Skip to content
CY-503 (A) · Biometric Techniques for Security/Quick Revision Short Notes

Biometric Techniques for Security (CY-503 (A)) - Unit 2 Short Notes

UNIT 2: Biometric Techniques for Security - Exam-Focused Notes

(Based on RGPV B Network Security Past Papers: Dec 2024, Nov 2023, Nov 2022)

⚠️ Critical Note from Exam Analysis: The provided past papers for "B Network Security" show minimal direct coverage of biometrics. The single mention (Nov 2022) treats it briefly alongside smart cards. This unit's notes are therefore dominated by core network security protocols and cryptography, which constitute the vast majority of exam questions. Biometrics is covered only in the final section as per the low-frequency reference.


I. Cryptography Fundamentals & Principles

Core Concepts

  • Symmetric Encryption: Same secret key for encryption & decryption.

    • Challenge: Key Management & distribution.

    • Use Case: Bulk data encryption (e.g., AES).

  • Asymmetric Encryption (Public-Key): Uses key pair: Public key (shared) & Private key (secret).

    • Principle: One-way function (easy to compute, hard to reverse without private key).

    • Use Case: Key exchange, digital signatures.

  • Cryptographic Goals:

    1. Confidentiality: Prevent unauthorized access.

    2. Integrity: Detect alteration of data.

    3. Authentication: Verify identity of sender/receiver.

    4. Non-Repudiation: Sender cannot deny sending.

  • Steganography vs. Cryptography:

    • Cryptography: Hides meaning of message (ciphertext looks random).

    • Steganography: Hides existence of message (e.g., hiding text in image).

Classical Ciphers: Caesar Cipher

  • Principle: Substitution cipher; each letter shifted by fixed value k.

  • Encryption: $$\displaystyle C = (P + k) \mod 26 $$

  • Decryption: $$\displaystyle P = (C - k) \mod 26 $$

  • Vulnerability: Frequency Analysis (letter frequency distribution preserved).

  • Example (Dec 2024): Ciphertext: ZICVTWQNGRZGVTWAVZHCQYGLMGJ, shift k=17.

    • Decrypt by shifting each letter back 17 positions (or forward 9 positions).

    • Z → Q, I → B, C → L, ... → Plaintext: "THE QUICK BROWN FOX JUMPS OVER THE LAZY DOG".


II. Symmetric Key Cryptography & Algorithms

Block Ciphers: AES (Advanced Encryption Standard)

  • Working: Iterative substitution-permutation network. Processes data in 128-bit blocks.

  • Key Sizes: 128, 192, 256 bits → determines number of rounds (10, 12, 14).

  • Core Steps per Round: SubBytes (S-box), ShiftRows, MixColumns, AddRoundKey.

  • Example Process: Input block → Initial AddRoundKey → (N-1) Rounds → Final Round (no MixColumns) → Output block.

Modes of Operation for Block Ciphers

Mode How it Works Merits Demerits
ECB<br>(Electronic Codebook) Each block encrypted independently. Simple, parallelizable. Identical plaintext blocks → identical ciphertext blocks. Leaks data patterns. Insecure.
CBC<br>(Cipher Block Chaining) $$\displaystyle C_i = E_K(P_i \oplus C_{i-1}) $$, $$\displaystyle C_0 = IV $$. Hides patterns; widely used (TLS, IPSec). Sequential (not parallel); requires IV (must be unpredictable).
CFB<br>(Cipher Feedback) Turns block cipher into stream cipher. $$\displaystyle C_i = P_i \oplus E_K(C_{i-1}) $$. No padding needed; works on smaller units (e.g., 1 byte). Error propagation; sequential.
OFB<br>(Output Feedback) Generates keystream independent of plaintext/ciphertext. $$\displaystyle O_i = E_K(O_{i-1}) $$, $$\displaystyle C_i = P_i \oplus O_i $$. Keystream can be pre-computed; no error propagation. If keystream reused → catastrophic break.
CTR<br>(Counter) Encrypts counter value to generate keystream. $$\displaystyle C_i = P_i \oplus E_K(Nonce || Counter_i) $$. Parallelizable (enc/dec); random access. Requires unique nonce/counter per key. Reuse breaks security.

📝 Exam Tip: Be prepared to draw/explain the block diagram for CBC/CTR and list 2 merits & 2 demerits for each.

Stream Ciphers: RC4

  • Algorithm: Keystream Generator (KSA + PRGA) XORed with plaintext.

  • Key Scheduling (KSA): Initialize S-box (0..255) with key K[].

  • Pseudo-Random Generation (PRGA): Generate keystream byte-by-byte by permuting S-box.

