Chapter 1 of Trappe & Washington: the Alice-Bob-Eve scenario, Eve's four goals, the four attack models, Kerckhoffs's principle, and the split between symmetric and public key cryptography — with RSA, ElGamal, NTRU and McEliece each introduced through the hard problem it rests on. Closes on the chapter's central argument, that key length bounds brute force and nothing else.
Subject: Cryptography · 61 slides · diagram-first lesson
Open the interactive version of this deck
Title
Cryptography · Chapter 1
The players, the four attack models, and why key length is not security
Objectives
This chapter sets the vocabulary that the next twenty-four use without comment. It is short, and almost every sentence in it is load-bearing.
Figure (svg): Alice encrypts a plaintext into ciphertext with a key, sends it over a channel, and Bob decrypts it with the same key while Eve watches the channel.
Warm-up
Before any mathematics: a supplier emails you a bank account number for an invoice. You encrypt the reply.
Discussion prompt
Encryption stops an eavesdropper reading the number. Name two attacks it does nothing about.
Hint: Think about who sent the original email, and about whether the number arrived intact.
Answer:
The email might not be from the supplier. Encryption protects a message in transit; it says nothing about who composed it. This is authentication, and invoice-redirection fraud is exactly this attack, run at scale.
The number might have been altered. A ciphertext can be corrupted in flight, and many ciphers will decrypt corrupted input into corrupted plaintext without complaint. This is data integrity.
Both are on the list of four objectives at the end of this chapter, and neither is solved by encryption. Holding on to that distinction is most of what Chapter 1 is for.
Section
Section 1.1 · pp. 2-8
Concept
Two parties want to communicate. Convention names them Alice and Bob, and names the adversary Eve — as in eavesdropper. The names are not whimsy: they make protocol descriptions with three or four participants readable.
The security question is never 'is the channel safe'. It is assumed unsafe. The question is what Eve can do with what she sees.
Figure (svg): Alice encrypts a plaintext into ciphertext with a key, sends it over a channel, and Bob decrypts it with the same key while Eve watches the channel.
Notation
Every chapter from here writes encryption in this form. It is worth two minutes now.
Annotate
On: \( c = E_K(m), \qquad m = D_K(c) \)
Correctness says the system works. Security says nothing else works. Never let the first be mistaken for the second.
Fill the middle
Before any security property, a cipher has to be usable. Complete the two conditions.
Fill in the blanks
D_K\bigl(E_K(m)\bigr) = m \qquad \textone-to-one E_K \text___ ___
Why: Decryption must undo encryption on every message, and that forces encryption to be injective: if two plaintexts shared a ciphertext, no decryption function could tell them apart. Chapter 2 has a concrete failure of exactly this — the affine map 13x + 4 sends both input and alter to ERRER, which makes it not a weak cipher but not a cipher at all. Correctness is a much weaker demand than security, and it is worth checking first because it is the one you can check.
Invariant
The scenario has five moving parts. Step through them once and watch what Eve holds at each moment.
Step through it
At which step does the system's security actually get tested?
Only step four. Everything before it happens inside a trusted endpoint, which is why endpoint compromise is outside cryptography's promise entirely.
Ranking
Eve is not a single kind of attacker. The book lists four things she might be trying to do.
Put in order
Why: Reading one message costs one message. Finding the key costs every message under that key, past and future — which is why key compromise is the event security engineering is organised around. But corruption and impersonation are worse still, because they turn a passive listener into an active participant: Bob now acts on Eve's instructions believing they are Alice's. Confidentiality is the goal that gets the attention and the least damaging one to lose.
Figure (svg): Eve's four goals arranged by how much damage each one does, from reading one message up to impersonating Alice.
Intuition
Almost every construction in this book is built from a function that is easy to compute and hard to invert. It is worth naming the idea before meeting six instances of it.
One-way function — A function f that is cheap to evaluate but for which recovering x from f(x) is computationally infeasible. No function has ever been proved one-way — their existence would settle deep open problems in complexity theory — so every use of one is a well-tested assumption, not a theorem.
Multiplying two 300-digit primes takes microseconds. Factoring the product is the obstacle RSA is built on. Raising g to a power mod p is cheap by repeated squaring; recovering the exponent is the discrete logarithm problem. The pattern is the same both times.
This is also where the honesty of the subject lives. When a chapter says a system is secure, it means: secure provided this particular inversion stays hard, and that proviso is doing real work.
Figure (svg): A wide arrow going forwards labelled cheap, and a thin blocked arrow coming back labelled infeasible.
Concept
An attack model says what Eve has, not how clever she is. The book lists four, and they form a ladder — each gives Eve everything the one below it gives, and more.
A cipher that survives model 4 survives all of them. Modern security definitions are stated against the strongest model available for exactly this reason.
