Chapter 1: Overview of Cryptography and Its Applications

Chapter 1 of Trappe & Washington: the Alice-Bob-Eve scenario, Eve's four goals, the four attack models, Kerckhoffs's principle, and the split between symmetric and public key cryptography — with RSA, ElGamal, NTRU and McEliece each introduced through the hard problem it rests on. Closes on the chapter's central argument, that key length bounds brute force and nothing else.

Subject: Cryptography · 61 slides · diagram-first lesson

Open the interactive version of this deck

What this lesson covers

The lesson, slide by slide

1. Overview of Cryptography

Title

Cryptography · Chapter 1

The players, the four attack models, and why key length is not security

2. What you will be able to do

Objectives

This chapter sets the vocabulary that the next twenty-four use without comment. It is short, and almost every sentence in it is load-bearing.

Figure (svg): Alice encrypts a plaintext into ciphertext with a key, sends it over a channel, and Bob decrypts it with the same key while Eve watches the channel.

The whole subject in one picture: two endpoints Alice and Bob trust, and a channel they do not.

3. What are you actually protecting?

Warm-up

Before any mathematics: a supplier emails you a bank account number for an invoice. You encrypt the reply.

Discussion prompt

Encryption stops an eavesdropper reading the number. Name two attacks it does nothing about.

Hint: Think about who sent the original email, and about whether the number arrived intact.

Answer:

The email might not be from the supplier. Encryption protects a message in transit; it says nothing about who composed it. This is authentication, and invoice-redirection fraud is exactly this attack, run at scale.

The number might have been altered. A ciphertext can be corrupted in flight, and many ciphers will decrypt corrupted input into corrupted plaintext without complaint. This is data integrity.

Both are on the list of four objectives at the end of this chapter, and neither is solved by encryption. Holding on to that distinction is most of what Chapter 1 is for.

4. The Basic Communication Scenario

Section

Section 1.1 · pp. 2-8

5. Alice, Bob, and Eve

Concept

Two parties want to communicate. Convention names them Alice and Bob, and names the adversary Eve — as in eavesdropper. The names are not whimsy: they make protocol descriptions with three or four participants readable.

The security question is never 'is the channel safe'. It is assumed unsafe. The question is what Eve can do with what she sees.

Figure (svg): Alice encrypts a plaintext into ciphertext with a key, sends it over a channel, and Bob decrypts it with the same key while Eve watches the channel.

The whole subject in one picture: two endpoints Alice and Bob trust, and a channel they do not.

6. The notation you will see for the rest of the book

Notation

Every chapter from here writes encryption in this form. It is worth two minutes now.

Annotate

On: \( c = E_K(m), \qquad m = D_K(c) \)

  • The plaintext — the message itself. Lowercase m throughout the book.
  • The ciphertext. What travels on the channel, and the only thing Eve is guaranteed to see.
  • The encryption and decryption algorithms. These are PUBLIC — Kerckhoffs's principle, two slides from here.
  • The key, and the only secret. In a symmetric system the same K appears in both; in a public key system the two differ, and only one of them is secret.
  • Together they say D_K undoes E_K. That is the correctness requirement, and it is separate from — and much easier than — any security requirement.

Correctness says the system works. Security says nothing else works. Never let the first be mistaken for the second.

7. The correctness requirement, written out

Fill the middle

Before any security property, a cipher has to be usable. Complete the two conditions.

Fill in the blanks

D_K\bigl(E_K(m)\bigr) = m \qquad \textone-to-one E_K \text___ ___

Why: Decryption must undo encryption on every message, and that forces encryption to be injective: if two plaintexts shared a ciphertext, no decryption function could tell them apart. Chapter 2 has a concrete failure of exactly this — the affine map 13x + 4 sends both input and alter to ERRER, which makes it not a weak cipher but not a cipher at all. Correctness is a much weaker demand than security, and it is worth checking first because it is the one you can check.

8. Follow one message all the way through

Invariant

The scenario has five moving parts. Step through them once and watch what Eve holds at each moment.

Step through it

At which step does the system's security actually get tested?

  1. Alice has a plaintext. Nothing has moved yet.
  2. Alice applies the key. The key never travels on this channel — how it got to both ends is Chapter 15's problem.
  3. The ciphertext exists. Still nothing has been transmitted.
  4. Transmission. This is the only moment Eve gets anything, and she gets the ciphertext in full.
  5. Bob decrypts. Eve ends holding the ciphertext and the algorithm — and by Kerckhoffs's principle we assume she always had the algorithm.

Only step four. Everything before it happens inside a trusted endpoint, which is why endpoint compromise is outside cryptography's promise entirely.

9. Eve's four goals, from least to most damaging

Ranking

Eve is not a single kind of attacker. The book lists four things she might be trying to do.

Put in order

  1. Read this particular message
  2. Find the key, and so read every message
  3. Corrupt the message so Bob acts on something false
  4. Masquerade as Alice, so Bob believes he is talking to her

Why: Reading one message costs one message. Finding the key costs every message under that key, past and future — which is why key compromise is the event security engineering is organised around. But corruption and impersonation are worse still, because they turn a passive listener into an active participant: Bob now acts on Eve's instructions believing they are Alice's. Confidentiality is the goal that gets the attention and the least damaging one to lose.

Figure (svg): Eve's four goals arranged by how much damage each one does, from reading one message up to impersonating Alice.

Encryption alone answers goal 1. Goals 2, 3 and 4 need integrity, authentication and key management.

10. A one-way street is the raw material

Intuition

Almost every construction in this book is built from a function that is easy to compute and hard to invert. It is worth naming the idea before meeting six instances of it.

One-way function — A function f that is cheap to evaluate but for which recovering x from f(x) is computationally infeasible. No function has ever been proved one-way — their existence would settle deep open problems in complexity theory — so every use of one is a well-tested assumption, not a theorem.

Multiplying two 300-digit primes takes microseconds. Factoring the product is the obstacle RSA is built on. Raising g to a power mod p is cheap by repeated squaring; recovering the exponent is the discrete logarithm problem. The pattern is the same both times.

This is also where the honesty of the subject lives. When a chapter says a system is secure, it means: secure provided this particular inversion stays hard, and that proviso is doing real work.

Figure (svg): A wide arrow going forwards labelled cheap, and a thin blocked arrow coming back labelled infeasible.

The asymmetry between the two directions is the only thing standing between a public key and a private one.

11. The four attack models

Concept

An attack model says what Eve has, not how clever she is. The book lists four, and they form a ladder — each gives Eve everything the one below it gives, and more.