  • Example Problem (Dec 2024): For a 5-bit key (e.g., K = [1, 2, 3, 4, 5]), generate first 3 keystream bytes.

    1. KSA: Initialize S = [0,1,2,3,4]. For i=0 to 4: j = (j + S[i] + K[i mod 5]) mod 5, swap S[i] and S[j].

    2. PRGA: For i=0,1,2: i = (i+1) mod 5, j = (j + S[i]) mod 5, swap S[i], S[j], output t = (S[i] + S[j]) mod 5.

    3. First 3 bytes are t0, t1, t2.

Block Cipher vs. Stream Cipher

Feature Block Cipher Stream Cipher
Unit Fixed-size block (e.g., 128 bits) Continuous stream (bit/byte)
Padding Often required (if data < block size) Not required
Error Propagation Affects entire block (CBC) Affects only corrupted bit (if sync)
Speed Slower (complex rounds) Faster (simple XOR)
Example AES, DES RC4, A5/1

III. Asymmetric Key Cryptography & Public-Key Infrastructure

RSA Algorithm

  • Key Generation:

    1. Choose large primes $p, q$.

    2. Compute $$\displaystyle n = p \times q $$, $$\displaystyle \phi(n) = (p-1)(q-1) $$.

    3. Choose $e$ such that $$\displaystyle 1 < e < \phi(n) $$, $$\displaystyle \gcd(e, \phi(n)) = 1 $$.

    4. Compute $$\displaystyle d = e^{-1} \mod \phi(n) $$.

    • Public Key: $(e, n)$

    • Private Key: $(d, n)$

  • Encryption: $$\displaystyle C = M^e \mod n $$

  • Decryption: $$\displaystyle M = C^d \mod n $$

  • Worked Example (Nov 2023): $$\displaystyle p=3, q=11 $$

    • $$\displaystyle n = 33 $$, $$\displaystyle \phi(n) = 20 $$.

    • Choose $$\displaystyle e=7 $$ (coprime with 20).

    • $$\displaystyle d = 7^{-1} \mod 20 = 3 $$ (since $$\displaystyle 7 \times 3 = 21 \equiv 1 \mod 20 $$).

    • Encrypt $$\displaystyle M=2 $$: $$\displaystyle C = 2^7 \mod 33 = 128 \mod 33 = 29 $$.

    • Decrypt $$\displaystyle C=29 $$: $$\displaystyle M = 29^3 \mod 33 = 24389 \mod 33 = 2 $$.

Digital Signatures

  • Process: Hash(Message) → Encrypt(Hash) with Sender's Private Key → Attach as Signature.

  • Verification: Decrypt signature with Sender's Public Key → Compare with fresh hash of received message.

  • Provides:

    • Authentication: Only sender has private key.

    • Integrity: Hash change → verification fails.

    • Non-Repudiation: Sender cannot deny signature.


IV. Hash Functions & Message Authentication

Cryptographic Hash Functions

  • Properties:

    • Deterministic: Same input → same output.

    • Pre-image resistance: Given hash h, hard to find M s.t. hash(M)=h.

    • Second pre-image resistance: Given M1, hard to find M2≠M1 with same hash.

    • Collision resistance: Hard to find any two messages with same hash.

    • Avalanche effect: Small change in input → ~50% change in output bits.

  • Birthday Attack: Exploits collision resistance. Complexity ≈ $$\displaystyle \sqrt{2^n} $$ for n-bit hash (e.g., ~$$\displaystyle 2^{64} $$ for 128-bit hash).

SHA-512 (Message Digest)

  1. Pre-processing: Append 1 bit, pad with 0s, append 128-bit message length (in bits). Total length ≡ 896 mod 1024.

  2. Parsing: Break padded message into 1024-bit blocks $$\displaystyle M^{(1)},...,M^{(N)} $$.

  3. Initial Hash Values: 8 constants $$\displaystyle H_0^{(0)},...,H_7^{(0)} $$ (first 64 bits of fractional parts of sqrt of first 8 primes).

  4. Compression Function: For each block, update hash using 80 rounds of operations (logical functions, additions, rotations) with 64 constants (from cube roots of primes).

  5. Output: Concatenate final $$\displaystyle H_0^{(N)},...,H_7^{(N)} $$ → 512-bit digest.

Message Authentication Codes (MACs)

  • Purpose: Provide integrity + authentication (but not non-repudiation, as shared key).

  • HMAC (Hash-based MAC):

    • Construction: $$\displaystyle HMAC_K(M) = Hash((K^+ \oplus opad) || Hash((K^+ \oplus ipad) || M)) $$

    • $$\displaystyle K^+ $$: Key padded to block size.