Figure (svg): The four attack models as an escalating ladder: ciphertext only, known plaintext, chosen plaintext, chosen ciphertext.
Prediction
Ciphertext-only is the most likely situation in practice. Chosen-ciphertext is the least likely.
Predict first
Which model should a cipher be designed to resist?
Correct: The strongest one, chosen ciphertext, even though it is unlikely
This is the same reasoning as designing a bridge for the worst load rather than the average one. The cost of the stronger assumption is paid once; the cost of the weaker one is paid at every future integration.
It is also why Chapter 4 goes to the trouble of defining indistinguishability rather than stopping at 'Eve cannot read it'.
Why: Security is a claim about all futures, not the expected one. A deployment's attack model is not fixed: a cipher used inside a protocol you have not designed yet, on a server that reports decryption errors, is suddenly in the chosen-ciphertext model without anybody deciding so. Designing against the strongest model costs little and removes the need to re-argue security every time the cipher is reused.
Elimination
A web server decrypts whatever you send it and returns a different error message when the padding is malformed than when it is merely wrong.
Eliminate the wrong options
Which model has the attacker been handed?
Survives elimination: c
Why: Any oracle that reveals something about the decryption of an attacker-chosen ciphertext puts the system in the chosen-ciphertext model, even when the oracle is only a one-bit difference in an error message. This is not hypothetical: padding-oracle attacks on CBC mode recover full plaintext from exactly this leak, which is why Chapter 6 treats modes of operation as a security question rather than a formatting one. It is also the concrete reason to design against the strongest model — nobody deploying that server thought they were building a decryption oracle.
Concept
Machines get captured. People defect. Software gets disassembled. The book's own list of ways an adversary learns your algorithm is short and entirely mundane.
So the rule is: the security of the system must rest on the key, and never on the obscurity of the algorithm. We always assume Eve knows exactly which algorithm is in use.
There is a historical progression hiding in this, and it is one of the nicer observations in the chapter. Early cryptography kept the method secret. Symmetric cryptography publishes the method and keeps the key secret. Public key cryptography publishes the method and the encryption key, and keeps secret only a decryption key that everyone knows how to look for.
Cryptography got stronger as it gave the adversary more information. That is the paradox worth carrying out of this chapter.
Figure (svg): Three eras of cryptography, each publishing more than the last: secret method, then public method with secret key, then public method and public encryption key.
Counterexample
A vendor tells you their cipher is secure because the algorithm is proprietary and has never been published.
Discussion prompt
Give two independent reasons to distrust that claim — one about the adversary, one about you.
Hint: Ask what happens the day the algorithm leaks, and ask how the claim could ever have been checked.
Answer:
About the adversary: obscurity is not a property you control. The algorithm ships in the product, so anyone with the product and a disassembler has it. Secrecy that any customer can undo is not secrecy, and the day it breaks, every deployment breaks at once and none of them can be fixed by changing a key.
About you: an unpublished algorithm has not been analysed. The only evidence that a cipher is strong is that competent people tried hard to break it and failed, in public. A proprietary cipher has no such evidence, so 'we found no weakness' means only that the vendor found none.
The contrast is AES, which was chosen through an open five-year competition with the explicit goal of letting the world attack the candidates. Chapter 8 covers what that process produced.
The practical form of the principle: a system should survive its own source code being published.
Section
Section 1.1.2 · pp. 4-6
Two truths and a lie
Two of these are misstatements that sound right. One is the principle.
Eliminate the wrong options
Which statement is Kerckhoffs's principle?
Survives elimination: a
Why: The principle is a statement about dependency: it forbids security from resting on the secrecy of the algorithm, and requires the key to carry all of it. That is why (b) and (c) are near misses rather than paraphrases — one converts a constraint into an obligation, the other into an absolute. The practical test is the one from the previous slide: would the system survive its own source code being published?
Concept
In a symmetric system Alice and Bob both hold the key — either literally the same key, or two keys from which each is easily computed. Every cipher before 1970 is symmetric, and so are DES (Chapter 7) and AES (Chapter 8), which are the workhorses of everything deployed today.
\[ c = E_K(m), \qquad m = D_K(c), \qquad \text{same } K \]
Symmetric cryptography is fast — several orders of magnitude faster than public key methods for the same volume of data. Its problem is not speed but key distribution: before Alice and Bob can use it, they must already share a secret.
With n people who all want to talk to each other, that is n(n−1)/2 keys. At n = 1000 it is 499 500 keys to create, distribute and protect. This does not scale, and the whole of public key cryptography exists to answer it.
Figure (svg): A network of six people needing a shared key on every pair, showing fifteen separate keys.
Worked example
The scaling problem deserves an actual calculation, because the number is the argument.
Each pair of people needs its own shared key
Why: If two pairs shared a key, either party could read the other pair's traffic, so a distinct key per pair is forced.