1. Ciphertext only
Eve has ciphertext and nothing else. The weakest model and the most realistic. Everything in Chapter 2 falls here.
2. Known plaintext
Eve has some plaintext together with its ciphertext. She did not choose it — perhaps it is a standard header or a stereotyped opening.
3. Chosen plaintext
Eve gets to pick plaintexts and see their ciphertexts. Realistic whenever she has temporary access to the encrypting machine, or can cause a known message to be sent.
4. Chosen ciphertext
Eve gets to pick ciphertexts and see what they decrypt to. Realistic against a server that decrypts and reports errors — Chapter 6's padding attacks live here.

A cipher that survives model 4 survives all of them. Modern security definitions are stated against the strongest model available for exactly this reason.

Figure (svg): The four attack models as an escalating ladder: ciphertext only, known plaintext, chosen plaintext, chosen ciphertext.

Each rung gives Eve strictly more than the one below it, so a cipher secure against the top rung is secure against all four.

12. Which model is the right one to design against?

Prediction

Ciphertext-only is the most likely situation in practice. Chosen-ciphertext is the least likely.

Predict first

Which model should a cipher be designed to resist?

  • Ciphertext only, because it is what actually happens
  • The strongest one, chosen ciphertext, even though it is unlikely
  • Whichever matches the deployment
  • Known plaintext, as a sensible middle

Correct: The strongest one, chosen ciphertext, even though it is unlikely

This is the same reasoning as designing a bridge for the worst load rather than the average one. The cost of the stronger assumption is paid once; the cost of the weaker one is paid at every future integration.

It is also why Chapter 4 goes to the trouble of defining indistinguishability rather than stopping at 'Eve cannot read it'.

Why: Security is a claim about all futures, not the expected one. A deployment's attack model is not fixed: a cipher used inside a protocol you have not designed yet, on a server that reports decryption errors, is suddenly in the chosen-ciphertext model without anybody deciding so. Designing against the strongest model costs little and removes the need to re-argue security every time the cipher is reused.

13. Name the attack model

Elimination

A web server decrypts whatever you send it and returns a different error message when the padding is malformed than when it is merely wrong.

Eliminate the wrong options

Which model has the attacker been handed?

  • a. Ciphertext only — she is just sending data over the wire
  • b. Known plaintext — the error messages reveal plaintext
  • c. Chosen ciphertext — she picks ciphertexts and learns about their decryptions
  • d. No model applies — this is an implementation bug, not cryptanalysis

Survives elimination: c

Why: Any oracle that reveals something about the decryption of an attacker-chosen ciphertext puts the system in the chosen-ciphertext model, even when the oracle is only a one-bit difference in an error message. This is not hypothetical: padding-oracle attacks on CBC mode recover full plaintext from exactly this leak, which is why Chapter 6 treats modes of operation as a security question rather than a formatting one. It is also the concrete reason to design against the strongest model — nobody deploying that server thought they were building a decryption oracle.

14. Kerckhoffs's principle: assume the algorithm is known

Concept

Machines get captured. People defect. Software gets disassembled. The book's own list of ways an adversary learns your algorithm is short and entirely mundane.

So the rule is: the security of the system must rest on the key, and never on the obscurity of the algorithm. We always assume Eve knows exactly which algorithm is in use.

There is a historical progression hiding in this, and it is one of the nicer observations in the chapter. Early cryptography kept the method secret. Symmetric cryptography publishes the method and keeps the key secret. Public key cryptography publishes the method and the encryption key, and keeps secret only a decryption key that everyone knows how to look for.

Cryptography got stronger as it gave the adversary more information. That is the paradox worth carrying out of this chapter.

Figure (svg): Three eras of cryptography, each publishing more than the last: secret method, then public method with secret key, then public method and public encryption key.

Each era hands the adversary strictly more information than the last, and each is stronger than the last.

15. Test the principle

Counterexample

A vendor tells you their cipher is secure because the algorithm is proprietary and has never been published.

Discussion prompt

Give two independent reasons to distrust that claim — one about the adversary, one about you.

Hint: Ask what happens the day the algorithm leaks, and ask how the claim could ever have been checked.

Answer:

About the adversary: obscurity is not a property you control. The algorithm ships in the product, so anyone with the product and a disassembler has it. Secrecy that any customer can undo is not secrecy, and the day it breaks, every deployment breaks at once and none of them can be fixed by changing a key.

About you: an unpublished algorithm has not been analysed. The only evidence that a cipher is strong is that competent people tried hard to break it and failed, in public. A proprietary cipher has no such evidence, so 'we found no weakness' means only that the vendor found none.

The contrast is AES, which was chosen through an open five-year competition with the explicit goal of letting the world attack the candidates. Chapter 8 covers what that process produced.

The practical form of the principle: a system should survive its own source code being published.

16. Symmetric and Public Key Algorithms

Section

Section 1.1.2 · pp. 4-6

17. Kerckhoffs's principle, correctly stated

Two truths and a lie

Two of these are misstatements that sound right. One is the principle.

Eliminate the wrong options

Which statement is Kerckhoffs's principle?

  • a. The security of the system must rest on the key, not on the obscurity of the algorithm
  • b. The algorithm must be published for the system to be secure
  • c. Hiding the algorithm provides no benefit whatsoever

Survives elimination: a

Why: The principle is a statement about dependency: it forbids security from resting on the secrecy of the algorithm, and requires the key to carry all of it. That is why (b) and (c) are near misses rather than paraphrases — one converts a constraint into an obligation, the other into an absolute. The practical test is the one from the previous slide: would the system survive its own source code being published?

18. Symmetric Key Cryptography: one shared secret

Concept

In a symmetric system Alice and Bob both hold the key — either literally the same key, or two keys from which each is easily computed. Every cipher before 1970 is symmetric, and so are DES (Chapter 7) and AES (Chapter 8), which are the workhorses of everything deployed today.

\[ c = E_K(m), \qquad m = D_K(c), \qquad \text{same } K \]

Symmetric cryptography is fast — several orders of magnitude faster than public key methods for the same volume of data. Its problem is not speed but key distribution: before Alice and Bob can use it, they must already share a secret.

With n people who all want to talk to each other, that is n(n−1)/2 keys. At n = 1000 it is 499 500 keys to create, distribute and protect. This does not scale, and the whole of public key cryptography exists to answer it.

Figure (svg): A network of six people needing a shared key on every pair, showing fifteen separate keys.

Every edge is a secret that has to be created, delivered and stored. The count grows as the square of the group.

19. Counting the keys a symmetric network needs

Worked example

The scaling problem deserves an actual calculation, because the number is the argument.

Each pair of people needs its own shared key

Why: If two pairs shared a key, either party could read the other pair's traffic, so a distinct key per pair is forced.

With n people, count the pairs: each of the n people has n − 1 partners

Why: That counts n(n − 1) ordered pairs.

