Cryptography Protocols
Here some basic functions in our toolbox:
Authenticated Encryption:
k = genKey()generate a symmetric keyc = Enc(k, m)encrypts a messagemwith the keykassumingcincludes the ciphertext, the nonce and the MAC tag.m = Dec(k, c)decrypts the payloadcusingkto get the plaintextmback. It raises an error if the MAC tag is not valid
Authenticated Encryption:
(sKem, pKem) = genKem()returns a pair (private and public) of EC keys for key exchangek=ECDH(sKem1, pKem2)=ECDH(sKem2, pKem1)generates a keykby combining two key exchange pairs
Digital Signature:
(sSig, pSig) = genSig()returns a pair (private and public) of EC keys for signatures = Sig(sSig, m)generate the signaturesby signing the messagemwith the private keysSigVer(pSig, s, m)verify the signaturescorrespond to the messagemsigned with the private key corresponding topSig.
Synchronous Protocol: TLS 1.3 and the Public Key Infrastructure
TLS 1.3 has only two rounds:
- A -> B: pKemA
-
B -> A: pKemB, *Enc(k, CertB+ Sig(pKemA pKemB CertB))*
- What are pKemA and pKemB? What are they used for? Are they long term of short term keys?
- Explain what Alice must do and check after receiving
- How does Alice’s browser trust a certificate supplied by Bob’s website? What does she need to verify that certificate? 4. Why Mallory cannot do a replay attack on Bob’s response?
- Explain why TLS ensures Perfect-Forward Secrecy?
- Describe how a man-in-the-middle attack could succeed on TLS/SSL? 7. In this version of the protocol, why does not Alice sign any message so that Bob can check her identity?
Asynchronous Protocol: GPG
GPG uses two types of EC keys:
- a signature key
Sigto sign messages - a key exchange key
Kemto exchange a symmetric encryption key and encrypt message
Assume that Alice is sending a GPG message to Bob:
- Alice has the GPG public key
(pSignA, pKemA)and the corresponding GPG private Key(sSignA, sKemA) - Bob has the GPG public key
(pSignB, pKemB)and the corresponding GPG private Key(sSignB, sKemB)
- Explain how Alice can sign her message
musing GPG - Explain how Bob can verify that the message comes from Alice?
- Explain how Alice can encrypt her message
musing GPG - Explain how Bob can decrypt the message from Alice
- Explain why GPG does not protect against replay attack.
- Explain why GPG does not ensure Perfect-Forward Secrecy.