With n people, count the pairs: each of the n people has n − 1 partners
Why: That counts n(n − 1) ordered pairs.
Each pair was counted twice — Alice-Bob and Bob-Alice are the same key — so divide by 2
Why: Giving n(n − 1)/2 keys.
\[ n = 1000 \;\Longrightarrow\; \frac{1000 \times 999}{2} = 499\,500 \text{ keys} \]
Now add one person: the new arrival needs a key with each of the existing 1000
Why: Growth is linear per person but quadratic overall, and every one of those keys must be generated, delivered securely, stored securely and revoked on compromise.
Verify: compare with public key: 1000 people need 1000 key pairs, and only the public halves are distributed
Why: Linear instead of quadratic, and nothing secret has to travel. That is the whole argument for public key cryptography in one line.
Figure (svg): Two curves: the quadratic growth of symmetric key counts against the linear growth of public key pairs.
Concept
Introduced in the 1970s, and the book calls it a revolution without exaggeration. The encryption key is made public. Anyone may encrypt to Bob. Only Bob can decrypt, because finding the decryption key from the public one is computationally infeasible.
The book's non-mathematical version is worth memorising, because it makes the asymmetry obvious: Bob sends Alice a box and an open padlock. Alice puts her message in the box, snaps Bob's padlock shut, and sends it back. Only Bob has the key. Alice never had to learn a secret, and nothing secret ever travelled.
Note what the analogy also shows. Eve could intercept the first transmission and substitute her padlock. Alice would lock her message with it, and Eve would open it. Public key cryptography does not solve authentication by itself — it makes it urgent. Chapter 15 is largely about this.
Figure (svg): The padlock analogy for public key cryptography: Bob sends an open padlock, Alice locks her message in the box, only Bob's key opens it.
Socratic
In a symmetric system, Eve fails because she lacks information — she does not have the key. In a public key system she has the encryption key and the algorithm.
Discussion prompt
So what is left to stop her? And what kind of guarantee is that?
Hint: Compare 'Eve cannot know this' with 'Eve cannot compute this in reasonable time'.
Answer:
Nothing is hidden from her except an answer she could in principle compute. Bob's private key is determined by his public key; it is not unknown, only expensive to find.
So the guarantee changes kind. Symmetric security can be information-theoretic — Chapter 4 proves the one-time pad secure against an adversary with unlimited computing power. Public key security is always computational: it holds only as long as a particular problem stays hard.
That is a weaker guarantee, and it is contingent on the state of the art. The book's own warning is blunt: DES withstood twenty years of scrutiny and then fell to a purpose-built parallel machine, and quantum computing research is under way that could change the terrain again — Chapter 25 shows exactly how Shor's algorithm dismantles the factoring assumption.
The honest summary: public key cryptography is a bet that certain problems are hard, and the bet has to be re-examined as the world changes.
Break the constraint
Bob sends Alice an open padlock; Alice locks her message with it. The analogy is good, and it has one hole the book points out immediately.
Discussion prompt
Describe the attack Eve mounts on the analogy, and say what it corresponds to in the real system.
Hint: Eve is on the channel for the first transmission too, not just the second.
Answer:
Eve intercepts the padlock and substitutes her own. Alice locks the box with Eve's padlock, believing it is Bob's. Eve intercepts the returning box, opens it with her key, reads the message, then re-locks it with Bob's real padlock and forwards it. Neither Alice nor Bob notices anything.
In the real system this is the intruder-in-the-middle attack, and it is the opening subject of Chapter 15. Eve substitutes her public key for Bob's.
The crucial point: public key cryptography does not authenticate the public key. Encrypting to a public key proves only that whoever holds the matching private key can read it — and says nothing about who that is.
So a public key system is incomplete until there is some way to know a public key really belongs to Bob. That gap is what certificates, PKI and the whole X.509 apparatus of Sections 15.4 and 15.5 exist to fill, and it is where most real-world failures happen.
Concept
The most widely deployed public key system, and the subject of Chapter 9. Its public key contains a number n that is the product of two large secret primes.
\[ n = pq, \qquad \text{public: } (n, e), \qquad \text{private: } d \]
Anyone can encrypt with (n, e). Recovering d requires knowing p and q, which requires factoring n — and no efficient factoring algorithm is known for numbers of the sizes used, around 600 digits.
The scale argument from later in this chapter applies here in its sharpest form: trial division would need to test roughly 1.4 × 10²⁹⁷ primes below 10³⁰⁰, and the universe contains fewer than 10⁹⁰ electrons. Real factoring uses far better algorithms — but even those fall short, which is the whole basis of the system.
Figure (svg): Four public key systems, each resting on a different hard problem: RSA on factoring, ElGamal on discrete logs, NTRU on lattices, McEliece on decoding.