Each pair was counted twice — Alice-Bob and Bob-Alice are the same key — so divide by 2

Why: Giving n(n − 1)/2 keys.

\[ n = 1000 \;\Longrightarrow\; \frac{1000 \times 999}{2} = 499\,500 \text{ keys} \]

Now add one person: the new arrival needs a key with each of the existing 1000

Why: Growth is linear per person but quadratic overall, and every one of those keys must be generated, delivered securely, stored securely and revoked on compromise.

Verify: compare with public key: 1000 people need 1000 key pairs, and only the public halves are distributed

Why: Linear instead of quadratic, and nothing secret has to travel. That is the whole argument for public key cryptography in one line.

Figure (svg): Two curves: the quadratic growth of symmetric key counts against the linear growth of public key pairs.

At 100 people it is 4950 shared secrets against 100 key pairs, and the gap only widens.

20. Public Key Cryptography: publish the lock, keep the key

Concept

Introduced in the 1970s, and the book calls it a revolution without exaggeration. The encryption key is made public. Anyone may encrypt to Bob. Only Bob can decrypt, because finding the decryption key from the public one is computationally infeasible.

The book's non-mathematical version is worth memorising, because it makes the asymmetry obvious: Bob sends Alice a box and an open padlock. Alice puts her message in the box, snaps Bob's padlock shut, and sends it back. Only Bob has the key. Alice never had to learn a secret, and nothing secret ever travelled.

Note what the analogy also shows. Eve could intercept the first transmission and substitute her padlock. Alice would lock her message with it, and Eve would open it. Public key cryptography does not solve authentication by itself — it makes it urgent. Chapter 15 is largely about this.

Figure (svg): The padlock analogy for public key cryptography: Bob sends an open padlock, Alice locks her message in the box, only Bob's key opens it.

Alice never learns anything Bob has to keep secret — she only needs the lock, and the lock is public.

21. Where does the security actually come from?

Socratic

In a symmetric system, Eve fails because she lacks information — she does not have the key. In a public key system she has the encryption key and the algorithm.

Discussion prompt

So what is left to stop her? And what kind of guarantee is that?

Hint: Compare 'Eve cannot know this' with 'Eve cannot compute this in reasonable time'.

Answer:

Nothing is hidden from her except an answer she could in principle compute. Bob's private key is determined by his public key; it is not unknown, only expensive to find.

So the guarantee changes kind. Symmetric security can be information-theoretic — Chapter 4 proves the one-time pad secure against an adversary with unlimited computing power. Public key security is always computational: it holds only as long as a particular problem stays hard.

That is a weaker guarantee, and it is contingent on the state of the art. The book's own warning is blunt: DES withstood twenty years of scrutiny and then fell to a purpose-built parallel machine, and quantum computing research is under way that could change the terrain again — Chapter 25 shows exactly how Shor's algorithm dismantles the factoring assumption.

The honest summary: public key cryptography is a bet that certain problems are hard, and the bet has to be re-examined as the world changes.

22. Break the padlock analogy

Break the constraint

Bob sends Alice an open padlock; Alice locks her message with it. The analogy is good, and it has one hole the book points out immediately.

Discussion prompt

Describe the attack Eve mounts on the analogy, and say what it corresponds to in the real system.

Hint: Eve is on the channel for the first transmission too, not just the second.

Answer:

Eve intercepts the padlock and substitutes her own. Alice locks the box with Eve's padlock, believing it is Bob's. Eve intercepts the returning box, opens it with her key, reads the message, then re-locks it with Bob's real padlock and forwards it. Neither Alice nor Bob notices anything.

In the real system this is the intruder-in-the-middle attack, and it is the opening subject of Chapter 15. Eve substitutes her public key for Bob's.

The crucial point: public key cryptography does not authenticate the public key. Encrypting to a public key proves only that whoever holds the matching private key can read it — and says nothing about who that is.

So a public key system is incomplete until there is some way to know a public key really belongs to Bob. That gap is what certificates, PKI and the whole X.509 apparatus of Sections 15.4 and 15.5 exist to fill, and it is where most real-world failures happen.

23. RSA: the bet on factoring

Concept

The most widely deployed public key system, and the subject of Chapter 9. Its public key contains a number n that is the product of two large secret primes.

\[ n = pq, \qquad \text{public: } (n, e), \qquad \text{private: } d \]

Anyone can encrypt with (n, e). Recovering d requires knowing p and q, which requires factoring n — and no efficient factoring algorithm is known for numbers of the sizes used, around 600 digits.

The scale argument from later in this chapter applies here in its sharpest form: trial division would need to test roughly 1.4 × 10²⁹⁷ primes below 10³⁰⁰, and the universe contains fewer than 10⁹⁰ electrons. Real factoring uses far better algorithms — but even those fall short, which is the whole basis of the system.

Figure (svg): Four public key systems, each resting on a different hard problem: RSA on factoring, ElGamal on discrete logs, NTRU on lattices, McEliece on decoding.

One idea, four independent bets. If factoring falls, RSA falls — and the other three do not.

24. ElGamal: the bet on discrete logarithms

Concept

Covered in Chapter 10. Instead of factoring, ElGamal rests on the difficulty of the discrete logarithm problem: given g and gˣ mod p, recover x.

\[ \text{given } g, \; p, \; g^{x} \bmod p \quad \longrightarrow \quad \text{find } x \]

Raising g to a power is cheap — modular exponentiation by repeated squaring, which Section 3.5 covers. Going backwards is not. That gap between a fast direction and a slow one is the shape of every public key system in this book.

Diffie-Hellman key exchange rests on the same problem, and so does the Digital Signature Algorithm in Chapter 13. The elliptic-curve versions of Chapter 21 are this same problem in a different group, which is why they can use much shorter keys for the same security.

Figure (svg): A one-way street: exponentiation is fast in one direction, and the discrete logarithm going back is not known to be.

A function easy to compute and believed hard to invert is called a one-way function; it is the raw material of the subject.

25. NTRU: the bet on lattices

Concept

Chapter 23. NTRU's hard problem is finding a short vector in a lattice — a grid of points generated by a basis. Given a badly chosen basis of very long vectors, finding the short ones is hard.

This matters for a reason the other two do not share: Shor's algorithm (Chapter 25) breaks both factoring and discrete logarithms on a quantum computer, and it does not break lattice problems. Lattice systems are therefore leading candidates for post-quantum cryptography, which is why Section 23.6 exists.

The lesson from having four different hard problems is diversification. A cryptographic system tied to one assumption fails completely when that assumption fails, and the assumptions here are genuinely independent of one another.

Figure (svg): A lattice drawn with a good short basis and a bad long basis generating the same grid of points.

Both pairs of arrows generate exactly the same grid; only one of them makes the grid easy to work with.

