CS 161, Lesson 20, in 52 slides. It explains what a block cipher is - a keyed permutation - why AES on its own is not IND-CPA even though it is a strong PRP, and how the modes of operation ECB, CBC, and CTR, together with parallelization, turn the primitive into a usable scheme. It is anchored to textbook sections 6.4 to 6.7.
Subject: Computer Security · 85 slides · applied lesson
Open the interactive version of this deck · Homework for this lesson
Title
CS 161 · Lesson 20 of 45
Block ciphers as keyed permutations · PRPs · modes of operation (ECB / CBC / CTR)
Objectives
Warm-up
Discussion prompt
Before we open L20 · Block Ciphers, PRPs & Modes of Operation (ECB/CBC/CTR): without looking back, what was the main idea of L19 · One-Time Pad, XOR & the IND-CPA Game, and what could you do by the end of it that you could not do before?
Hint: One sentence for the idea, one for the skill. If the second one is blank, that is the part to revisit.
Answer:
CS 161, Lesson 19, in 50 slides. It covers XOR and its algebra in section 6.2, the one-time pad and its perfect secrecy in section 6.3, and the fatal two-time-pad break that key reuse allows, as seen in VENONA. It then gives the formal IND-CPA game from section 6.1 and uses it to prove that a one-time pad with a reused key is not IND-CPA. It is anchored to textbook sections 6.1 to 6.3.
Concept
Lesson 18 set the bar (IND-CPA) and Lesson 19 built the one-time pad. Now we build a practical scheme from a real primitive — and the primitive alone is not enough.
Matching
Match the pairs
From Three questions this lesson answers — match each one to what it actually does. The descriptions have been shuffled.
Why: What is the primitive?, How strong is it?, How do we use it? are easy to tell apart while they are sitting next to their descriptions and much harder afterwards, which is what this checks.
Section
Part 1 · §6.4 What a block cipher is
Concept
You're handed a hardware box. Feed it a fixed-size chunk of bits and a key, and it spits out a scrambled chunk of the same size. That's the whole device — it does one block at a time.
But real messages are emails, images, and files of arbitrary length. The gap between 'scramble one fixed block' and 'encrypt my message securely' is exactly what this lesson closes.
Counterexample
Discussion prompt
You're handed a hardware box. Feed it a fixed-size chunk of bits and a key, and it spits out a scrambled chunk of the same size. That's the whole device — it does one block at a time.
That is stated as though it always holds. Do one of two things: produce a case where it fails, or say precisely what rules such a case out. "It just does" is not on the menu.
Hint: Hunt at the extremes first — zero, one, negative, empty, equal. If every extreme survives, the reason they survive is the proof.
Concept
Block cipher — A function that maps a fixed n-bit input block to an n-bit output block under a k-bit key. The key selects one of 2^k different scrambling settings. It has two operations: Encrypt and Decrypt.
Encrypt takes an n-bit plaintext and a k-bit key and returns an n-bit ciphertext. Decrypt takes an n-bit ciphertext and the same key and returns the n-bit plaintext.
Concept
\[ E : \{0,1\}^k \times \{0,1\}^n \;\longrightarrow\; \{0,1\}^n \]
Once we fix the key K, the cipher becomes a function from n-bit blocks to n-bit blocks:
\[ E_K : \{0,1\}^n \;\longrightarrow\; \{0,1\}^n \]
Analogy
Discussion prompt
Explain §6.4 The notation by analogy to something with no Computer Security in it at all — a queue, a recipe, a map, a bank balance, whatever fits. Then say where your analogy breaks.
Hint: An analogy that never breaks is not an analogy, it is the same idea wearing a hat. Find the seam — that is the part that is actually new.
Answer:
Once we fix the key K, the cipher becomes a function from n-bit blocks to n-bit blocks:
Concept
Two non-negotiable properties. First, the block cipher is deterministic: the same plaintext and key always give the same ciphertext. Second, for a fixed key it is a permutation — a bijection on the set of n-bit blocks.
\[ D_K = E_K^{-1} \qquad\Longrightarrow\qquad D_K(E_K(M)) = M \]
Intuition
Decryption has to recover exactly the plaintext that went in. That only works if the encryption map never collides — no two different plaintexts may land on the same ciphertext.