Concept
Covered in Chapter 10. Instead of factoring, ElGamal rests on the difficulty of the discrete logarithm problem: given g and gˣ mod p, recover x.
\[ \text{given } g, \; p, \; g^{x} \bmod p \quad \longrightarrow \quad \text{find } x \]
Raising g to a power is cheap — modular exponentiation by repeated squaring, which Section 3.5 covers. Going backwards is not. That gap between a fast direction and a slow one is the shape of every public key system in this book.
Diffie-Hellman key exchange rests on the same problem, and so does the Digital Signature Algorithm in Chapter 13. The elliptic-curve versions of Chapter 21 are this same problem in a different group, which is why they can use much shorter keys for the same security.
Figure (svg): A one-way street: exponentiation is fast in one direction, and the discrete logarithm going back is not known to be.
Concept
Chapter 23. NTRU's hard problem is finding a short vector in a lattice — a grid of points generated by a basis. Given a badly chosen basis of very long vectors, finding the short ones is hard.
This matters for a reason the other two do not share: Shor's algorithm (Chapter 25) breaks both factoring and discrete logarithms on a quantum computer, and it does not break lattice problems. Lattice systems are therefore leading candidates for post-quantum cryptography, which is why Section 23.6 exists.
The lesson from having four different hard problems is diversification. A cryptographic system tied to one assumption fails completely when that assumption fails, and the assumptions here are genuinely independent of one another.
Figure (svg): A lattice drawn with a good short basis and a bad long basis generating the same grid of points.
Concept
Chapter 24. The McEliece system uses an error-correcting code whose structure the owner knows and nobody else does. Encryption adds deliberate errors; decryption removes them using the hidden structure.
Decoding a random linear code is a known hard problem. Decoding a specific structured code — a Goppa code, in McEliece's case — is easy if you know the structure. The public key is the code disguised so that it looks random.
McEliece dates from 1978, the same era as RSA, and has never been broken. Its drawback is practical rather than mathematical: the public keys are very large. Like NTRU, it is a post-quantum candidate, because Shor's algorithm gives no help against decoding.
Figure (svg): A codeword with deliberate errors added by the encrypter, and the private structure that removes them.
Hypothesis
Public key operations are several orders of magnitude more expensive per byte than symmetric ones.
Predict first
A developer encrypts a 1 GB backup directly with RSA instead of using a hybrid scheme. What is the first thing that goes wrong?
Correct: It will not work at all — RSA cannot encrypt data longer than its modulus
This is why the book's rule of thumb is stated so flatly: public key methods should not be used for encrypting large quantities of data.
Every HTTPS connection follows the hybrid pattern — public key to agree a session key, then a symmetric cipher for the traffic.
Why: Textbook RSA encrypts a number smaller than the modulus n — a couple of hundred bytes at typical key sizes. A gigabyte simply does not fit, so the scheme must be applied block by block, and applying it deterministically block by block reproduces every weakness of ECB mode from Chapter 6 on top of being thousands of times slower. The correct answer is not 'slow' but 'the wrong tool': RSA's job is to move a short key, and the hybrid construction exists precisely because of this limit.
Figure (svg): A hybrid scheme: public key encryption carries a short symmetric key, and the symmetric cipher carries the bulk of the data.
Matching
The single most useful thing to carry out of this chapter is which bet each system makes.
Match the pairs
Why: RSA rests on factoring (Chapter 9), ElGamal on discrete logarithms (Chapter 10), NTRU on lattice problems (Chapter 23), and McEliece on the difficulty of decoding a random-looking linear code (Chapter 24). The first two fall to Shor's algorithm on a quantum computer; the last two, as far as is known, do not — which is exactly why the last two are still being actively developed forty years on.
Figure (svg): Four public key systems, each resting on a different hard problem: RSA on factoring, ElGamal on discrete logs, NTRU on lattices, McEliece on decoding.
Trade off
Public key methods solve key distribution outright. Fill in what they cost.
Comparison matrix
| Property | Symmetric key | Public key |
|---|---|---|
| Speed on bulk data | fast | several orders of magnitude slower |
| Keys needed for n parties | n(n−1)/2 | n key pairs |
| Prior shared secret required? | yes — this is the whole problem | no |
| Non-repudiation | impossible | achievable, via signatures |
| Typical use | the message itself | small data: keys and signatures |
So real systems use both: public key to move a session key, symmetric to move the data. That hybrid is what TLS does on every HTTPS connection.
Figure (svg): A hybrid scheme: public key encryption carries a short symmetric key, and the symmetric cipher carries the bulk of the data.
Explain it
You have to explain to a non-technical colleague why it is safe to publish an encryption key.
Discussion prompt
Give the explanation, and then say honestly what your analogy leaves out.
Hint: The padlock does most of the work. The honesty is in what the padlock cannot show.