26. McEliece: the bet on decoding

Concept

Chapter 24. The McEliece system uses an error-correcting code whose structure the owner knows and nobody else does. Encryption adds deliberate errors; decryption removes them using the hidden structure.

Decoding a random linear code is a known hard problem. Decoding a specific structured code — a Goppa code, in McEliece's case — is easy if you know the structure. The public key is the code disguised so that it looks random.

McEliece dates from 1978, the same era as RSA, and has never been broken. Its drawback is practical rather than mathematical: the public keys are very large. Like NTRU, it is a post-quantum candidate, because Shor's algorithm gives no help against decoding.

Figure (svg): A codeword with deliberate errors added by the encrypter, and the private structure that removes them.

Errors are usually the enemy of a code; here they are the encryption.

27. Predict the cost of getting it wrong

Hypothesis

Public key operations are several orders of magnitude more expensive per byte than symmetric ones.

Predict first

A developer encrypts a 1 GB backup directly with RSA instead of using a hybrid scheme. What is the first thing that goes wrong?

  • It is slow but otherwise fine
  • It will not work at all — RSA cannot encrypt data longer than its modulus
  • The ciphertext is insecure because RSA is weaker than AES
  • It works, but the key has to be regenerated per block

Correct: It will not work at all — RSA cannot encrypt data longer than its modulus

This is why the book's rule of thumb is stated so flatly: public key methods should not be used for encrypting large quantities of data.

Every HTTPS connection follows the hybrid pattern — public key to agree a session key, then a symmetric cipher for the traffic.

Why: Textbook RSA encrypts a number smaller than the modulus n — a couple of hundred bytes at typical key sizes. A gigabyte simply does not fit, so the scheme must be applied block by block, and applying it deterministically block by block reproduces every weakness of ECB mode from Chapter 6 on top of being thousands of times slower. The correct answer is not 'slow' but 'the wrong tool': RSA's job is to move a short key, and the hybrid construction exists precisely because of this limit.

Figure (svg): A hybrid scheme: public key encryption carries a short symmetric key, and the symmetric cipher carries the bulk of the data.

This is why the slow method being slow does not matter: it only ever encrypts something short.

28. Four systems, four hard problems

Matching

The single most useful thing to carry out of this chapter is which bet each system makes.

Match the pairs

  • a. RSA
  • b. ElGamal
  • c. NTRU
  • d. McEliece
  • p. Factoring a large integer into primes
  • q. Recovering x from gˣ mod p
  • r. Finding a short vector in a lattice
  • s. Decoding a code that looks random

Why: RSA rests on factoring (Chapter 9), ElGamal on discrete logarithms (Chapter 10), NTRU on lattice problems (Chapter 23), and McEliece on the difficulty of decoding a random-looking linear code (Chapter 24). The first two fall to Shor's algorithm on a quantum computer; the last two, as far as is known, do not — which is exactly why the last two are still being actively developed forty years on.

Figure (svg): Four public key systems, each resting on a different hard problem: RSA on factoring, ElGamal on discrete logs, NTRU on lattices, McEliece on decoding.

One idea, four independent bets. If factoring falls, RSA falls — and the other three do not.

29. Why not use public key cryptography for everything?

Trade off

Public key methods solve key distribution outright. Fill in what they cost.

Comparison matrix

PropertySymmetric keyPublic key
Speed on bulk datafastseveral orders of magnitude slower
Keys needed for n partiesn(n−1)/2n key pairs
Prior shared secret required?yes — this is the whole problemno
Non-repudiationimpossibleachievable, via signatures
Typical usethe message itselfsmall data: keys and signatures

So real systems use both: public key to move a session key, symmetric to move the data. That hybrid is what TLS does on every HTTPS connection.

Figure (svg): A hybrid scheme: public key encryption carries a short symmetric key, and the symmetric cipher carries the bulk of the data.

This is why the slow method being slow does not matter: it only ever encrypts something short.

30. Explain public key cryptography without mathematics

Explain it

You have to explain to a non-technical colleague why it is safe to publish an encryption key.

Discussion prompt

Give the explanation, and then say honestly what your analogy leaves out.

Hint: The padlock does most of the work. The honesty is in what the padlock cannot show.

Answer:

The explanation. A padlock and its key do different jobs: anyone can snap a padlock shut, only the key opens it. Bob hands out open padlocks freely and keeps the one key. Anyone can lock a message to Bob; only Bob can read it. Nothing secret ever has to travel.

What it leaves out, first: in the analogy Bob's key is physically separate from the padlock. In the real system the private key is mathematically determined by the public one — it is not unknown, only expensive to compute. Security is computational, not absolute, and it can expire.

What it leaves out, second: the analogy assumes Alice got a padlock that is genuinely Bob's. Nothing in the picture guarantees that, and the substitution attack from two slides ago walks straight through the gap.

Being able to give the clean version and name its two limits is a better test of understanding than either one alone.

31. Stream Cipher and Block Cipher

Concept

Inside symmetric cryptography there are two shapes, and the difference is about how much data the algorithm consumes at once.

A stream cipher takes the data in small pieces — bits or characters — and produces output in matching small pieces. Chapter 5 covers these: LFSR-based generators and RC4.

A block cipher collects a fixed-size block of bits, transforms the whole block at once, and outputs a block. Chapters 6, 7 and 8 are about these, and most of the book's attention goes here. Public key methods such as RSA can also be regarded as block ciphers.

The consequence is that a block cipher needs a rule for messages that are not exactly one block long — and choosing that rule badly is a real vulnerability, not a formality. That is Chapter 6's modes of operation.

Figure (svg): A stream cipher consuming one symbol at a time next to a block cipher consuming a fixed-size block at once.

The distinction is about buffering, and it decides which modes of operation Chapter 6 will need.

32. Stream and block ciphers side by side

Comparison

Fill the blanks. The differences are practical, and each one becomes a chapter later.

Comparison matrix

PropertyStream cipherBlock cipher
Unit consumeda bit or a charactera fixed-size block
Needs padding?no — output length matches inputyes, unless the message is a multiple of the block size
Needs a mode of operation?noyes — Chapter 6
Effect of one corrupted bitcorrupts exactly that bitcorrupts the whole block, and possibly the next
Covered inChapter 5 — LFSRs, RC4Chapters 6-8 — Hill, DES, AES

The fourth row is the one people forget, and it decides which cipher suits a noisy channel.

33. Code or cipher?

Definition probe

The book draws a historical distinction that is still worth keeping straight, because the words are used loosely everywhere else.

Sort into buckets

Sort each example into the right category.

