⚠ Switch to EXCALIDRAW VIEW in the MORE OPTIONS menu of this document. ⚠ You can decompress Drawing data with the command palette: ‘Decompress current Excalidraw file’. For more info check in plugin settings under ‘Saving’
Excalidraw Data
Text Elements
Confidentiality, Integrity, Authenticity, Correctness
If I am signing up for a website, there must be confidentiality when I submit my password, so that man in the middle attackers cannot hack my account.
being used where?
A one time pad takes a randomly generated key, and xors it with your plaintext, to make a ciphertext. you need a new key for every message.
Encryption is Enc(m,k): C = m xor k Decryption is Dec(C,k): m = C xor k
you need a new key every time, the keys are one time use.
the IND-CPA game is one where eve can submit 2 messages for encryption and must try to guess, with greater than 50% accuracy which one was encrypted, given just the resulting ciphertext No deterministic algorithm is IND-CPA secure
Yes, the key is random every time.
No, because then it is a fully deterministic algorithm, and eve can just use process of elimination to figure out the ciphertext for some chosen plaintext
Your key is a fixed length block and it is xor’d with your plaintext
because your key is a fixed length block, and your plaintext is also fixed length
different block ciphers are useful for different tasks
in encryption and decryption
Not inherently, though, through avalanching they can.
Randomly generated bits which are used to add randomness to your encryption, passed alongside your ciphertext for use in decryption.
we use them in both encryption and decryption, on block ciphers. in encryption, they add the randomness. in decryption, they are used to undo that randomness, and get back correctness. Without them, we have a fully deterministic encryption scheme, which is not IND-CPA secure.
a one way function is one that you cannot reverse engineer the inputs from, when given only the outputs.
collision resistance is when it is hard to find any 2 inputs that when ran through the function generate the same output.
Add extra stuff to the end of a message, and produce a valid hash of that message
one way, collision resistant, deterministic
Not alone, no, as a man in the middle attack could just replace the hash with an attacker provided one
encrypt((plaintext + hash), k) Then, we need to decrypt in order to see the hash, so you now have integrity. OR hash + ciphertext + hash where then length extension attacks cant be done.
MAC are
Embedded Files
d5d093873df38e3ad1301182f1297c803951999b: page=1
b4b2c8bcaab4d1b5f06ee50c9e3ab1e617865605: page=2
c57f86093329b0e88f48a7559bde39c4c7199253: page=3
5827dc7b34330f7c826bcf291b9af54d8495caba: page=4
f341a5ff3c1cf1d8650c8df5dfd4c4261d1e1f4e: page=5
acacf9022f40e54ac3b47d67c248e7cbf1effb66: page=6
8db57c633803e60d6d80cba9b58e0c2e1b7af9ad: page=7
f1a15ce62a47986aec68b521c36cd3731cdbd46a: page=8
f418eddb73d1295372d9d117b498445b0854eed6: page=9
0d30849f4240f0706f8d9cfb5848c8ef267c79de: page=10
793d7eac349595cf9d74e4a2630d762c70d79b32: page=11
0a5d90275ebe362825bf652ed644070202ea3b7d: page=12
dfbd4a0fbaf1932d212c08ebeeed7099d711ab00: page=13
9930dc9ca10eb9dda4a4d39269b450c62cc5ac86: page=14