Answer:
The explanation. A padlock and its key do different jobs: anyone can snap a padlock shut, only the key opens it. Bob hands out open padlocks freely and keeps the one key. Anyone can lock a message to Bob; only Bob can read it. Nothing secret ever has to travel.
What it leaves out, first: in the analogy Bob's key is physically separate from the padlock. In the real system the private key is mathematically determined by the public one — it is not unknown, only expensive to compute. Security is computational, not absolute, and it can expire.
What it leaves out, second: the analogy assumes Alice got a padlock that is genuinely Bob's. Nothing in the picture guarantees that, and the substitution attack from two slides ago walks straight through the gap.
Being able to give the clean version and name its two limits is a better test of understanding than either one alone.
Concept
Inside symmetric cryptography there are two shapes, and the difference is about how much data the algorithm consumes at once.
A stream cipher takes the data in small pieces — bits or characters — and produces output in matching small pieces. Chapter 5 covers these: LFSR-based generators and RC4.
A block cipher collects a fixed-size block of bits, transforms the whole block at once, and outputs a block. Chapters 6, 7 and 8 are about these, and most of the book's attention goes here. Public key methods such as RSA can also be regarded as block ciphers.
The consequence is that a block cipher needs a rule for messages that are not exactly one block long — and choosing that rule badly is a real vulnerability, not a formality. That is Chapter 6's modes of operation.
Figure (svg): A stream cipher consuming one symbol at a time next to a block cipher consuming a fixed-size block at once.
Comparison
Fill the blanks. The differences are practical, and each one becomes a chapter later.
Comparison matrix
| Property | Stream cipher | Block cipher |
|---|---|---|
| Unit consumed | a bit or a character | a fixed-size block |
| Needs padding? | no — output length matches input | yes, unless the message is a multiple of the block size |
| Needs a mode of operation? | no | yes — Chapter 6 |
| Effect of one corrupted bit | corrupts exactly that bit | corrupts the whole block, and possibly the next |
| Covered in | Chapter 5 — LFSRs, RC4 | Chapters 6-8 — Hill, DES, AES |
The fourth row is the one people forget, and it decides which cipher suits a noisy channel.
Definition probe
The book draws a historical distinction that is still worth keeping straight, because the words are used loosely everywhere else.
Sort into buckets
Sort each example into the right category.
Section
Section 1.1.3 · pp. 6-8
Translation
The vocabulary of this chapter is compact, and every term is used without explanation from Chapter 2 onwards.
Match the pairs
Why: Each of these is a phrase you will meet in the next twenty-four chapters with no re-introduction. The one worth extra attention is non-repudiation, because it is easy to blur into authentication: authentication convinces the recipient, non-repudiation convinces a third party, and a shared symmetric key gives you the first while making the second impossible.
Concept
The most obvious attack is to try every key and see which produces a meaningful decryption. This is a brute force attack, and key length is exactly the measure of how long it takes.
\[ \text{16-bit key} \Rightarrow 2^{16} = 65\,536, \qquad \text{DES's 56-bit key} \Rightarrow 2^{56} \approx 7.2 \times 10^{16} \]
Brute force should be the last resort. A cryptanalyst always hopes for something faster, and this book is largely a catalogue of faster things: frequency analysis for the substitution and Vigenère ciphers, birthday attacks for discrete logarithms, differential cryptanalysis for DES.
Figure (svg): A comparison of key spaces: a 16-bit key, DES's 56-bit key, a substitution cipher's 26 factorial, and AES's 128 bits.
Worked example
The book's own arithmetic, and it is worth doing once by hand so the numbers stop being abstract.
Suppose there are 10³⁰ possibilities to try
Why: This is around a 100-bit key, since 2¹⁰⁰ ≈ 1.3 × 10³⁰.
Suppose the machine performs 10⁹ such trials per second
Why: A billion per second is generous for a full trial decryption, and generous is the right direction for a security argument.
There are about 3 × 10⁷ seconds in a year
Why: Worth memorising: π × 10⁷ is a standard approximation.
\[ \frac{10^{30}}{10^{9} \times 3 \times 10^{7}} \approx 3 \times 10^{13} \text{ years} \]
Verify: compare with the age of the universe, about 1.4 × 10¹⁰ years
Why: The search takes roughly two thousand times the age of the universe, so 100 bits closes off brute force by an enormous margin. That margin is why key sizes stopped growing once they reached 128 bits.
Figure (svg): The book's scale argument: 10 to the 30 operations at a billion per second takes 3 times 10 to the 13 years, longer than the age of the universe.
Cost model
Every feasibility argument in this book has this shape. Learn to read the parts and you can sanity-check any security claim in a minute.
Annotate
On: \( T = \frac{N}{R \times S} \)
Note which way the asymmetry runs: a huge T proves almost nothing, and a small T proves the system dead.