Code — replaces words
The British navy using 03680C to mean "shipped at"; Giving a covert operation the name OVERLORD; A dictionary replacing each place name with a four-digit group
Cipher — transforms symbols
AES encrypting an arbitrary file byte by byte; A shift cipher applied to any string, meaningful or not
code
A code substitutes for linguistic units — words, phrases, names — using a codebook. It is limited to what the codebook anticipated, so an unforeseen word cannot be sent at all. Codes still exist as operation names, but anything that must stay secret is enciphered.
cipher
A cipher ignores meaning entirely and transforms every string of characters by an algorithm, so it can carry anything. That versatility is why the rest of this book deals exclusively with ciphers.

34. Key Length and What It Does Not Tell You

Section

Section 1.1.3 · pp. 6-8

35. Say it in plain English

Translation

The vocabulary of this chapter is compact, and every term is used without explanation from Chapter 2 onwards.

Match the pairs

  • t1. Ciphertext-only attack
  • t2. Kerckhoffs's principle
  • t3. Non-repudiation
  • t4. Hybrid encryption
  • t5. Brute force attack
  • u1. Eve has intercepted messages and nothing else
  • u2. Only the key is secret; assume the method is published
  • u3. The sender cannot later deny having sent it
  • u4. Use the slow method to move a key, the fast one to move the data
  • u5. Try every key until something readable comes out

Why: Each of these is a phrase you will meet in the next twenty-four chapters with no re-introduction. The one worth extra attention is non-repudiation, because it is easy to blur into authentication: authentication convinces the recipient, non-repudiation convinces a third party, and a shared symmetric key gives you the first while making the second impossible.

36. Brute force sets the ceiling, not the floor

Concept

The most obvious attack is to try every key and see which produces a meaningful decryption. This is a brute force attack, and key length is exactly the measure of how long it takes.

\[ \text{16-bit key} \Rightarrow 2^{16} = 65\,536, \qquad \text{DES's 56-bit key} \Rightarrow 2^{56} \approx 7.2 \times 10^{16} \]

Brute force should be the last resort. A cryptanalyst always hopes for something faster, and this book is largely a catalogue of faster things: frequency analysis for the substitution and Vigenère ciphers, birthday attacks for discrete logarithms, differential cryptanalysis for DES.

Figure (svg): A comparison of key spaces: a 16-bit key, DES's 56-bit key, a substitution cipher's 26 factorial, and AES's 128 bits.

Key length bounds one attack. The substitution cipher bar is the counterexample to reading anything more into it.

37. How long is 10³⁰ operations?

Worked example

The book's own arithmetic, and it is worth doing once by hand so the numbers stop being abstract.

Suppose there are 10³⁰ possibilities to try

Why: This is around a 100-bit key, since 2¹⁰⁰ ≈ 1.3 × 10³⁰.

Suppose the machine performs 10⁹ such trials per second

Why: A billion per second is generous for a full trial decryption, and generous is the right direction for a security argument.

There are about 3 × 10⁷ seconds in a year

Why: Worth memorising: π × 10⁷ is a standard approximation.

\[ \frac{10^{30}}{10^{9} \times 3 \times 10^{7}} \approx 3 \times 10^{13} \text{ years} \]

Verify: compare with the age of the universe, about 1.4 × 10¹⁰ years

Why: The search takes roughly two thousand times the age of the universe, so 100 bits closes off brute force by an enormous margin. That margin is why key sizes stopped growing once they reached 128 bits.

Figure (svg): The book's scale argument: 10 to the 30 operations at a billion per second takes 3 times 10 to the 13 years, longer than the age of the universe.

The book's own arithmetic. Note that it settles feasibility, not security.

38. Reading a brute-force cost calculation

Cost model

Every feasibility argument in this book has this shape. Learn to read the parts and you can sanity-check any security claim in a minute.

Annotate

On: \( T = \frac{N}{R \times S} \)

  • The number of possibilities. For an exhaustive key search this is 2^(key bits) — but only if no better attack exists, which is exactly the assumption the whole trap slide is about.
  • Trials per second per machine. Be generous to the attacker: a factor of a thousand here is a factor of a thousand in the answer, and it is far cheaper to over-estimate than to under-estimate.
  • Seconds per year, about 3 × 10⁷. The only constant in the formula, and the reason answers come out in units a person can judge.
  • Parallelism and budget. A million machines divides T by a million — six orders of magnitude for money rather than mathematics. DES fell to exactly this, not to a cleverer idea.
  • If T is astronomically large, brute force is closed off and you have learned one thing. If T is small, the system is broken and you have learned everything.

Note which way the asymmetry runs: a huge T proves almost nothing, and a small T proves the system dead.

39. Not all 128-bit algorithms are created equal

Trap

The trap

The trap. Two ciphers both use 128-bit keys. Both therefore have 2¹²⁸ ≈ 3.4 × 10³⁸ possible keys, which is unsearchable. So the two ciphers are equally secure, and comparing key sizes is a fair way to compare security.

This is the reasoning behind every 'military-grade 256-bit encryption' claim you will ever read on a product page.

The fix

Why it fails. The book's own counterexample: the substitution cipher has 26! ≈ 4 × 10²⁶ keys — nearly ten orders of magnitude more than DES's 7.2 × 10¹⁶ — and it is one of the easiest systems in the book to break, while DES took a purpose-built parallel machine over a day.

The difference is what the attack uses. Against the substitution cipher, Eve exploits the structure of the language and never enumerates a key at all. Against DES, the best general attack really is exhaustion — so for DES, and only for DES, key length is the honest measure.

Some algorithms simply do not make efficient use of their key bits. A key space is a set of possible keys; it says nothing about whether the map from key to behaviour is any good.

The rule to carry away: key length is a necessary condition and never a sufficient one. A cipher is as strong as the best attack against it, and the key count only bounds one attack out of all of them.

40. Put the counterexample in numbers

Estimation

The substitution cipher has 26! keys; DES has 2⁵⁶.

Predict first

Roughly how many times larger is the substitution cipher's key space?

  • About 100 times
  • About a million times
  • About 10 billion times
  • They are about equal

Correct: About 10 billion times

It also puts a number on how much a structural attack is worth. Frequency analysis does not shave a factor off the search; it replaces the search entirely.

Chapter 2 carries this out in full on all seven of its ciphers.

Why: 26! ≈ 4 × 10²⁶ and 2⁵⁶ ≈ 7.2 × 10¹⁶, so the ratio is about 5.6 × 10⁹ — roughly ten billion. And the cipher with ten billion times as many keys is the one a person can break on paper. Holding both numbers at once is the point of the exercise: it makes the key-length fallacy impossible to fall for again.

41. A system with a perfect cipher and no security

Anomaly

A messaging app uses AES-256 correctly, with keys drawn from a good random source. Every message is encrypted before it leaves the device. An auditor reports that an eavesdropper can nevertheless learn who is talking to whom, when, and roughly how much they said.

