairs
Match each term to the definition this lesson gave it — not the one you would guess from the word.
Why: These are the working definitions of Caesar cipher, Enigma, Eve — the eavesdropper, Mallory — the malicious one, Key as L16 · Cryptography Intro: History, Definitions, Keys uses them. Pairing them correctly is the test of whether you could state each one with the slide switched off.
Concept
Scenario: Alice and Bob met in person last week and agreed on one shared secret. Now, apart, they use that ONE key both to encrypt and to decrypt.
Symmetric-key cryptography — Alice and Bob share a single secret key K. Encryption and decryption both use K. Anyone with K can read and write messages.
\[ C = \text{Enc}(K, M), \qquad M = \text{Dec}(K, C) \]
Intuition
Symmetric crypto is two people with identical copies of the same key to the same padlock. Either can lock the box, either can unlock it. Fast and simple — IF you could safely hand over that key.
The catch you'll feel later: how do Alice and Bob agree on K over a channel Eve is already watching? That bootstrap problem is what motivates the next idea.
Explain it
Discussion prompt
Explain §5.5 The shared-padlock picture to a student a year behind you. No notation, no jargon they have not met — and it still has to be true.
Hint: If your explanation needs a symbol they have never seen, you are describing the notation rather than the idea.
Answer:
Symmetric crypto is two people with identical copies of the same key to the same padlock. Either can lock the box, either can unlock it. Fast and simple — IF you could safely hand over that key.
Step zero
Discussion prompt
§5.5 A round trip with one shared key — before any calculation: what is the plan? Name the moves in order, in plain English, without doing the arithmetic.
Hint: It starts with: Alice and Bob share secret key K (arranged earlier, in person)
Answer:
Worked example
Alice and Bob share secret key K (arranged earlier, in person)
Why: Symmetric crypto's precondition: the same K is already in both hands and known to no one else.
Alice computes C = Enc(K, M) and sends C over the wire
Why: Eve sees C but, lacking K, cannot recover M — confidentiality holds against a passive eavesdropper.
Bob computes Dec(K, C)
Why: The SAME key that locked the message unlocks it. That single shared K is the defining feature of the symmetric model.
\[ \text{Dec}(K, \text{Enc}(K, M)) = M \]
Verify: only holders of K can read or produce valid messages
Why: Encrypt-then-decrypt under the same K returns M; anyone without K is locked out. The cost: K had to be shared securely first.
Notation
Annotate
From §5.5 A round trip with one shared key — read this one piece at a time. What is each part doing?
On: \( \text{Dec}(K, \text{Enc}(K, M)) = M \)
Concept
Scenario: Alice has never met Bob, yet wants to send him a secret today. With public-key crypto she can — no shared secret required in advance.
Asymmetric (public-key) cryptography — Each party has a key PAIR: a public key (shared with everyone) and a matching private key (kept secret). You met RSA in CS 70 — this is its security setting.
\[ C = \text{Enc}(\text{PK}_{\text{Bob}}, M), \qquad M = \text{Dec}(\text{SK}_{\text{Bob}}, C) \]
Analogy
Discussion prompt
Explain §5.5 Asymmetric (public-key) keys by analogy to something with no Computer Security in it at all — a queue, a recipe, a map, a bank balance, whatever fits. Then say where your analogy breaks.
Hint: An analogy that never breaks is not an analogy, it is the same idea wearing a hat. Find the seam — that is the part that is actually new.
Answer:
Scenario: Alice has never met Bob, yet wants to send him a secret today. With public-key crypto she can — no shared secret required in advance.
Ranking
Put in order
Put the moves of §5.5 Who holds what? into the order they have to happen.
Why: These are the moves of the worked example in the order it makes them, and each one is set up by the one before it. This is the case symmetric crypto can't bootstrap on its own — we need a key Bob can publish safely.
Worked example
Set the goal: Alice sends Bob a confidential message, no prior meeting
Why: This is the case symmetric crypto can't bootstrap on its own — we need a key Bob can publish safely.
Bob publishes his PUBLIC key; he keeps his PRIVATE key secret
Why: Anyone — including Eve — may know the public key. Only Bob holds the matching private key.