Trap
The trap. Two ciphers both use 128-bit keys. Both therefore have 2¹²⁸ ≈ 3.4 × 10³⁸ possible keys, which is unsearchable. So the two ciphers are equally secure, and comparing key sizes is a fair way to compare security.
This is the reasoning behind every 'military-grade 256-bit encryption' claim you will ever read on a product page.
Why it fails. The book's own counterexample: the substitution cipher has 26! ≈ 4 × 10²⁶ keys — nearly ten orders of magnitude more than DES's 7.2 × 10¹⁶ — and it is one of the easiest systems in the book to break, while DES took a purpose-built parallel machine over a day.
The difference is what the attack uses. Against the substitution cipher, Eve exploits the structure of the language and never enumerates a key at all. Against DES, the best general attack really is exhaustion — so for DES, and only for DES, key length is the honest measure.
Some algorithms simply do not make efficient use of their key bits. A key space is a set of possible keys; it says nothing about whether the map from key to behaviour is any good.
The rule to carry away: key length is a necessary condition and never a sufficient one. A cipher is as strong as the best attack against it, and the key count only bounds one attack out of all of them.
Estimation
The substitution cipher has 26! keys; DES has 2⁵⁶.
Predict first
Roughly how many times larger is the substitution cipher's key space?
Correct: About 10 billion times
It also puts a number on how much a structural attack is worth. Frequency analysis does not shave a factor off the search; it replaces the search entirely.
Chapter 2 carries this out in full on all seven of its ciphers.
Why: 26! ≈ 4 × 10²⁶ and 2⁵⁶ ≈ 7.2 × 10¹⁶, so the ratio is about 5.6 × 10⁹ — roughly ten billion. And the cipher with ten billion times as many keys is the one a person can break on paper. Holding both numbers at once is the point of the exercise: it makes the key-length fallacy impossible to fall for again.
Anomaly
A messaging app uses AES-256 correctly, with keys drawn from a good random source. Every message is encrypted before it leaves the device. An auditor reports that an eavesdropper can nevertheless learn who is talking to whom, when, and roughly how much they said.
Predict first
Is the auditor describing a flaw in the cipher?
Correct: No — the cipher is fine; the leak is metadata, which encryption was never going to protect
Chapter 2 has the same lesson at letter granularity: a monoalphabetic cipher hides the letters but not the pattern the letters make, and the pattern is enough.
The general form: a cipher protects the values, not the shape of the values.
Why: Encryption protects message contents. It does not hide the existence of a message, its length, its timing, or its endpoints — and those four together are often as revealing as the text. This is traffic analysis, and it is the reason real systems add padding, cover traffic and mixing on top of encryption. The example matters because it separates two things Chapter 1 is careful to keep apart: the strength of a primitive and the security of a system.
Error analysis
From a product security whitepaper. Three sentences, and each one has a problem.
Annotate
Run it through the four-part template: what is public, what is secret, what Eve can do, what breaks it. The whitepaper answers only the second, and gets that wrong too.
Edge cases
The book warns that an algorithm secure now may not stay secure, and gives DES as the example: twenty years of scrutiny, then a purpose-built parallel computer.
Discussion prompt
What kinds of change can invalidate a security claim, and which of them can you plan for?
Hint: Separate 'the machines got faster' from 'somebody had a better idea'.
Answer:
Faster hardware. Predictable, roughly, and therefore plannable: pick key sizes with decades of margin. This is the cheapest failure to defend against and the one that actually killed DES.
Better algorithms. Not predictable. Factoring got substantially better between RSA's invention and the RSA-129 challenge, and each improvement shortened every RSA key in the world at once.
A change of computational model. Quantum computing is the live case. Shor's algorithm does not make factoring somewhat faster; it makes it easy, which retires RSA and ElGamal together rather than requiring longer keys. Chapter 25 shows the algorithm.
Implementation and protocol failures. The book notes these are the most common cause in practice — the mathematics stands and the deployment leaks. Chapter 14 is a whole chapter of examples, and WEP is the standout: sound primitives, fatal assembly.
So: plan for the first, monitor the second, hedge against the third by keeping independent assumptions alive, and treat the fourth as the most likely thing to go wrong on any given day.
Section
Section 1.2 · pp. 8-9
Real world
Everything in this chapter is in use on every HTTPS connection you make, in the order the chapter introduced it.
Discussion prompt
Walk through what happens when your browser opens a connection to a bank, and name which idea from this chapter each step uses.
Hint: There are four steps, and they map onto certificates, public key, symmetric key, and integrity.
Answer:
1. The server presents a certificate. This is the answer to the padlock-substitution attack: a third party the browser already trusts has vouched that this public key belongs to this domain. Sections 15.4 and 15.5.
2. The browser and server agree a session key, using public key cryptography or Diffie-Hellman. This is the key-establishment problem, and it is solved without any prior shared secret. Chapters 10 and 15.