Predict first

Is the auditor describing a flaw in the cipher?

  • Yes — AES must be leaking information about the plaintext
  • No — the cipher is fine; the leak is metadata, which encryption was never going to protect
  • Yes — the key size is too small for this use
  • No — but only because AES-256 is stronger than needed here

Correct: No — the cipher is fine; the leak is metadata, which encryption was never going to protect

Chapter 2 has the same lesson at letter granularity: a monoalphabetic cipher hides the letters but not the pattern the letters make, and the pattern is enough.

The general form: a cipher protects the values, not the shape of the values.

Why: Encryption protects message contents. It does not hide the existence of a message, its length, its timing, or its endpoints — and those four together are often as revealing as the text. This is traffic analysis, and it is the reason real systems add padding, cover traffic and mixing on top of encryption. The example matters because it separates two things Chapter 1 is careful to keep apart: the strength of a primitive and the security of a system.

42. Find the flaw in this security argument

Error analysis

From a product security whitepaper. Three sentences, and each one has a problem.

Annotate

  • Kerckhoffs's principle: the algorithm ships in the product, so it is recoverable by anyone who wants it. Security resting on it is security on a timer.
  • The key-length fallacy, and the substitution cipher is the counterexample: 4 × 10²⁶ keys and a newspaper-puzzle break. A large key space closes off brute force and says nothing about any other attack.
  • True but irrelevant, and the irrelevance is the point. The claim answers a question nobody was asking, and the reader is invited to mistake it for an answer to the question that matters.
  • Unpublished also means unanalysed. The only evidence a cipher is strong is that competent people attacked it publicly and failed — so secrecy does not add a layer, it removes the evidence.

Run it through the four-part template: what is public, what is secret, what Eve can do, what breaks it. The whitepaper answers only the second, and gets that wrong too.

43. When does a security claim expire?

Edge cases

The book warns that an algorithm secure now may not stay secure, and gives DES as the example: twenty years of scrutiny, then a purpose-built parallel computer.

Discussion prompt

What kinds of change can invalidate a security claim, and which of them can you plan for?

Hint: Separate 'the machines got faster' from 'somebody had a better idea'.

Answer:

Faster hardware. Predictable, roughly, and therefore plannable: pick key sizes with decades of margin. This is the cheapest failure to defend against and the one that actually killed DES.

Better algorithms. Not predictable. Factoring got substantially better between RSA's invention and the RSA-129 challenge, and each improvement shortened every RSA key in the world at once.

A change of computational model. Quantum computing is the live case. Shor's algorithm does not make factoring somewhat faster; it makes it easy, which retires RSA and ElGamal together rather than requiring longer keys. Chapter 25 shows the algorithm.

Implementation and protocol failures. The book notes these are the most common cause in practice — the mathematics stands and the deployment leaks. Chapter 14 is a whole chapter of examples, and WEP is the standout: sound primitives, fatal assembly.

So: plan for the first, monitor the second, hedge against the third by keeping independent assumptions alive, and treat the fourth as the most likely thing to go wrong on any given day.

44. Cryptographic Applications

Section

Section 1.2 · pp. 8-9

45. Where all of this is running right now

Real world

Everything in this chapter is in use on every HTTPS connection you make, in the order the chapter introduced it.

Discussion prompt

Walk through what happens when your browser opens a connection to a bank, and name which idea from this chapter each step uses.

Hint: There are four steps, and they map onto certificates, public key, symmetric key, and integrity.

Answer:

1. The server presents a certificate. This is the answer to the padlock-substitution attack: a third party the browser already trusts has vouched that this public key belongs to this domain. Sections 15.4 and 15.5.

2. The browser and server agree a session key, using public key cryptography or Diffie-Hellman. This is the key-establishment problem, and it is solved without any prior shared secret. Chapters 10 and 15.

3. The traffic is encrypted with a symmetric cipher — AES, almost always. This is the hybrid pattern: the expensive method moved a short key, and the fast method carries the gigabytes. Chapter 8.

4. Every record carries an authentication tag, so tampering is detected. Confidentiality alone was never the goal — integrity and authentication ride along. Chapters 11 and 12.

Four steps, four of this chapter's ideas, and the ordering is not accidental: each step is useless without the one before it.

46. How much does one compromised key cost?

Commit first

A company uses one symmetric key shared across all 40 of its offices, rotated annually.

Predict first

One office is breached in month three. What is the exposure?

  • That office's traffic, from month three onwards
  • That office's traffic for the whole year
  • All 40 offices' traffic for the whole year, including the two months already recorded
  • Nothing, provided the breach is detected

Correct: All 40 offices' traffic for the whole year, including the two months already recorded

Two defences follow directly. Segmentation: a key per pair rather than a key for everyone, which is where the n(n−1)/2 problem comes from. Forward secrecy: derive a fresh session key per conversation and destroy it afterwards, so recorded ciphertext stays unreadable even after a later compromise.

Forward secrecy is the modern reason TLS prefers Diffie-Hellman key agreement over encrypting a session key with the server's long-term RSA key.

Why: One key protecting everything means one key compromising everything. The attacker reads all traffic between all offices — and if she recorded ciphertext during months one and two, she can now decrypt that too, because the key was already in use. This is Eve's second goal from earlier in the chapter, and it is why key compromise is treated as a catastrophic rather than a local event.

47. Four objectives, only one of which is encryption

Concept

Cryptography is not only about encrypting and decrypting. The book names four objectives, and the rest of the volume is organised around them.

Confidentiality
Eve should not be able to read Alice's message. The tools are encryption and decryption — Chapters 2 through 10.
Data integrity
Bob wants to be sure the message was not altered, whether by a transmission error or by an adversary. The tools are hash functions and MACs — Chapters 11 and 12.
Authentication
Bob wants to be sure only Alice could have sent it. Splits into entity authentication (who am I talking to) and data-origin authentication (who made this data, and when).
Non-repudiation
Alice cannot later claim she did not send it. Essential in electronic commerce, where a consumer must not be able to disown a purchase — Chapters 13 and 16.

Figure (svg): The four security objectives — confidentiality, data integrity, authentication, non-repudiation — with the primitive that provides each.

Only the last one needs public key cryptography — symmetric keys cannot provide non-repudiation at all.

48. Which objective is at stake?

Discrimination

Almost every real security incident is a failure of exactly one of the four.

Sort into buckets

Sort each failure into the objective it violates.