If two plaintexts M and M' both encrypted to the same C, then Bob holding C couldn't tell which one to return — decryption would be ambiguous. A function with no collisions on a finite set is a bijection, i.e. a permutation.
Ask yourself: a permutation of n-bit blocks just shuffles all 2^n possible blocks into a new order — and the key picks which shuffle. How many shuffles can a k-bit key choose from? (Exactly 2^k of them.)
Explain it
Discussion prompt
Explain §6.4 Why must it be invertible? to a student a year behind you. No notation, no jargon they have not met — and it still has to be true.
Hint: If your explanation needs a symbol they have never seen, you are describing the notation rather than the idea.
Answer:
Decryption has to recover exactly the plaintext that went in. That only works if the encryption map never collides — no two different plaintexts may land on the same ciphertext.
Ranking
Put in order
Put the moves of §6.4 Encrypt then decrypt, one block into the order they have to happen.
Why: These are the moves of the worked example in the order it makes them, and each one is set up by the one before it. A k-bit key indexes 2^k scrambling settings; choosing K nails down a single, fixed shuffle of the n-bit blocks.
Worked example
Fix a key K; this selects one permutation E_K out of 2^k
Why: A k-bit key indexes 2^k scrambling settings; choosing K nails down a single, fixed shuffle of the n-bit blocks.
Encrypt one n-bit plaintext block M to get C = E_K(M)
Why: Deterministic: the same M under the same K always produces the same C — there is no randomness inside the box.
Apply the inverse permutation: D_K(C)
Why: Because E_K is a bijection, its inverse D_K = E_K^{-1} exists and is unique.
Verify the round trip returns the original: D_K(E_K(M)) = M
Why: Inverting the exact permutation the key selected lands us back on M — the defining correctness property of a block cipher.
Blank canvas
Draw it
Draw what §6.4 Encrypt then decrypt, one block just did — the shape of it, not the line-by-line working. One picture, labels only where you need them. Then check it against the steps: anything you could not draw is a step you followed rather than understood.
Concept
AES (the Advanced Encryption Standard, originally Rijndael) was designed in 1998 by Belgian cryptographers Joan Daemen and Vincent Rijmen and won the open NIST competition to standardize a cipher.
AES has block size n = 128 bits. The key can be 128, 192, or 256 bits; in this class assume k = 128.
Anomaly
Predict first
A student writes this, and it looks reasonable:
A student: 'If I know the algorithm, I can run Decrypt to undo Encrypt — the key only matters for encrypting.'
It is wrong. Say what breaks — and say it before you turn the page.
Correct: False. There are 2^k different permutations; the algorithm is public but the KEY selects which one.
A student: what does the key actually do in Decrypt?
Why: False. There are 2^k different permutations; the algorithm is public but the KEY selects which one. Without K you don't know which of 2^k shuffles to invert.
Trap
A student: 'If I know the algorithm, I can run Decrypt to undo Encrypt — the key only matters for encrypting.'
Treat the algorithm as enough to invert the cipher
Why: False. There are 2^k different permutations; the algorithm is public but the KEY selects which one. Without K you don't know which of 2^k shuffles to invert.
A student: what does the key actually do in Decrypt?
The key selects the permutation; D_K = E_K^{-1} is defined only for that specific K
Why: §6.4 + Kerckhoff (L18): the design is public, the key is the secret. Decryption needs the same K that encryption used — that's why D_K(E_K(M)) = M only holds under one key.
Section
Part 2 · §6.5 Block-cipher security & PRPs
Concept
Recall the L18 result: any deterministic encryption fails IND-CPA. A block cipher is deterministic by definition, so AES alone is not IND-CPA.
It's the same break as one-time-pad key reuse: equal plaintexts produce equal ciphertexts, and the equality is a visible signal Eve can exploit.
Step zero
Discussion prompt
§6.5 Break AES-alone in the IND-CPA game — before any calculation: what is the plan? Name the moves in order, in plain English, without doing the arithmetic.
Hint: It starts with: Eve uses her chosen-plaintext oracle to encrypt M_0, recording c_0 =…
Answer:
Worked example
Eve uses her chosen-plaintext oracle to encrypt M_0, recording c_0 = E_K(M_0)
Why: CPA power lets her get the exact ciphertext M_0 produces under the key — and the cipher is deterministic, so c_0 is fixed.