3. The traffic is encrypted with a symmetric cipher — AES, almost always. This is the hybrid pattern: the expensive method moved a short key, and the fast method carries the gigabytes. Chapter 8.
4. Every record carries an authentication tag, so tampering is detected. Confidentiality alone was never the goal — integrity and authentication ride along. Chapters 11 and 12.
Four steps, four of this chapter's ideas, and the ordering is not accidental: each step is useless without the one before it.
Commit first
A company uses one symmetric key shared across all 40 of its offices, rotated annually.
Predict first
One office is breached in month three. What is the exposure?
Correct: All 40 offices' traffic for the whole year, including the two months already recorded
Two defences follow directly. Segmentation: a key per pair rather than a key for everyone, which is where the n(n−1)/2 problem comes from. Forward secrecy: derive a fresh session key per conversation and destroy it afterwards, so recorded ciphertext stays unreadable even after a later compromise.
Forward secrecy is the modern reason TLS prefers Diffie-Hellman key agreement over encrypting a session key with the server's long-term RSA key.
Why: One key protecting everything means one key compromising everything. The attacker reads all traffic between all offices — and if she recorded ciphertext during months one and two, she can now decrypt that too, because the key was already in use. This is Eve's second goal from earlier in the chapter, and it is why key compromise is treated as a catastrophic rather than a local event.
Concept
Cryptography is not only about encrypting and decrypting. The book names four objectives, and the rest of the volume is organised around them.
Figure (svg): The four security objectives — confidentiality, data integrity, authentication, non-repudiation — with the primitive that provides each.
Discrimination
Almost every real security incident is a failure of exactly one of the four.
Sort into buckets
Sort each failure into the objective it violates.
Missing information
A specification reads, in full: "All customer records shall be encrypted using AES."
Discussion prompt
List what a security reviewer still cannot determine, and say why each gap matters.
Hint: Walk the four-part template — public, secret, adversary, best attack — and see which parts the sentence touches.
Answer:
Which key, and who holds it. One key for all records, or one per customer? Held by the application, or an HSM? A single application-held key means an application compromise is a total compromise — the wager two slides back.
How keys are generated, rotated and destroyed. A 256-bit key from a weak generator has far less than 256 bits of entropy, and no amount of AES fixes that.
Which mode of operation. "AES" alone permits ECB, which leaks equal plaintexts as equal ciphertexts — the failure Chapter 6 opens with, and precisely wrong for a database column.
Whether integrity is protected. Encryption without authentication lets an attacker alter ciphertext; some modes will decrypt the result into plaintext of the attacker's choosing. Confidentiality was specified; integrity was not mentioned.
What the adversary is assumed to be. An outside eavesdropper, a rogue administrator, someone with a stolen backup? Each implies different answers above.
Naming a cipher is the smallest part of specifying encryption, and it is the part these documents usually contain in isolation.
Constraint
You are securing telemetry from ten thousand battery-powered sensors. Each has a tiny processor, sends 20 bytes every minute, and must run for five years on one cell.
Discussion prompt
Which of this chapter's tools do you reach for, and which do you rule out — and on what grounds in each case?
Hint: Cost per byte matters far less than cost per operation here, and the key distribution problem has a shape you get to choose.
Answer:
Rule out per-message public key operations. Several orders of magnitude more computation than symmetric, on a processor with a five-year power budget. The rule of thumb applies with force.
Reach for a symmetric cipher with a per-device key, provisioned at manufacture. The n(n−1)/2 problem does not bite, because the sensors never talk to each other — the topology is a star with one hub, so it is n keys, not n²/2.
Do not skip integrity. A 20-byte telemetry reading is exactly the kind of message an attacker would rather forge than read, so a MAC matters more here than encryption does. This is the chapter's point that confidentiality is only one of four objectives.
Consider public key once, at provisioning, to establish those per-device keys without a factory-floor secret. Paying the expensive operation once in a device's life is very different from paying it every minute.
The general move: the topology and the threat decide the tools. 'Use strong crypto' is not a design.
Explain it to yourself
With a shared key, Bob knows a message came from Alice, because nobody else could have produced a ciphertext that decrypts correctly. So authentication is automatic.
Discussion prompt
Explain why that same reasoning fails to convince a third party — a judge, say — that Alice sent it.
Hint: Ask what else Bob could have done with the key he holds.
Answer:
Because Bob has the same key. Anything Alice could produce, Bob could produce. So a valid ciphertext proves it came from someone holding the key, and there are two such people.
Bob is convinced, because he knows he did not write it. A judge is not, because the judge cannot rule Bob out. Authentication is a claim Bob can verify for himself; non-repudiation is a claim Bob must be able to prove to someone else, and the shared key destroys exactly that.