Confidentiality
An eavesdropper reads a password sent in the clear
Data integrity
A transmitted file arrives with three bits flipped and nobody notices; A middlebox rewrites a payment amount in transit
Authentication
An attacker sends an email that appears to come from the finance director; Someone logs in with a stolen session token
Non-repudiation
A customer denies having authorised a purchase they did make
conf
Information reached someone who should not have it. Encryption is the tool, and it is the only one of the four that encryption alone fixes.
integ
The data changed and the change went undetected. Note that integrity covers accidental corruption as well as deliberate tampering — hash functions catch both.
auth
The recipient was wrong about who they were dealing with. No amount of encryption helps: a message can be perfectly confidential and entirely fraudulent.
nonrep
The sender can deny an action they took. This is the objective symmetric cryptography cannot provide at all, and the reason digital signatures exist.

49. What is missing from this specification?

Missing information

A specification reads, in full: "All customer records shall be encrypted using AES."

Discussion prompt

List what a security reviewer still cannot determine, and say why each gap matters.

Hint: Walk the four-part template — public, secret, adversary, best attack — and see which parts the sentence touches.

Answer:

Which key, and who holds it. One key for all records, or one per customer? Held by the application, or an HSM? A single application-held key means an application compromise is a total compromise — the wager two slides back.

How keys are generated, rotated and destroyed. A 256-bit key from a weak generator has far less than 256 bits of entropy, and no amount of AES fixes that.

Which mode of operation. "AES" alone permits ECB, which leaks equal plaintexts as equal ciphertexts — the failure Chapter 6 opens with, and precisely wrong for a database column.

Whether integrity is protected. Encryption without authentication lets an attacker alter ciphertext; some modes will decrypt the result into plaintext of the attacker's choosing. Confidentiality was specified; integrity was not mentioned.

What the adversary is assumed to be. An outside eavesdropper, a rogue administrator, someone with a stolen backup? Each implies different answers above.

Naming a cipher is the smallest part of specifying encryption, and it is the part these documents usually contain in isolation.

50. Design under a real constraint

Constraint

You are securing telemetry from ten thousand battery-powered sensors. Each has a tiny processor, sends 20 bytes every minute, and must run for five years on one cell.

Discussion prompt

Which of this chapter's tools do you reach for, and which do you rule out — and on what grounds in each case?

Hint: Cost per byte matters far less than cost per operation here, and the key distribution problem has a shape you get to choose.

Answer:

Rule out per-message public key operations. Several orders of magnitude more computation than symmetric, on a processor with a five-year power budget. The rule of thumb applies with force.

Reach for a symmetric cipher with a per-device key, provisioned at manufacture. The n(n−1)/2 problem does not bite, because the sensors never talk to each other — the topology is a star with one hub, so it is n keys, not n²/2.

Do not skip integrity. A 20-byte telemetry reading is exactly the kind of message an attacker would rather forge than read, so a MAC matters more here than encryption does. This is the chapter's point that confidentiality is only one of four objectives.

Consider public key once, at provisioning, to establish those per-device keys without a factory-floor secret. Paying the expensive operation once in a device's life is very different from paying it every minute.

The general move: the topology and the threat decide the tools. 'Use strong crypto' is not a design.

51. Why can't symmetric cryptography give non-repudiation?

Explain it to yourself

With a shared key, Bob knows a message came from Alice, because nobody else could have produced a ciphertext that decrypts correctly. So authentication is automatic.

Discussion prompt

Explain why that same reasoning fails to convince a third party — a judge, say — that Alice sent it.

Hint: Ask what else Bob could have done with the key he holds.

Answer:

Because Bob has the same key. Anything Alice could produce, Bob could produce. So a valid ciphertext proves it came from someone holding the key, and there are two such people.

Bob is convinced, because he knows he did not write it. A judge is not, because the judge cannot rule Bob out. Authentication is a claim Bob can verify for himself; non-repudiation is a claim Bob must be able to prove to someone else, and the shared key destroys exactly that.

Public key cryptography breaks the symmetry. Alice signs with a private key only she holds, and anyone can verify with her public key. Now the verifier does not need to be trusted, and Bob cannot have forged it.

This is why Chapter 13 exists as a separate chapter from Chapter 9, and why electronic commerce needed public key cryptography rather than merely wanting it.

52. What the rest of the book does

Concept

The applications the book previews here, and where each lands:

ApplicationThe problemChapter
Digital signaturesTie an identity to a document that is trivially copyable13
IdentificationProve who you are without handing over the proof7, 19
Key establishmentAgree a shared key over an open channel10, 15
Secret sharingSplit a secret so that k of n people can recover it17
Security protocolsAssemble primitives into something that survives an active adversary15
Digital cashSpend a token once, anonymously, without a bank in the loop16

Notice how few of these are 'encrypt a message'. Encryption is the first tool in the box and the smallest part of the job.

Figure (svg): A map of what the rest of the book covers, from digital signatures through key establishment to secret sharing and protocols.

Cryptography is not only encryption — most of this book is about the problems encryption does not solve.

53. Which chapter answers this?

Sorting

The book's structure follows the four objectives. Getting the map straight now makes the rest of the course navigable.

Sort into buckets

Sort each question into the part of the book that answers it.

Symmetric ciphers (Ch. 5-8)
How do I encrypt a large file quickly?
Hashes and integrity (Ch. 11-12)
How do I know this file has not been altered?
Public key and signatures (Ch. 9, 10, 13)
How do two strangers agree on a key over an open channel?; How can Alice prove to a court that she signed this?
Specialised constructions (Ch. 17, 24)
How do I detect a single corrupted bit and repair it?; How do I split a secret among five people so any three can recover it?
sym
Bulk data is symmetric cryptography's job, and its speed advantage is what makes the hybrid pattern worth the complexity.
hash
Detecting change is what hash functions and message authentication codes do, and it is a completely separate mechanism from encryption — a fact worth over-learning early.
pk
Key agreement between strangers and provable authorship are the two things only public key cryptography provides. Both are impossible with a shared secret alone.
other
Error correction (Chapter 24) repairs accidental corruption rather than detecting malicious change, and secret sharing (Chapter 17) is a threshold problem with no encryption in it at all. Both are reminders that the field is wider than confidentiality.

54. Watch the numbers grow

Scale up

One more pass over the chapter's central quantities, in the order they get large.

Step through it

Which row is out of order if you sort by security rather than by key count?

  1. A 16-bit key. Every one of the 65 536 possibilities in well under a second.
  2. DES. Large enough to resist a general-purpose computer in 1977, and not large enough to resist a machine built for the job in 1998.
  3. The substitution cipher — ten billion times DES's key space, and the easiest break in the book. This is the row that carries the argument.
  4. AES-128. Comfortably beyond exhaustion by the calculation two slides ago, and the reason key sizes stopped growing.
  5. RSA's scale. The universe holds fewer than 10⁹⁰ electrons, so enumerating primes was never on the table — which is why real factoring uses algorithms, not counting.