Eve submits the pair M_0, M_1 to the challenge and receives C = E_K(M_b)
Why: Now she just compares C against the value she precomputed.
\[ b' = \begin{cases} 0 & \text{if } C = c_0 \\ 1 & \text{otherwise} \end{cases} \]
Verify Eve wins with probability 1
Why: Determinism makes E_K(M_0) repeat exactly, so C = c_0 iff b = 0. A perfect distinguisher — AES alone is not IND-CPA. We must add randomness later.
Notation
Annotate
From §6.5 Break AES-alone in the IND-CPA game — read this one piece at a time. What is each part doing?
On: \( b' = \begin{cases} 0 & \text{if } C = c_0 \\ 1 & \text{otherwise} \end{cases} \)
Concept
AES is still extremely useful, because it has a strong security property of its own: it is a pseudorandom permutation (PRP).
Pseudorandom permutation (PRP) — A block cipher is a PRP if, with a randomly chosen key, it is computationally indistinguishable from a permutation chosen uniformly at random from all permutations of n-bit blocks.
Intuition
Imagine Eve is handed a black box that answers queries: she sends in n-bit inputs and gets back n-bit outputs. The box is secretly one of two kinds.
Box (I): the AES function E_K with a random key K. Box (II): a permutation drawn uniformly at random from ALL permutations of n-bit blocks. Eve may query as many inputs as she likes and study the outputs.
Ask yourself: if Eve can't tell which box she's holding — guessing right only ~1/2 the time — what does that say about AES? (Its outputs look like pure random shuffling; the structure is invisible.)
Step zero
Discussion prompt
§6.5 Walk the box experiment — before any calculation: what is the plan? Name the moves in order, in plain English, without doing the arithmetic.
Hint: It starts with: A coin flip decides whether Eve gets Box (I) AES-with-random-K or Box…
Answer:
Worked example
A coin flip decides whether Eve gets Box (I) AES-with-random-K or Box (II) a truly random permutation
Why: Eve doesn't know which; her job is to distinguish them using only input/output queries.
Eve queries chosen inputs and records the outputs, hunting for any pattern that betrays AES's structure
Why: This is the CPA-style probing of the box — exactly the access a real attacker has to an encryption oracle.
Eve outputs a guess: 'this is AES' or 'this is a random permutation'
Why: If AES is a good PRP, no efficient strategy of queries gives her a reliable tell.
\[ \Pr[\text{Eve guesses correctly}] \;\le\; \tfrac{1}{2} + \varepsilon, \qquad \varepsilon \approx \tfrac{1}{2^{128}} \]
Verify the meaning: she does no better than a coin flip plus a negligible edge
Why: §6.5: that negligible ε is the PRP advantage. AES being a PRP means its outputs are indistinguishable from random — so a ciphertext leaks nothing about M.
Notation
Annotate
From §6.5 Walk the box experiment — read this one piece at a time. What is each part doing?
On: \( \Pr[\text{Eve guesses correctly}] \;\le\; \tfrac{1}{2} + \varepsilon, \qquad \varepsilon \approx \tfrac{1}{2^{128}} \)
Concept
After decades of analysis, the best known attack on AES is still essentially brute force: try every possible key until one decrypts correctly.
\[ 2^{128}\ \text{keys worst case},\qquad 2^{127}\ \text{on average} \]
Intuition
2^128 is about 3.4 × 10^38. Even imagining billions of machines each testing billions of keys per second, exhausting the keyspace would take far longer than the lifetime of the solar system.
So 'computationally indistinguishable' isn't a hedge — the gap ε ≈ 1/2^128 is so tiny it is meaningless in practice. Given a ciphertext, an attacker learns nothing usable about M.
Ask yourself: if brute force is infeasible and no structural attack beats it, what's the weak point left? (Not the cipher — it's how we USE it: the mode.)
Anomaly
Predict first
A student writes this, and it looks reasonable:
A student: 'AES is a strong PRP with a 128-bit key, so just AES-encrypting each block of my message is IND-CPA secure.'
It is wrong. Say what breaks — and say it before you turn the page.
Correct: False. PRP strength is about one block looking random.
A student: what does a PRP give you, and what does it NOT give you?
Why: False. PRP strength is about one block looking random. But AES is DETERMINISTIC, so equal plaintext blocks give equal ciphertext blocks — Eve wins the game with probability 1 (this is ECB).