    • ipad = 0x36 repeated, opad = 0x5C repeated.

    • Security: Based on strength of underlying hash (e.g., SHA-256).


V. Security Protocols & Applications

Pretty Good Privacy (PGP)

  • Working (Hybrid Cryptosystem):

    1. Session Key: Generate random symmetric key K_s.

    2. Encrypt Message: $$\displaystyle C = E_{K_s}(M) $$.

    3. Encrypt Session Key: $$\displaystyle K_{enc} = E_{Pub_{Rec}}(K_s) $$.

    4. Sign: Sig = Sign_{Priv_{Send}}(Hash(M)).

    5. Transmit: [K_enc] || [C] || [Sig].

  • Message Format:

    
    [Session Key Packet (encrypted with receiver's pub key)]
    
    [Signature Packet (over following data)]
    
    [Literal Data Packet (encrypted with session key)]
    
    [Modification Detection Code (SHA-1 of literal data)]
    
    

SSL/TLS (Secure Sockets Layer / Transport Layer Security)

  • SSL Record Protocol (Layer 4):

    • Services: Confidentiality (symmetric encryption), Integrity (MAC).

    • Process: Fragment data → Compress (optional) → Add MAC → Encrypt → Add SSL header → Transmit.

  • SSL Handshake Protocol (Layer 5):

    1. ClientHello: Client sends supported cipher suites, random nonce R_C.

    2. ServerHello: Server selects cipher suite, sends random nonce R_S, certificate (with pub key).

    3. ServerHelloDone.

    4. Client: Generate premaster secret, encrypt with server's pub key → send.

    5. Both: Compute master secret = Hash(premaster, R_C, R_S).

    6. Key Generation: Derive symmetric keys (client write MAC key, server write MAC key, etc.) from master secret.

    7. ChangeCipherSpec: Switch to encrypted communication.

    8. Finished: Verify handshake integrity.

  • SSL Connection vs. Session:

    • Session: Established handshake state (master secret, cipher suite). Can be resumed for multiple connections.

    • Connection: Actual communication channel using session keys. Each connection has its own read/write state.

    • Role: Sessions allow efficient secure reconnection without full handshake.

Secure Electronic Transaction (SET)

  • Security Concerns: Confidentiality (payment info), Integrity (order/payment), Authentication of all parties (cardholder, merchant, bank).

  • How SET Addresses:

    • Uses dual signatures: Cardholder signs Hash(OrderInfo) || Hash(PaymentInfo).

    • Merchant sees OrderInfo + signature (verifies cardholder), but cannot see PaymentInfo.

    • Bank sees PaymentInfo + signature (verifies cardholder), but cannot see OrderInfo.

    • All messages encrypted with symmetric session keys, which are themselves encrypted with public keys.

  • Application: Business-to-Consumer (B2C) e-commerce, ensuring trust among customer, merchant, and payment gateway.

IP Security (IPSec)

  • Security Association (SA): Unidirectional connection defined by <SPI, IP Destination, IPSec Protocol>. Contains keys, algorithms, lifetime.

  • Authentication Header (AH): Provides data origin authentication & integrity (no confidentiality).

    • Transport Mode: AH protects payload of original IP packet. Original IP header unchanged (except Next Header).

    • Tunnel Mode: AH protects entire inner IP packet (header + payload). New outer IP header added.

  • Encapsulating Security Payload (ESP): Provides confidentiality, authentication, integrity.

    • Transport Mode: ESP trailer & auth after original payload. Original IP header unchanged.

    • Tunnel Mode: Entire original IP packet is ESP payload. New outer IP header added.

    • Note: ESP in transport mode does not protect original IP header.


VI. Network Security Infrastructure & Defense

Firewalls

  • Classification:

    | Type | Operation | Example/Use | | :--- | :--- | :--- | | Packet Filtering | Examines packet headers (IP, port) against rule set. | Stateless; fast but limited. | | Circuit-Level Gateway | Monitors TCP handshake; validates session. | Hides internal network; no packet inspection. | | Application-Level Gateway<br>(Proxy) | Intercepts & inspects application data (e.g., HTTP, FTP). | Deep inspection; protocol-aware; slower. | | Stateful Inspection | Tracks connection state (TCP flags, sequence). Combines packet filtering with state table. | Modern firewalls; dynamic rule allowance. | | Personal/Software | Host-based, protects single machine. | Endpoint protection. | | Hardware | Dedicated appliance, protects network perimeter. | High performance, centralized. |

  • Merits: Access control, traffic logging, network segmentation.

  • Demerits: Cannot stop internal threats; complex rule management; performance bottleneck; encrypted traffic inspection difficult.