The third. Sorting by key space puts the substitution cipher near the top; sorting by security puts it at the bottom. That inversion is Chapter 1's thesis in one table.

55. The shape of every argument in this book

Pattern

Chapter 1 hands you a template. Every security claim in the following twenty-four chapters has these four parts, and a claim missing any of them is not yet a claim.

  1. What is public. The algorithm always. Often the encryption key too. State it, because Kerckhoffs's principle means the answer is 'more than you think'.
  2. What is secret. Exactly one thing, and its compromise must be the only way the system fails.
  3. What the adversary can do. Which of the four attack models, and whether her computation is bounded. 'Eve cannot read it' is not a threat model.
  4. What breaks it. The best known attack, and its cost. Not the brute force cost — the best cost.

Run a product claim through those four and most of them fall apart on the third. That is the practical value of this chapter.

Figure (svg): The four-part template for a security claim: what is public, what is secret, what the adversary can do, and what breaks it.

Four questions. Most marketing claims answer only the second.

56. Check: reading a security claim

Check

Work it out before you click.

Check your understanding

A system uses a 256-bit key and its designers say the key space cannot be searched. Which question does this claim leave completely unanswered?

  • A. Whether the key is long enough
  • B. Whether an attack faster than brute force exists (correct)
  • C. Whether the algorithm is published
  • D. Whether the keys are generated randomly

Answer: B

Why: The claim is about the size of the key space, which bounds exactly one attack. The substitution cipher has 26! ≈ 4 × 10²⁶ keys and is broken by frequency analysis without enumerating any of them, so a large key space is entirely consistent with the cipher being trivially breakable. B is the question the claim does not touch, and it is the one that matters.

Why A tempts people
The claim does answer this — 256 bits is comfortably beyond brute force, and it is essentially the only thing the claim establishes.
Why C tempts people
A real omission and a fair concern under Kerckhoffs's principle, but not the one the claim's own reasoning fails on. The claim would be equally hollow if the algorithm were published.
Why D tempts people
A genuine and common implementation failure — a 256-bit key drawn from a weak generator has far less than 256 bits of entropy — but it is a question about the key, not about the existence of a better attack.

57. Check: symmetric versus public key

Check

Think about what each party has to hold.

Check your understanding

Alice and Bob have never met and share no secret. Which is possible?

  • A. They can establish a shared key over an open channel using public key methods (correct)
  • B. They cannot communicate securely without a trusted courier
  • C. They can use AES directly, since AES keys are public
  • D. Only a one-time pad delivered in advance will work

Answer: A

Why: Solving exactly this problem is what public key cryptography was invented for. Bob publishes an encryption key; Alice uses it to send a session key; from then on they use fast symmetric encryption. The book's padlock analogy captures it: Bob's open padlock can travel in public because it is not the secret.

Why B tempts people
This was true before the 1970s and is the problem public key cryptography solved. It remains true only for information-theoretic security — a one-time pad really does need prior delivery.
Why C tempts people
AES is a symmetric cipher and its keys are emphatically not public. The algorithm is public, which is Kerckhoffs's principle, and confusing the published algorithm with a published key is the error this option tests.
Why D tempts people
A one-time pad does need pre-shared material, but it is not the only option, and its key must be as long as the message — the opposite of practical here.

58. Check: which objective

Check

Read the failure carefully before choosing.

Check your understanding

A signed contract is transmitted encrypted. The recipient later cannot prove to a court who signed it, because both parties held the same key. Which objective failed?

  • A. Confidentiality
  • B. Data integrity
  • C. Authentication
  • D. Non-repudiation (correct)

Answer: D

Why: Non-repudiation is the ability to prove authorship to a third party, and a shared key destroys it: anything Alice could produce, Bob could too, so no outside observer can attribute the message. Note that authentication is intact — Bob himself is convinced, because he knows he did not write it. The failure appears only when a third party has to be convinced.

Why A tempts people
The message was encrypted and nobody read it who should not have. Confidentiality held.
Why B tempts people
Nothing was altered, and nothing failed to detect an alteration. Integrity is not in question.
Why C tempts people
Authentication succeeded from Bob's point of view — this is the distinction the question turns on. Authentication convinces the recipient; non-repudiation convinces everyone else.

59. Draw the map before Chapter 2

Connect it up

Everything in this chapter is definitions, and definitions stick only if you rebuild them once yourself.

Draw it

On one page: draw the Alice-Bob-Eve channel and label plaintext, ciphertext, both keys, and what Eve sees. Beside it, list Eve's four goals in order of damage and the four attack models in order of strength. Underneath, write the two-column comparison of symmetric and public key — speed, keys needed for n parties, prior secret required, non-repudiation. Finally write the one-sentence version of Kerckhoffs's principle, and the one counterexample that kills the key-length fallacy.

If you can produce that page from memory, Chapter 2's seven ciphers will be seven instances of one story rather than seven things to learn.

60. Exit ticket

Exit ticket

One question. It is the one this chapter exists to install.

Predict first

What is the single most important thing Kerckhoffs's principle tells a system designer to do?

  • Keep the algorithm secret as an extra layer of defence
  • Design so the system stays secure even if the algorithm is fully published
  • Use the longest key the hardware allows
  • Prefer public key cryptography wherever possible

Correct: Design so the system stays secure even if the algorithm is fully published

Why: The principle is that security must rest on the key alone. Machines are captured, code is disassembled, people defect — so any secrecy in the algorithm is temporary, and worse, it cannot be repaired: a leaked algorithm breaks every deployment at once, while a leaked key breaks one and is replaceable. Designing for publication also makes the security claim checkable by people other than its authors, which is the only evidence a cipher is ever going to have.

61. What to carry into Chapter 2

Recap

A short chapter, and the vocabulary for the whole book.

Chapter 2 next. Seven classical ciphers, each broken. Every break uses the structure of the cipher rather than the size of its key space, so keep the counterexample from this chapter in view the whole way through.

Figure (svg): A comparison of key spaces: a 16-bit key, DES's 56-bit key, a substitution cipher's 26 factorial, and AES's 128 bits.

Key length bounds one attack. The substitution cipher bar is the counterexample to reading anything more into it.

Sources

  1. Introduction to Cryptography with Coding Theory, 3rd edition — Wade Trappe and Lawrence C. Washington — Pearson, 2020 (ISBN 978-0-13-485906-4)
  2. Chapter 1 — Overview of Cryptography and Its Applications (sections 1.1-1.2) — Trappe & Washington, 3rd edition, pp. 1-9

Want this taught 1-on-1? Alexander tutors Cryptography — $55/session, free consultation.

Book on Wyzant · Text (657) 465-8108