Trap
A student: 'AES is a strong PRP with a 128-bit key, so just AES-encrypting each block of my message is IND-CPA secure.'
Conflate 'strong PRP' with 'IND-CPA scheme'
Why: False. PRP strength is about one block looking random. But AES is DETERMINISTIC, so equal plaintext blocks give equal ciphertext blocks — Eve wins the game with probability 1 (this is ECB).
A student: what does a PRP give you, and what does it NOT give you?
Use the PRP as a building block, then add randomness with a MODE (an IV/nonce) to reach IND-CPA
Why: §6.5: the PRP property makes each block look random, but only a randomized MODE (CBC/CTR with a fresh IV) breaks the repeat signal and achieves IND-CPA.
Section
Part 3 · §6.6 ECB mode
Concept
A block cipher handles exactly n bits. To encrypt a longer message we chop it into n-bit blocks M_1, M_2, …, M_L and apply the cipher across them. How we chain the blocks is called a mode of operation.
The simplest idea — encrypt each block independently — is called ECB, and it is exactly the wrong thing to do.
Concept
ECB (Electronic Code Book) — Split the message into n-bit blocks and encrypt each block independently with the same key. No chaining, no randomness.
\[ C_i = E_K(M_i), \qquad M_i = D_K(C_i) \]
Intuition
ECB feels obviously correct: each block is encrypted with a strong cipher, so each block is safe. The error is thinking block-by-block instead of about the whole message.
Because there's no randomness and no chaining, the cipher is still a fixed deterministic function — so whenever the same plaintext block appears twice, the same ciphertext block appears twice.
Ask yourself: if your image has a big region of one solid color (lots of identical blocks), what will the ciphertext look like? (The same repeated pattern — the shape shows through.)
Sorting
Sort into buckets
These are the pieces of L20 · Block Ciphers, PRPs & Modes of Operation (ECB/CBC/CTR), out of order. Put each one back under the part of the lesson it belongs to.
Concept
\[ M_i = M_j \;\Longrightarrow\; C_i = C_j \]
Identical plaintext blocks become identical ciphertext blocks, leaking where the message repeats. The famous demonstration is the 'ECB penguin': encrypting a bitmap of Tux with ECB still shows the penguin's outline, because the solid color regions repeat.
Ranking
Put in order
Put the moves of §6.6 Watch repeats leak through ECB into the order they have to happen.
Why: These are the moves of the worked example in the order it makes them, and each one is set up by the one before it. Blocks 1 and 3 are identical — a realistic situation for images, padded records, or repeated headers.
Worked example
Take a message whose blocks are M_1 = 'AAAA', M_2 = 'BBBB', M_3 = 'AAAA'
Why: Blocks 1 and 3 are identical — a realistic situation for images, padded records, or repeated headers.
Encrypt each block independently under the same key
Why: ECB applies the same fixed permutation E_K to each block with no chaining and no IV.
| i | M_i | C_i = E_K(M_i) |
|---|---|---|
| 1 | AAAA | 9f3c… |
| 2 | BBBB | 1ae8… |
| 3 | AAAA | 9f3c… |
Verify the leak: C_1 = C_3, so Eve learns block 1 = block 3 without any key
Why: §6.6: the repeat in the plaintext is copied verbatim into the ciphertext. Eve reads the message's structure — and in the game, equal challenge messages would be trivially distinguishable.
Comparison
Comparison matrix
From §6.6 Watch repeats leak through ECB: refill the M_i column from what you know. The rest of the table is as it appeared.
| i | M_i | C_i = E_K(M_i) |
|---|---|---|
| 1 | AAAA | 9f3c… |
| 2 | BBBB | 1ae8… |
| 3 | AAAA | 9f3c… |
Anomaly
Predict first
A student writes this, and it looks reasonable:
A student: 'The penguin only showed up because of a weak cipher. With AES-256 and a strong key, ECB is fine.'
It is wrong. Say what breaks — and say it before you turn the page.
Correct: The leak is STRUCTURAL: M_i = M_j ⇒ C_i = C_j holds for ANY deterministic block cipher, no matter how strong.
A student: where does the ECB leak actually come from?
Why: The leak is STRUCTURAL: M_i = M_j ⇒ C_i = C_j holds for ANY deterministic block cipher, no matter how strong. The penguin appears even with perfect AES.
