The Symmetric Cipher Model
Chapter Seven
Syllabus topic Module 1, "Classical Encryption Techniques: Symmetric Cipher Model"
Pages 30 to 34 of 678
In one line
One key, held by both parties, used to encrypt and to decrypt. That is a symmetric cipher, and until 1976 it was the only kind there was.
In the wording a student can write in an examination: a symmetric cipher, also called conventional, secret-key or single-key encryption, is a scheme with five ingredients: plaintext, the original message; an encryption algorithm, which performs substitutions and transformations on it; a secret key, which is an input to the algorithm and determines what it does; ciphertext, the scrambled output; and a decryption algorithm, which is the encryption algorithm run in reverse and which recovers the plaintext from the ciphertext using the same key. X.800 puts the defining property precisely: in symmetric encipherment, "knowledge of the encipherment key implies knowledge of the decipherment key and vice versa".
Why the model is written down before any cipher
Because it tells you exactly what a cipher has to be, and therefore what a question about a cipher can ask. Every cipher in the next fifteen chapters is an instance of this one picture, so the picture is worth getting exactly right, and the two requirements below are worth more marks than the five ingredients.
The five ingredients, in the order a program uses them
- Plaintext. The message or data as it stands. Written
PorM. - Secret key. A value independent of the plaintext and of the algorithm. Written
K. Its exact bits decide which of the algorithm's many possible transformations is performed. - Encryption algorithm. Written
E. It performs substitutions and permutations on the plaintext under the control of the key. - Ciphertext. The output, written
C. It depends on both the plaintext and the key: for one plaintext, two different keys give two unrelated ciphertexts. - Decryption algorithm. Written
D. The encryption algorithm run backwards, taking the ciphertext and the same key and producing the plaintext.
In symbols, which is how an answer should state it:
C = E(K, P)
P = D(K, C)
P = D(K, E(K, P))
The two requirements, which are what the marks are in
Requirement 1: the algorithm must be strong enough. An opponent who knows the algorithm and who has one or more ciphertexts should be unable to decipher the ciphertext or to work out the key. Notice the phrasing carefully: the opponent knows the algorithm. That is assumed, not conceded. It is the requirement that a student most often states too weakly, writing "the opponent should not be able to break it", which says nothing about what the opponent is given.
Requirement 2: sender and receiver must have obtained the key in a secure fashion, and must keep it secure. The security of a symmetric cipher rests on the secrecy of the key, and on nothing else. If somebody learns the key, all communication using it is readable.
The Symmetric Cipher Model
Requirement 2 is the harder of the two in practice, and it is the reason a third of this syllabus is about key management rather than about ciphers. Designing a cipher is a problem you solve once, publicly, and then everybody uses the answer. Getting a key to the other party is a problem you have again with every new party, and it is why the Diffie-Hellman chapter exists.
Kerckhoffs's principle: why the algorithm is published
A student's instinct is that a secret algorithm must be safer than a published one, because the opponent knows less. It is the opposite, and the reason is practical rather than mathematical.
A secret algorithm cannot be reviewed. The only way to gain confidence that a cipher is strong is for many skilled people to attack it and fail. A cipher nobody has seen has not been tested; it has only not been tested yet. AES was chosen after a five-year open competition in which everybody was invited to break every candidate. That is evidence. "Nobody has broken our secret cipher" is not evidence, because nobody has tried.
A secret algorithm cannot be replaced. Keys change easily and algorithms do not. If security rests on the algorithm and the algorithm leaks, everything must be rebuilt. If security rests on the key and the key leaks, you change the key. Putting the secret in the smaller, cheaper, more replaceable component is simply good engineering.
A secret algorithm cannot be standardised. Two parties who have never met cannot interoperate over a secret. Every protocol in Module 2 works because both ends can look the algorithm up in a published document.
The principle, in one line: a cryptosystem should be secure even if everything about the system, except the key, is public knowledge. That is Kerckhoffs's principle, from 1883, and it is the working assumption of this entire subject. Every algorithm on this syllabus is published: DES in FIPS 46-3, AES in FIPS 197, the hash functions in FIPS 180-4, RSA in RFC 8017. You can read all of them. They are secure anyway.
The opposite practice has a name, security through obscurity, and it is used as a criticism. It is not worthless as one layer among many, but as the foundation it fails, because obscurity is lost once and cannot be restored.
A worked example: what the key actually decides
The setup. Take the simplest possible symmetric cipher: shift every letter forward by K positions in the alphabet. Plaintext MEET ME AFTER THE TOGA PARTY.
The Symmetric Cipher Model
Step 1: the algorithm is public. Everybody, including the opponent, knows that the rule is "shift by K". Requirement 1 says the cipher must be secure anyway.
Step 2: the key is secret. Suppose K is 3. The program below performs the encryption and the decryption, and prints both.