Alice encrypts under Bob's public key and sends the ciphertext
Why: The public key locks; only the matching private key unlocks. Eve seeing the public key and ciphertext still can't read M.
| Model | Keys | Shared openly | Kept secret |
|---|---|---|---|
| Symmetric | one shared key K | nothing | K (both Alice & Bob) |
| Asymmetric | public key + private key per party | the public key | the private key only |
Verify: Bob decrypts with his private key and recovers M
Why: Enc under PK then Dec under the matching SK returns M — and no one lacking SK can. The contrast with the symmetric row is the whole point.
Blank canvas
Draw it
Draw what §5.5 Who holds what? just did — the shape of it, not the line-by-line working. One picture, labels only where you need them. Then check it against the steps: anything you could not draw is a step you followed rather than understood.
Intuition
Asymmetric crypto is a padlock Bob hands out OPEN, by the thousand. Anyone can snap a message shut inside it. But only Bob keeps the one key that reopens it — his private key.
This is what symmetric crypto couldn't do: it lets total strangers send Bob a secret with nothing arranged in advance, because the locking key being public is harmless.
Ask yourself: with the open-padlock model, what is the ONE thing Bob must never let leak? (His private key — the only thing that reopens the locks.)
Counterexample
Discussion prompt
Asymmetric crypto is a padlock Bob hands out OPEN, by the thousand. Anyone can snap a message shut inside it. But only Bob keeps the one key that reopens it — his private key.
That is stated as though it always holds. Do one of two things: produce a case where it fails, or say precisely what rules such a case out. "It just does" is not on the menu.
Hint: Hunt at the extremes first — zero, one, negative, empty, equal. If every extreme survives, the reason they survive is the proof.
Answer:
Ask yourself: with the open-padlock model, what is the ONE thing Bob must never let leak? (His private key — the only thing that reopens the locks.)
Concept
Neither model is 'better' — they solve different problems. The unit uses both, often together: asymmetric crypto to agree on a key, then fast symmetric crypto for the bulk data.
| Question | Symmetric | Asymmetric |
|---|---|---|
| Keys involved | one shared K | public + private pair |
| Prior arrangement? | must share K first | none — publish public key |
| Speed | fast | slow (heavy math) |
| Best for | bulk encryption | key setup, signatures |
Trade off
Comparison matrix
From §5.5 Two key models, two cost profiles: every row here is a choice with a cost. Fill the Symmetric column, then say which row you would actually pick and what you give up for it.
| Question | Symmetric | Asymmetric |
|---|---|---|
| Keys involved | one shared K | public + private pair |
| Prior arrangement? | must share K first | none — publish public key |
| Speed | fast | slow (heavy math) |
| Best for | bulk encryption | key setup, signatures |
Anomaly
Predict first
A student writes this, and it looks reasonable:
Bob, being careful, hides his public key so attackers can't get it.
It is wrong. Say what breaks — and say it before you turn the page.
Correct: Misreads 'public.' If Bob hides his public key, Alice can't get it either — and nobody can send him anything.
Bob publishes his public key widely and guards only his private key.
Why: Misreads 'public.' If Bob hides his public key, Alice can't get it either — and nobody can send him anything. The name says it: it's meant to be shared.
Trap
Bob, being careful, hides his public key so attackers can't get it.
Treat the public key as a secret to protect
Why: Misreads 'public.' If Bob hides his public key, Alice can't get it either — and nobody can send him anything. The name says it: it's meant to be shared.
Bob publishes his public key widely and guards only his private key.
Public key is shared; ONLY the private key is secret
Why: §5.5: security depends solely on keeping the private key secret. Eve may freely know the public key and still cannot decrypt.
Anomaly
Predict first
A student writes this, and it looks reasonable:
Alice and Bob never met. A student says: 'just use their shared symmetric key.'
It is wrong. Say what breaks — and say it before you turn the page.
Correct: Symmetric crypto presupposes a key already shared over a secure channel — the very thing Alice and Bob lack.
Alice and Bob never met, and Eve watches the channel.
Why: Symmetric crypto presupposes a key already shared over a secure channel — the very thing Alice and Bob lack. You can't bootstrap it from nothing over Eve's wire.
Trap
Alice and Bob never met. A student says: 'just use their shared symmetric key.'
Assume a shared symmetric key already exists between strangers
Why: Symmetric crypto presupposes a key already shared over a secure channel — the very thing Alice and Bob lack. You can't bootstrap it from nothing over Eve's wire.