Trap
A student: 'The penguin only showed up because of a weak cipher. With AES-256 and a strong key, ECB is fine.'
Blame the cipher / key strength for the leak
Why: Wrong. The leak is STRUCTURAL: M_i = M_j ⇒ C_i = C_j holds for ANY deterministic block cipher, no matter how strong. The penguin appears even with perfect AES.
A student: where does the ECB leak actually come from?
Recognize the leak as determinism, not weakness — fix it with a randomized MODE, not a bigger key
Why: §6.6: equal blocks map to equal ciphertexts because E_K is a fixed function. A 256-bit key doesn't change that; only chaining or a nonce (CBC/CTR) does.
Section
Part 4 · §6.6 CBC & CTR
Concept
Both good modes start by adding a fresh, random value — an initialization vector (IV), also called a nonce — so that encrypting the same message twice gives different ciphertexts. That randomness is what gets us to IND-CPA.
We'll keep two modes: CBC (cipher block chaining) and CTR (counter mode). Two others — OFB and CFB — also exist, but CBC and CTR are the workhorses.
Concept
CBC (Cipher Block Chaining) — Before encrypting each block, XOR it with the previous ciphertext block. The first block is XORed with a random IV (which is published as C_0).
\[ C_0 = \text{IV} \;(\text{random}), \qquad C_i = E_K(P_i \oplus C_{i-1}) \]
Definition probe
Sort into buckets
Every line below is part of the definition of Block cipher or of CBC (Cipher Block Chaining) — one or the other, never both. Put each where it belongs.
Intuition
In ECB, equal plaintext blocks fed the cipher equal inputs. In CBC, each block is first XORed with the previous ciphertext — which is effectively random and different each time.
So even two identical plaintext blocks enter the cipher as different inputs, and come out as different ciphertexts. The IV being random and unpredictable means even the first block, and the whole message, encrypts differently on every run.
Ask yourself: what happens if you reuse the same IV for two messages that start identically? (Their first ciphertext blocks match — so the IV must be fresh and unpredictable every time.)
Concept
\[ P_i = D_K(C_i) \oplus C_{i-1} \]
To undo CBC, decrypt the block with D_K, then XOR back the previous ciphertext block. Note CBC uses the decryption function D_K to decrypt — and the receiver already has every C_i, including the IV = C_0.
Step zero
Discussion prompt
§6.6 Trace CBC over three blocks — before any calculation: what is the plan? Name the moves in order, in plain English, without doing the arithmetic.
Hint: It starts with: Start from a random IV = C_0 and three plaintext blocks P_1, P_2, P_3
Answer:
Worked example
Start from a random IV = C_0 and three plaintext blocks P_1, P_2, P_3
Why: C_0 is sent in the clear so Bob can start the chain; it must be freshly random for each message.
Encrypt each block by XOR-then-cipher, feeding the previous ciphertext forward
Why: Each C_i depends on C_{i-1}, so the chain links every block to all the ones before it.
| i | cipher input (P_i ⊕ C_{i-1}) | C_i = E_K(input) |
|---|---|---|
| 1 | P_1 ⊕ IV | C_1 |
| 2 | P_2 ⊕ C_1 | C_2 |
| 3 | P_3 ⊕ C_2 | C_3 |
Verify decryption recovers P_2: D_K(C_2) ⊕ C_1 = (P_2 ⊕ C_1) ⊕ C_1 = P_2
Why: §6.6: D_K undoes E_K to recover the cipher input P_2 ⊕ C_1, and XORing C_1 again cancels it. The chain inverts cleanly because Bob has all the C_i.
Trade off
Comparison matrix
From §6.6 Trace CBC over three blocks: every row here is a choice with a cost. Fill the cipher input (P_i ⊕ C_{i-1}) column, then say which row you would actually pick and what you give up for it.
| i | cipher input (P_i ⊕ C_{i-1}) | C_i = E_K(input) |
|---|---|---|
| 1 | P_1 ⊕ IV | C_1 |
| 2 | P_2 ⊕ C_1 | C_2 |
| 3 | P_3 ⊕ C_2 | C_3 |
Concept
CTR (Counter mode) — Encrypt a nonce concatenated with a counter to produce a keystream block, then XOR that with the plaintext. The plaintext never enters the cipher — it's a one-time pad built from the block cipher.
\[ Z_i = E_K(\text{IV} \,\Vert\, i), \qquad C_i = Z_i \oplus M_i \]
Concept
The key point about CTR: the plaintext never passes through the block cipher. The cipher only produces the keystream Z_i, and the message is XORed in afterward — exactly the one-time-pad idea from L19.
\[ M_i = E_K(\text{IV} \,\Vert\, i) \oplus C_i \]
Intuition
To decrypt CTR you regenerate the same keystream Z_i = E_K(IV ‖ i) and XOR it against the ciphertext. Since XOR is its own inverse, that recovers M_i. You used the encryption function E_K both times.