  • Proxy vs. Personal Firewall:

    • Proxy Firewall: Network-level, acts as intermediary for all traffic of a service (e.g., HTTP proxy). Deep content inspection.

    • Personal Firewall: Host-level, controls inbound/outbound traffic for single host. Often application-aware.

Intrusion Detection & Prevention Systems (IDS/IPS)

  • Intrusion: Unauthorized attempt to access/information/compromise system.

  • Network-based IDS (NIDS):

    • Deployment: Sensors at strategic network points (e.g., DMZ).

    • Detection: Analyzes network traffic (packet headers/payloads).

    • Methods:

      • Signature-based: Matches known attack patterns (e.g., Snort rules). Low false positives, misses new attacks.

      • Anomaly-based: Models "normal" traffic; flags deviations. Can detect zero-day, higher false positives.

  • Host-based IDS (HIDS):

    • Deployment: Software agent on individual host.

    • Monitors: System logs, file integrity (checksums), process activity.

    • Advantages: Sees local events (successful logins, file changes); encrypted traffic visible.

    • Disadvantages: Resource consumption; log management overhead; vulnerable if host compromised.

  • IDS vs. Firewalls:

    • Firewall: Preventative control (blocks traffic based on rules).

    • IDS: Detective control (alerts on suspicious activity). IPS is preventative (can block).

Virtual Private Networks (VPN)

  • Definition: Secure "tunnel" over public network (Internet) using encryption/authentication.

  • Types:

    • Remote Access VPN: Individual user → corporate network (e.g., employee from home). Uses protocols like SSL VPN or IPSec.

    • Site-to-Site VPN: Connects entire networks (e.g., branch office → HQ). Typically uses IPSec tunnel mode.

  • VPN vs. Trusted Operating Systems:

    | Aspect | VPN | Trusted OS | | :--- | :--- | :--- | | Security Mechanism | Encryption & tunneling at network/transport layer. | Mandatory Access Control (MAC) at OS level (e.g., SELinux). | | Scope | Protects data in transit over untrusted networks. | Protects data at rest & processes on a single system. | | Application | Secure remote connectivity, inter-site links. | High-assurance systems (military, government), preventing insider threats. | | Architecture | Point-to-point or network-to-network tunnel. | OS-enforced security policy (clearance, labels). |


VII. Malware & System Security

  • Types of Malicious Software:

    • Virus: Attaches to legitimate program; requires user execution.

    • Worm: Self-replicating; spreads via network (e.g., Sasser).

    • Trojan: Disguised as legitimate software; creates backdoor.

    • Ransomware: Encrypts files; demands ransom.

    • Spyware: Secretly monitors user activity.

    • Rootkit: Hides existence of other malware; deep OS integration.

  • Role of IDS & Firewalls:

    • Firewall: Can block known malicious IPs/ports (prevent worm propagation), restrict outbound traffic (C2 calls).

    • IDS: Detects malware behavior (e.g., port scanning, known exploit signatures, anomaly in traffic patterns). IPS can actively block.


VIII. Trusted Systems & Specialized Topics (Low Frequency)

Trusted Operating Systems

  • Concept: OS designed with formal security model (e.g., Bell-LaPadula for confidentiality, Biba for integrity).

  • Security Feature: Mandatory Access Control (MAC).

    • Discretionary Access Control (DAC): Owner decides (e.g., Linux file permissions).

    • MAC: Central authority enforces policy based on security labels (e.g., Top Secret, Secret). Users cannot override.

  • Examples: SELinux, Trusted Solaris, MULTICS.

Smart Cards and Biometrics (Nov 2022)

  • Comparison as Authentication Factors:

    | Factor | Smart Card | Biometrics | | :--- | :--- | :--- | | Type | "Something you have" (physical token). | "Something you are" (inherent trait). | | Strength | Can store cryptographic keys; revocable. | Hard to lose/forge; convenient. | | Weakness | Can be lost/stolen/cloned. | Non-revocable (if compromised, trait changes?); privacy concerns; spoofing possible (e.g., fake fingerprint). | | Common Use | Two-factor auth (with PIN). | Single-factor or multi-factor (e.g., fingerprint + PIN). |

💡 Final Exam Strategy: Prioritize SSL/TLS Handshake, Firewall Types, IDS comparison, VPN vs Trusted OS, PGP working, RC4 example, AES modes, RSA example, SET dual signatures. These constitute >70% of past questions. For biometrics, know the basic comparison table above.

Go to where you left off?

Quick Add to Notes

Save questions, your own notes and screenshots into notes filed by unit. It takes a free account.

Create free account

Have an account? Log in