Alice and Bob never met, and Eve watches the channel.
Use asymmetric crypto (or key exchange) to establish a secret, THEN switch to symmetric
Why: §5.5: the models aren't interchangeable. Asymmetric solves the no-prior-secret case; symmetric is the fast follow-up once a key exists.
Two truths and a lie
Sort into buckets
Some of these hold up and some are the exact mistakes this lesson is built to prevent. Sort them.
Concept
Today's vocabulary unlocks a toolbox. Each primitive ahead is symmetric or asymmetric, and each provides confidentiality, integrity/authenticity, or a supporting service.
| Primitive | Key model | Provides |
|---|---|---|
| Block ciphers & modes | symmetric | confidentiality of bulk data |
| MACs | symmetric | integrity / authenticity |
| Public-key encryption | asymmetric | confidentiality without a shared key |
| Digital signatures | asymmetric | integrity / authenticity, publicly verifiable |
| Hash functions | keyless | integrity, fingerprints, building block |
| PRNGs | keyless/seeded | the randomness everything else needs |
| Key exchange | asymmetric | agree on a symmetric key over Eve's channel |
Comparison
Comparison matrix
From Where this unit is going: refill the Key model column from what you know. The rest of the table is as it appeared.
| Primitive | Key model | Provides |
|---|---|---|
| Block ciphers & modes | symmetric | confidentiality of bulk data |
| MACs | symmetric | integrity / authenticity |
| Public-key encryption | asymmetric | confidentiality without a shared key |
| Digital signatures | asymmetric | integrity / authenticity, publicly verifiable |
| Hash functions | keyless | integrity, fingerprints, building block |
| PRNGs | keyless/seeded | the randomness everything else needs |
| Key exchange | asymmetric | agree on a symmetric key over Eve's channel |
Constraint
Discussion prompt
Run The crypto-intro checklist with this step confiscated:
Cast (§5.4): Alice ↔ Bob; Eve reads only (passive); Mallory reads AND tampers (active).
Is it still possible? If it is, say what takes its place and what it costs you. If it is not, say exactly what that step was providing that nothing else does.
Hint: A step you can drop for free was never load-bearing. If you cannot drop it, name the thing that goes wrong the moment it is gone.
Answer:
Pattern
Edge cases
Discussion prompt
The crypto-intro checklist works on the cases you have just seen. Push it to the edge: what is the most degenerate input it still handles — empty, zero, one item, everything equal — and what is the first case where it stops being true? Name the case, not just "it breaks".
Hint: Try the smallest legal input, then the largest, then the one where two things collide. Methods are specified at their edges; the middle takes care of itself.
Answer:
Check
Alice wants to send Bob a confidential message using public-key cryptography. Bob has already published his public key, and Eve is listening on the wire.
Check your understanding
Which statement is correct?
Answer: A
Why: §5.5: in public-key crypto Alice encrypts under Bob's PUBLIC key and only the matching PRIVATE key decrypts. The public key is meant to be shared, so Eve knowing it gives her no advantage — and as a passive eavesdropper she only reads.
Concept
Concept
Concept
Connect it up
Draw it
One page, no notation unless you need it: draw how these connect — A Brief History · Why We Need Definitions · The Cast · Keys: Symmetric vs Asymmetric. Put an arrow wherever one of them is what makes another possible, and label the arrow with why.
Recap
You can now trace cryptography's three eras, run and break a Caesar cipher, explain why we need formal definitions, name the cast and tell Eve from Mallory, and contrast symmetric and asymmetric keys.
| Idea | § | Keep in mind |
|---|---|---|
| Caesar cipher | 5.2 | 25 keys — broken instantly; shift size is irrelevant |
| Enigma | 5.2 | Huge keyspace, still broken — assume the machine is known |
| Modern era | 5.2 | Math + computers; Shannon, then DES for banking |
| Formal definitions | 5.3 | Prove security with games, don't just feel it |
| Eve vs Mallory | 5.4 | Passive (reads) vs active (tampers) |
| Channel goal | 5.4 | Simulate an untappable channel over an insecure one |
| Symmetric key | 5.5 | One shared secret encrypts AND decrypts |
| Asymmetric keys | 5.5 | Public key shared; only the private key is secret |
Want this taught 1-on-1? Alexander tutors Computer Security — $55/session, free consultation.