OFB mode shares this property: it also builds a keystream and uses only E_K. (CFB uses E_K for the keystream too.) Modes that build a pad never invoke the decryption function.
Ask yourself: if encrypting and decrypting both just compute E_K(IV ‖ i) and XOR, do they depend on each other across blocks? (No — each block is independent, which is why CTR parallelizes.)
Ranking
Put in order
Put the moves of §6.6 Trace a CTR keystream into the order they have to happen.
Why: These are the moves of the worked example in the order it makes them, and each one is set up by the one before it. Each block uses a distinct input IV ‖ i, so the cipher produces a fresh, independent keystream block each time.
Worked example
Fix a random nonce IV; the counter i runs 1, 2, 3, …
Why: Each block uses a distinct input IV ‖ i, so the cipher produces a fresh, independent keystream block each time.
Compute the keystream block by block, then XOR with the plaintext
Why: The plaintext is XORed onto the keystream — it never enters E_K; the cipher is only making one-time-pad material.
| i | Z_i = E_K(IV ‖ i) | C_i = Z_i ⊕ M_i |
|---|---|---|
| 1 | Z_1 | Z_1 ⊕ M_1 |
| 2 | Z_2 | Z_2 ⊕ M_2 |
| 3 | Z_3 | Z_3 ⊕ M_3 |
Verify decryption: E_K(IV ‖ i) ⊕ C_i = Z_i ⊕ (Z_i ⊕ M_i) = M_i
Why: §6.6: regenerating Z_i and XORing cancels it, recovering M_i — using E_K, never D_K. This is the one-time pad realized with a block cipher.
Comparison
Comparison matrix
From §6.6 Trace a CTR keystream: refill the Z_i = E_K(IV ‖ i) column from what you know. The rest of the table is as it appeared.
| i | Z_i = E_K(IV ‖ i) | C_i = Z_i ⊕ M_i |
|---|---|---|
| 1 | Z_1 | Z_1 ⊕ M_1 |
| 2 | Z_2 | Z_2 ⊕ M_2 |
| 3 | Z_3 | Z_3 ⊕ M_3 |
Anomaly
Predict first
A student writes this, and it looks reasonable:
A student: 'To decrypt CTR mode, run D_K on each ciphertext block, just like CBC.'
It is wrong. Say what breaks — and say it before you turn the page.
Correct: In CTR the plaintext never went through E_K, so there's nothing for D_K to invert.
A student: which block-cipher function does CTR decryption call?
Why: In CTR the plaintext never went through E_K, so there's nothing for D_K to invert. Running D_K(C_i) gives garbage.
Trap
A student: 'To decrypt CTR mode, run D_K on each ciphertext block, just like CBC.'
Assume every mode decrypts with D_K
Why: Wrong. In CTR the plaintext never went through E_K, so there's nothing for D_K to invert. Running D_K(C_i) gives garbage.
A student: which block-cipher function does CTR decryption call?
Regenerate the keystream with E_K and XOR: M_i = E_K(IV ‖ i) ⊕ C_i
Why: §6.6: CTR (and OFB) build a one-time pad, so BOTH encryption and decryption call E_K. D_K is only used by modes like ECB and CBC that push the plaintext through the cipher.
Section
Part 5 · §6.7 Parallelization
Concept
To encrypt block i in CBC you need C_{i-1} first, because C_i = E_K(P_i ⊕ C_{i-1}). You can't start block i until block i−1 is done.
So CBC encryption cannot be parallelized — it's a strict left-to-right chain. On a many-core machine, this is a real performance cost.
Explain it
Discussion prompt
Explain §6.7 CBC encryption is inherently sequential to a student a year behind you. No notation, no jargon they have not met — and it still has to be true.