ALPHABET = "ABCDEFGHIJKLMNOPQRSTUVWXYZ"
def shift(text, k):
out = ""
for ch in text.upper():
if ch in ALPHABET:
out += ALPHABET[(ALPHABET.index(ch) + k) % 26]
else:
out += ch
return out
plaintext = "MEET ME AFTER THE TOGA PARTY"
key = 3
ciphertext = shift(plaintext, key)
recovered = shift(ciphertext, -key)
print("plaintext :", plaintext)
print("key :", key)
print("ciphertext:", ciphertext)
print("recovered :", recovered)
print("P = D(K, E(K, P)) is", recovered == plaintext)plaintext : MEET ME AFTER THE TOGA PARTY
key : 3
ciphertext: PHHW PH DIWHU WKH WRJD SDUWB
recovered : MEET ME AFTER THE TOGA PARTY
P = D(K, E(K, P)) is TrueStep 3: read the model off the run. shift with a positive key is E; shift with a negative key is D; 3 is K. The last line is the identity from section 3, verified rather than asserted. Both parties need the number 3 and nothing else, and anybody who learns the number 3 reads everything.
Step 4: and this cipher fails requirement 1. There are only 25 useful keys, so an opponent who knows the algorithm tries all of them in a fraction of a second. That is not a criticism of the model; the model is fine. It is a statement about this particular algorithm's keyspace, and the next chapters are about making the keyspace large enough that requirement 1 is actually met.
Distinctions that carry marks
| Symmetric | Asymmetric | |
|---|---|---|
| Keys | one, shared | two, related, one public |
| X.800's test | knowing the encipherment key implies knowing the decipherment key | it does not |
| Who must share a secret | both parties, in advance | nobody |
| Speed | fast | slow, by a factor of hundreds or more |
| Keys needed for N parties | N(N - 1)/2 | 2N |
| Gives non-repudiation | no | yes |
| Used for | bulk data | keys, and signatures |
| Cryptography | Cryptanalysis | Cryptology | |
|---|---|---|---|
| Is | the design of ciphers | the breaking of ciphers without the key | both together |
| Practised by | the designer | the attacker, and the reviewer | the field |
| Block cipher | Stream cipher | |
|---|---|---|
| Processes | a fixed-size block at a time | one bit or byte at a time |
| Examples here | DES, 3DES, AES | RC4 |
What beginners get wrong here
"Symmetric" does not mean the two algorithms are identical. It means the two keys are the same, or trivially derived from each other. In DES the decryption algorithm is the encryption algorithm with the subkeys reversed, which is not the same thing as being identical.
The Symmetric Cipher Model
The key is not a password. A key is a value of a fixed length, usually 128 or 256 bits, chosen to be unpredictable. A password is something a human remembers and is far weaker; turning one into the other is a separate job, done by a key derivation function.
Knowing the algorithm is assumed, not a weakness. An answer that offers "keep the algorithm secret" as a countermeasure has misunderstood requirement 1.
Two parties, one key. The N(N - 1)/2 count in the table above is the reason symmetric cryptography alone does not scale, and it is worth being able to compute: ten parties need forty-five keys, a hundred parties need four thousand nine hundred and fifty.
Quick revision
- Five ingredients: plaintext, encryption algorithm, secret key, ciphertext, decryption algorithm.
C = E(K, P)andP = D(K, C).- Two requirements: a strong algorithm, against an opponent who knows the algorithm and holds ciphertext; and a securely obtained and kept key.
- X.800: symmetric means knowing the encipherment key implies knowing the decipherment key.
- Kerckhoffs's principle: secure even when everything but the key is public. Because a secret algorithm cannot be reviewed, replaced or standardised.
- Security through obscurity is the opposite practice and fails as a foundation, because obscurity is lost once.
- Symmetric needs N(N - 1)/2 keys for N parties; asymmetric needs 2N.
- Cryptography designs, cryptanalysis breaks, cryptology is both.
Test yourself
1. Name the five ingredients of a symmetric cipher. Plaintext, an encryption algorithm, a secret key, ciphertext and a decryption algorithm.
2. State the two requirements for secure use of conventional encryption. First, a strong encryption algorithm: an opponent who knows the algorithm and has access to one or more ciphertexts should be unable to decipher the ciphertext or to determine the key. Second, the sender and receiver must have obtained copies of the secret key in a secure fashion and must keep the key secure.
3. What does it mean to say a cipher is symmetric, in X.800's terms? That knowledge of the encipherment key implies knowledge of the decipherment key, and the other way round; in practice the two are the same key.
4. State Kerckhoffs's principle and give two reasons for it. A cryptosystem should remain secure even if everything about it except the key is public. First, a published algorithm can be attacked by many skilled people, and surviving that is the only real evidence of strength; a secret one is merely untested. Second, a key can be changed cheaply and an algorithm cannot, so the secret belongs in the replaceable part.
5. Why is requirement 2 harder in practice than requirement 1? Because a cipher is designed once and then used by everybody, whereas a key must be delivered securely to every new correspondent, again and again, over channels that may be no safer than the ones the cipher is protecting. Key distribution is therefore the recurring problem, and it is why public-key methods were invented.
The Symmetric Cipher Model
6. How many keys do twenty parties need to communicate pairwise under symmetric encryption, and under public-key encryption? Symmetric: 20 times 19 divided by 2, which is 190 keys. Public-key: two per party, so 40 keys, of which only the 20 private ones are secret.
7. A vendor says their cipher is safe because nobody knows how it works. What is wrong with that? It is security through obscurity. The claim is unverifiable, because the cipher has not been reviewed by anybody able to attack it; and it is fragile, because a single disclosure or reverse engineering destroys all security at once, with no key to change. Published algorithms with secret keys fail more gracefully and can be evaluated.
The rest of this subject
These notes are cut from the University's printed syllabus. Open the syllabus itself for the same subject.