munotes®

Symmetric Encryption

Get access to whole semester resourcesSemester Pass

Chapter Ninety-Five

Syllabus topic Module 2, "Symmetric encryption"

Pages 345 to 347 of 378

In one line

Symmetric encryption uses the same key to lock and unlock, which is fast and leaves you with the problem of getting the key to the other party.

In the wording you can write in an examination: a symmetric cipher uses a single key for both encipherment and decipherment. It is distinguished from an asymmetric cipher, in which a public key enciphers and a different private key deciphers. Symmetric ciphers are fast and require the key to be shared in advance through some channel other than the one being protected, which is the key distribution problem.

The defining property

One key, both directions. Encipher with k, decipher with k.

Every cipher in this block is symmetric. Caesar's shift, the keyword alphabet, the rail fence, the columnar transposition, and their composition in [Arthaśāstra-Inspired Cryptography as a Symmetric Cipher System]. So is the Arthaśāstra's gūḍhalekhya, whatever it was, because a prearranged secret is what makes the recipient able to read it.

And so are the modern ones a student meets: DES and AES. Asymmetric cryptography is a twentieth-century invention and is a different subject.

Block and stream

The two shapes a modern symmetric cipher takes.

Block cipherStream cipher
Operates onfixed-size blocks, typically 128 bitsone bit or byte at a time
Needs paddingyes, to fill the last blockno
Natural fordata at rest, files, recordsdata arriving continuously
ExamplesDES, AESRC4, and the keystream generators
How it worksa keyed permutation on the blocka keystream combined with the plaintext

A block cipher is a permutation of the block space. For a 128-bit block that is a permutation of 2 to the power 128 values, chosen by the key.

A stream cipher generates a keystream from the key and combines it with the plaintext, usually by exclusive or. And that is where the one-time pad sits: a keystream as long as the message, truly random, never reused.

The classical ciphers of this block are neither, strictly. A monoalphabetic substitution operates on one letter at a time, which makes it look like a stream cipher, and its keystream is constant, which is exactly why it is weak.

Modes of operation

A block cipher enciphers one block. A message is many blocks, and how they are chained is the mode.

Electronic codebook. Encipher each block independently. And this is the mode nobody should use, because identical plaintext blocks give identical ciphertext blocks, so the structure of the plaintext shows through. It is the monoalphabetic substitution problem of [Substitution Systems] at the level of blocks.

Cipher block chaining. Combine each plaintext block with the previous ciphertext block before enciphering. Identical plaintext blocks now give different ciphertext, because the previous block differs. Requires an initialisation vector for the first block.

munotes.in345

Symmetric Encryption

Counter mode. Encipher a counter and combine the result with the plaintext, turning a block cipher into a stream cipher. Blocks can be enciphered in any order and in parallel.

The level this paper needs is that the mode matters as much as the cipher, and that electronic codebook leaks structure. A question is unlikely to go further.

The key distribution problem

The problem. Both parties need the key before they can communicate securely, and the key cannot be sent over the channel they are trying to protect.

The classical answer. Arrange it in person, in advance. That is what the Arthaśāstra's prearranged signs require: [Secret Communication: What the Text Actually Says] notes that a sign system must be agreed before any message exists.

Worked, and the arithmetic is the reason it does not scale. For n parties who must each be able to talk privately to every other, the number of keys is n times n minus 1, over 2.

PartiesKeys needed
21
510
1045
1004,950
1,000499,500

A hundred parties need 4,950 keys, every one of which must be distributed securely and kept secret, and adding one more party needs a hundred new keys. That is why symmetric cryptography alone cannot serve an open network, and it is the problem asymmetric cryptography was invented to solve.

And the modern arrangement is both. A key is agreed using asymmetric cryptography, and then the traffic is enciphered with a symmetric cipher, because symmetric ciphers are far faster. Asymmetric for the key, symmetric for the data.

Kerckhoffs's principle

The statement. A cryptographic system should remain secure even if everything about it except the key is public knowledge.

Why it matters. A method can be reverse-engineered, leaked or deduced; a key can be changed. Security resting on a secret method is security that cannot be repaired.

And it bears on the Arthaśāstra directly. The text names gūḍhalekhya and gives no method, so whatever the method was, its secrecy was part of the protection. A system whose method is secret has no way to recover when the method is discovered, and that is a design criticism that can be made without knowing what the method was.

What symmetric encryption does NOT provide

Not authentication. A message deciphering correctly shows that the sender had the key, and if the key is shared by two parties it does not say which of them sent it. And an attacker who can alter ciphertext can often alter the plaintext predictably.

Not integrity. Encipherment does not detect alteration. That needs a separate mechanism, as [Information Protection Mechanisms] sets out.

munotes.in346

Symmetric Encryption

Not non-repudiation. Since both parties hold the same key, neither can prove the other sent something.

Three properties missing, and all three are why modern protocols use authenticated encryption, which combines a cipher with an integrity mechanism rather than relying on the cipher alone.

Quick revision

  • Symmetric: one key both ways. Every cipher in this block is symmetric, and so was the Arthaśāstra's, whatever it was.
  • Block ciphers operate on fixed-size blocks and need padding; stream ciphers operate on a bit or byte at a time and do not.
  • Modes: electronic codebook leaks structure and should not be used; cipher block chaining hides it at the cost of an initialisation vector; counter mode turns a block cipher into a stream cipher.
  • Key distribution: n parties need n(n-1)/2 keys, so a hundred parties need 4,950.
  • Modern practice: asymmetric cryptography to agree the key, symmetric to encipher the data.
  • Kerckhoffs: security should rest on the key alone, because a method cannot be changed once discovered.
  • Encipherment provides confidentiality only, not authentication, integrity or non-repudiation.

Test yourself

1. Define a symmetric cipher and give the key distribution arithmetic for ten parties.

One in which the same key enciphers and deciphers. Ten parties who must each communicate privately with every other need ten times nine over two, which is 45 keys.

2. Why should electronic codebook mode not be used?

Because each block is enciphered independently, so identical plaintext blocks produce identical ciphertext blocks and the structure of the plaintext shows through the ciphertext, which is the monoalphabetic substitution weakness at the level of blocks.

3. State Kerckhoffs's principle and apply it to the Arthaśāstra.

A system should remain secure even if everything about it except the key is public. The Arthaśāstra names cipher-writing without giving a method, so the method's secrecy was evidently part of the protection, and a system of that kind cannot be repaired when the method becomes known.

4. Name three properties encipherment does not provide, and say what modern practice does about it.

Authentication, integrity and non-repudiation. Modern protocols use authenticated encryption, combining a cipher with a separate integrity mechanism, rather than relying on the cipher alone.

munotes.in347

The rest of this subject

These notes are cut from the University's printed syllabus. Open the syllabus itself for the same subject.

Issue
Done!