Hint: If your explanation needs a symbol they have never seen, you are describing the notation rather than the idea.
Answer:
To encrypt block i in CBC you need C_{i-1} first, because C_i = E_K(P_i ⊕ C_{i-1}). You can't start block i until block i−1 is done.
Concept
Decryption is different. P_i = D_K(C_i) ⊕ C_{i-1} needs only C_i and C_{i-1} — and when decrypting you already hold the entire ciphertext. Every C_i is available up front.
\[ P_i = D_K(C_i) \oplus C_{i-1} \quad(\text{all } C_i \text{ known in advance}) \]
Analogy
Discussion prompt
Explain §6.7 But CBC DECRYPTION parallelizes by analogy to something with no Computer Security in it at all — a queue, a recipe, a map, a bank balance, whatever fits. Then say where your analogy breaks.
Hint: An analogy that never breaks is not an analogy, it is the same idea wearing a hat. Find the seam — that is the part that is actually new.
Answer:
Decryption is different. P_i = D_K(C_i) ⊕ C_{i-1} needs only C_i and C_{i-1} — and when decrypting you already hold the entire ciphertext. Every C_i is available up front.
Intuition
When you encrypt, the ciphertext blocks don't exist yet — you're creating C_{i-1} as you go, so you must wait for it. The dependency is on a value you haven't computed.
When you decrypt, all the C_i already arrived together. The formula for P_i references only ciphertext blocks, every one of which you have — so all blocks can be decrypted at once, on different cores.
Ask yourself: CTR's input is IV ‖ i, which depends only on a fixed nonce and the counter. Does any CTR block ever wait for another? (No — so CTR parallelizes in BOTH directions.)
Counterexample
Discussion prompt
When you encrypt, the ciphertext blocks don't exist yet — you're creating C_{i-1} as you go, so you must wait for it. The dependency is on a value you haven't computed.
That is stated as though it always holds. Do one of two things: produce a case where it fails, or say precisely what rules such a case out. "It just does" is not on the menu.
Hint: Hunt at the extremes first — zero, one, negative, empty, equal. If every extreme survives, the reason they survive is the proof.
Answer:
Ask yourself: CTR's input is IV ‖ i, which depends only on a fixed nonce and the counter. Does any CTR block ever wait for another? (No — so CTR parallelizes in BOTH directions.)
Concept
Every CTR block depends only on the nonce and its own counter i — never on any other block. So both CTR encryption and CTR decryption fully parallelize; you can compute the whole keystream at once and even seek to an arbitrary block.
\[ C_i = E_K(\text{IV} \,\Vert\, i) \oplus M_i \quad(\text{each } i \text{ independent}) \]
Worked example
Lay the two modes side by side on three properties
Why: Parallelizability and which block-cipher function each mode calls are the practical levers that drive real-world mode choice.
| Mode | Encrypt parallel? | Decrypt parallel? | Uses D_K? |
|---|---|---|---|
| CBC | No (needs C_{i-1}) | Yes (all C_i known) | Yes (decrypt only) |
| CTR | Yes (independent) | Yes (independent) | No (E_K both ways) |
Verify the takeaways: CTR wins on parallelism and needs no decryption circuit
Why: §6.7: CTR encrypt AND decrypt parallelize and use only E_K; CBC encryption is sequential and CBC needs D_K to decrypt. This is why CTR is often preferred for high-throughput systems.
Comparison
Comparison matrix
From §6.7 CBC vs CTR at a glance: refill the Encrypt parallel? column from what you know. The rest of the table is as it appeared.
| Mode | Encrypt parallel? | Decrypt parallel? | Uses D_K? |
|---|---|---|---|
| CBC | No (needs C_{i-1}) | Yes (all C_i known) | Yes (decrypt only) |
| CTR | Yes (independent) | Yes (independent) | No (E_K both ways) |
Anomaly
Predict first
A student writes this, and it looks reasonable:
A student: 'CBC chains blocks, so decryption must also be strictly sequential — block by block, left to right.'
It is wrong. Say what breaks — and say it before you turn the page.
Correct: Encryption waits because C_{i-1} doesn't exist yet.
A student: when can CBC blocks be processed in parallel?
Why: Encryption waits because C_{i-1} doesn't exist yet. But on decryption every C_i is already in hand, so the wait disappears.