Public key cryptography breaks the symmetry. Alice signs with a private key only she holds, and anyone can verify with her public key. Now the verifier does not need to be trusted, and Bob cannot have forged it.
This is why Chapter 13 exists as a separate chapter from Chapter 9, and why electronic commerce needed public key cryptography rather than merely wanting it.
Concept
The applications the book previews here, and where each lands:
| Application | The problem | Chapter |
|---|---|---|
| Digital signatures | Tie an identity to a document that is trivially copyable | 13 |
| Identification | Prove who you are without handing over the proof | 7, 19 |
| Key establishment | Agree a shared key over an open channel | 10, 15 |
| Secret sharing | Split a secret so that k of n people can recover it | 17 |
| Security protocols | Assemble primitives into something that survives an active adversary | 15 |
| Digital cash | Spend a token once, anonymously, without a bank in the loop | 16 |
Notice how few of these are 'encrypt a message'. Encryption is the first tool in the box and the smallest part of the job.
Figure (svg): A map of what the rest of the book covers, from digital signatures through key establishment to secret sharing and protocols.
Sorting
The book's structure follows the four objectives. Getting the map straight now makes the rest of the course navigable.
Sort into buckets
Sort each question into the part of the book that answers it.
Scale up
One more pass over the chapter's central quantities, in the order they get large.
Step through it
Which row is out of order if you sort by security rather than by key count?
The third. Sorting by key space puts the substitution cipher near the top; sorting by security puts it at the bottom. That inversion is Chapter 1's thesis in one table.
Pattern
Chapter 1 hands you a template. Every security claim in the following twenty-four chapters has these four parts, and a claim missing any of them is not yet a claim.
Run a product claim through those four and most of them fall apart on the third. That is the practical value of this chapter.
Figure (svg): The four-part template for a security claim: what is public, what is secret, what the adversary can do, and what breaks it.
Check
Work it out before you click.
Check your understanding
A system uses a 256-bit key and its designers say the key space cannot be searched. Which question does this claim leave completely unanswered?
Answer: B
Why: The claim is about the size of the key space, which bounds exactly one attack. The substitution cipher has 26! ≈ 4 × 10²⁶ keys and is broken by frequency analysis without enumerating any of them, so a large key space is entirely consistent with the cipher being trivially breakable. B is the question the claim does not touch, and it is the one that matters.
Check
Think about what each party has to hold.
Check your understanding
Alice and Bob have never met and share no secret. Which is possible?
Answer: A
Why: Solving exactly this problem is what public key cryptography was invented for. Bob publishes an encryption key; Alice uses it to send a session key; from then on they use fast symmetric encryption. The book's padlock analogy captures it: Bob's open padlock can travel in public because it is not the secret.
Check
Read the failure carefully before choosing.
Check your understanding
A signed contract is transmitted encrypted. The recipient later cannot prove to a court who signed it, because both parties held the same key. Which objective failed?
Answer: D
Why: Non-repudiation is the ability to prove authorship to a third party, and a shared key destroys it: anything Alice could produce, Bob could too, so no outside observer can attribute the message. Note that authentication is intact — Bob himself is convinced, because he knows he did not write it. The failure appears only when a third party has to be convinced.
Connect it up
Everything in this chapter is definitions, and definitions stick only if you rebuild them once yourself.
Draw it
On one page: draw the Alice-Bob-Eve channel and label plaintext, ciphertext, both keys, and what Eve sees. Beside it, list Eve's four goals in order of damage and the four attack models in order of strength. Underneath, write the two-column comparison of symmetric and public key — speed, keys needed for n parties, prior secret required, non-repudiation. Finally write the one-sentence version of Kerckhoffs's principle, and the one counterexample that kills the key-length fallacy.
If you can produce that page from memory, Chapter 2's seven ciphers will be seven instances of one story rather than seven things to learn.
Exit ticket
One question. It is the one this chapter exists to install.
Predict first
What is the single most important thing Kerckhoffs's principle tells a system designer to do?
Correct: Design so the system stays secure even if the algorithm is fully published
Why: The principle is that security must rest on the key alone. Machines are captured, code is disassembled, people defect — so any secrecy in the algorithm is temporary, and worse, it cannot be repaired: a leaked algorithm breaks every deployment at once, while a leaked key breaks one and is replaceable. Designing for publication also makes the security claim checkable by people other than its authors, which is the only evidence a cipher is ever going to have.
Recap
A short chapter, and the vocabulary for the whole book.
Chapter 2 next. Seven classical ciphers, each broken. Every break uses the structure of the cipher rather than the size of its key space, so keep the counterexample from this chapter in view the whole way through.
Figure (svg): A comparison of key spaces: a 16-bit key, DES's 56-bit key, a substitution cipher's 26 factorial, and AES's 128 bits.
Want this taught 1-on-1? Alexander tutors Cryptography — $55/session, free consultation.