Trap
A student: 'CBC chains blocks, so decryption must also be strictly sequential — block by block, left to right.'
Assume the decryption dependency mirrors the encryption dependency
Why: Wrong. Encryption waits because C_{i-1} doesn't exist yet. But on decryption every C_i is already in hand, so the wait disappears.
A student: when can CBC blocks be processed in parallel?
CBC ENCRYPTION is sequential; CBC DECRYPTION parallelizes because all ciphertext is available up front
Why: §6.7: P_i = D_K(C_i) ⊕ C_{i-1} references only known ciphertext blocks, so every P_i can be computed simultaneously on separate cores.
Two truths and a lie
Sort into buckets
Some of these hold up and some are the exact mistakes this lesson is built to prevent. Sort them.
Ranking
Put in order
These are the steps of Block cipher → secure scheme, the recipe, scrambled. Put them back in order before the next slide shows you.
Why: This is the order the recipe itself gives. Recalling the sequence without the slide in front of you is the difference between recognising the method and being able to run it — most of what goes wrong in practice is a step done out of turn.
Pattern
Edge cases
Discussion prompt
Block cipher → secure scheme, the recipe works on the cases you have just seen. Push it to the edge: what is the most degenerate input it still handles — empty, zero, one item, everything equal — and what is the first case where it stops being true? Name the case, not just "it breaks".
Hint: Try the smallest legal input, then the largest, then the one where two things collide. Methods are specified at their edges; the middle takes care of itself.
Answer:
Elimination
Eliminate the wrong options
Why is the image structure still visible, and what's the correct fix?
3 of these 4 are wrong. Strike them one at a time, and say what rules each one out before you strike the next. The survivor is the answer.
Survives elimination: A
Why: §6.6: encrypting each block independently is ECB mode. Because a block cipher is deterministic, equal plaintext blocks always produce equal ciphertext blocks, so the repeated solid-color regions of the image survive as repeated ciphertext — the 'ECB penguin.' The leak is structural and independent of key strength. The fix is a randomized mode (CBC or CTR) that injects a fresh IV/nonce so equal blocks no longer encrypt to equal ciphertext.
Check
A team encrypts each block of a bitmap image independently with AES-256 and a strong key, and is surprised the penguin's outline is still visible in the ciphertext.
Check your understanding
Why is the image structure still visible, and what's the correct fix?
Answer: A
Why: §6.6: encrypting each block independently is ECB mode. Because a block cipher is deterministic, equal plaintext blocks always produce equal ciphertext blocks, so the repeated solid-color regions of the image survive as repeated ciphertext — the 'ECB penguin.' The leak is structural and independent of key strength. The fix is a randomized mode (CBC or CTR) that injects a fresh IV/nonce so equal blocks no longer encrypt to equal ciphertext.
Concept
Concept
Concept
Connect it up
Draw it
One page, no notation unless you need it: draw how these connect — A Keyed Permutation · Strong, But Not Enough · The Penguin Problem · The Two We Keep · Who Can Run In Parallel?. Put an arrow wherever one of them is what makes another possible, and label the arrow with why.
Recap
You can now define a block cipher as a keyed permutation, explain why AES alone is a PRP but not IND-CPA, show why ECB leaks structure, trace CBC and CTR encryption and decryption, and predict which modes parallelize.
| Idea | § | The one-line version |
|---|---|---|
| Block cipher | 6.4 | Keyed, deterministic permutation on n-bit blocks; D_K = E_K^{-1} |
| AES | 6.4 | n = 128, k = 128/192/256; Daemen & Rijmen, NIST winner |
| Not IND-CPA | 6.5 | Deterministic ⇒ equal plaintexts leak — same break as OTP reuse |
| PRP | 6.5 | Indistinguishable from a random permutation; best attack = 2^128 brute force |
| ECB | 6.6 | C_i = E_K(M_i); equal blocks ⇒ equal ciphertexts (penguin) |
| CBC | 6.6 | C_i = E_K(P_i ⊕ C_{i-1}), random IV; decrypt with D_K |
| CTR | 6.6 | C_i = M_i ⊕ E_K(IV ‖ i); E_K both ways (a one-time pad) |
| Parallelism | 6.7 | CTR both ways; CBC decrypt only; CBC encrypt is sequential |
Want this taught 1-on-1? Alexander tutors Computer Security — $55/session, free consultation.