UNIT 2: Data Security - Comprehensive Short Notes
I. CRYPTOGRAPHIC FOUNDATIONS
A. Core Encryption Principles
Symmetric vs. Asymmetric Cryptography
| Feature | Symmetric Cryptography | Asymmetric Cryptography |
|---|---|---|
| Key Usage | Same key for encryption & decryption | Public key for encryption, private key for decryption |
| Speed | Fast (hardware efficient) | Slow (computationally intensive) |
| Key Distribution | Major challenge (secure channel needed) | Easy (public key can be shared openly) |
| Examples | AES, DES, RC4 | RSA, ECC, Diffie-Hellman |
| Primary Use | Bulk data encryption | Key exchange, digital signatures |
[!TIP] Exam Focus: Symmetric is fast but key distribution is hard. Asymmetric solves distribution but is slow. Often used together (e.g., TLS uses asymmetric to exchange a symmetric session key).
Block Ciphers vs. Stream Ciphers
| Feature | Block Ciphers | Stream Ciphers |
|---|---|---|
| Unit Size | Fixed-size blocks (e.g., 128 bits) | Continuous stream of bits/bytes |
| Operation | Encrypts entire block at once | Encrypts one bit/byte at a time |
| Error Propagation | One block error can corrupt entire block | Error affects only corresponding plaintext bit |
| Examples | AES, DES, 3DES | RC4, ChaCha20 |
| Use Case | File/disk encryption, databases | Real-time communication (TLS, WEP/WPA) |
Cipher Block Modes of Operation
Used to encrypt data larger than block size, prevent pattern leakage.
| Mode | How it Works | Merits | Demerits |
|---|---|---|---|
| ECB<br>(Electronic Codebook) | Each block encrypted independently | Simple, parallelizable | Identical plaintext blocks → identical ciphertext (pattern leakage) |
| CBC<br>(Cipher Block Chaining) | XOR current plaintext block with previous ciphertext block | Hides patterns, widely used | Sequential (not parallel), requires IV, error propagation |
| CFB<br>(Cipher Feedback) | Turns block cipher into stream cipher; XOR feedback from ciphertext | No padding needed, can handle partial blocks | Sequential, error propagation |
| OFB<br>(Output Feedback) | Generates keystream independent of plaintext/ciphertext; XOR with plaintext | No error propagation, can precompute keystream | If keystream repeats → catastrophic failure |
| CTR<br>(Counter) | Encrypts counter value, XOR with plaintext; counter increments | Parallelizable, random access, no padding | Requires unique counter for each block (nonce reuse = disaster) |
[!TIP] Common Pitfall: Never reuse a nonce/counter in CTR mode. It completely breaks confidentiality.
B. Symmetric Key Algorithms
Advanced Encryption Standard (AES)
-
Block Size: 128 bits
-
Key Sizes: 128, 192, 256 bits → 10, 12, 14 rounds respectively
-
Structure: Substitution-Permutation Network (SPN)
-
Round Operations (per round except last):
-
SubBytes (non-linear substitution via S-box)
-
ShiftRows (permutation: shift rows cyclically)
-
MixColumns (mixing columns via matrix multiplication)
-
AddRoundKey (XOR with round key)
-
-
Final Round: No MixColumns.
-
Key Expansion: Round keys derived from initial key via Rijndael's key schedule.
Example (Conceptual):
Plaintext block = 00112233445566778899aabbccddeeff (128-bit)
Key = 000102030405060708090a0b0c0d0e0f (128-bit)
After 10 rounds of transformations → ciphertext.
RC4 Stream Cipher
-
Type: Variable key-size stream cipher (8-bit operations).
-
Components:
-
KSA (Key Scheduling Algorithm): Initialize S-box (256 bytes) using key.
-
PRGA (Pseudo-Random Generation Algorithm): Generate keystream bytes from S-box.
-
-
KSA Steps:
-
Initialize S:
S[i] = ifor i=0..255. -
j = 0 -
For
i = 0to 255:-
j = (j + S[i] + key[i mod keylen]) mod 256 -
Swap
S[i]andS[j]
-
-
-
PRGA Steps:
-
i = (i + 1) mod 256 -
j = (j + S[i]) mod 256 -
Swap
S[i]andS[j] -
t = (S[i] + S[j]) mod 256 -
Keystream byte =
S[t]
-
-
Encryption:
Ciphertext[i] = Plaintext[i] XOR Keystream[i]
[!TIP] RC4 5-bit Key Example:
Key =
[1, 2, 3, 4, 5](5 bytes, but RC4 uses 8-bit bytes; for 5-bit, we'd mask to 5 bits).
Simplified 5-bit variant (illustrative):
- S-box size = 32 (2^5).
- KSA:
S = [0..31],j=0. Fori=0..31:j = (j + S[i] + key[i mod 5]) mod 32, swap.
- PRGA: similar with mod 32.
Generate first 3 keystream bytes after KSA.
In exam, show KSA table swaps and first 3 PRGA iterations.
C. Asymmetric Key Algorithms
RSA Algorithm (Rivest–Shamir–Adleman)
-
Mathematical Foundation: Difficulty of factoring large integers.
-
Key Generation:
-
Choose large primes
p,q. -
Compute
n = p * q. -
Compute
φ(n) = (p-1)(q-1). -
Choose
esuch that1 < e < φ(n)andgcd(e, φ(n)) = 1. -
Compute
dsuch thatd * e ≡ 1 mod φ(n)(using Extended Euclidean Algorithm). -
Public Key:
(e, n), Private Key:(d, n).
-
-
Encryption:
C = M^e mod n -
Decryption:
M = C^d mod n
Worked Example (p=3, q=11):
n = 3 * 11 = 33
φ(n) = (3-1)(11-1) = 2*10 = 20
- Choose
e=7(gcd(7,20)=1)
- Compute
d:7d ≡ 1 mod 20→d=3(since 7*3=21 ≡1 mod20)
- Public Key:
(7, 33), Private Key:(3, 33)
- Encrypt
M=2:C = 2^7 mod 33 = 128 mod 33 = 29
- Decrypt
C=29:M = 29^3 mod 33 = 24389 mod 33 = 2✓
Public Key Cryptography Principles
-
One-way Function: Easy to compute
f(x), hard to invertf⁻¹(y). -
Trapdoor Function: One-way function with secret "trapdoor" (private key) allowing easy inversion.
-
Key Distribution: Public keys can be shared openly via certificates (PKI) or web of trust (PGP).
D. Classical Ciphers (Application-Based)
Caesar Cipher
-
Type: Substitution cipher.
-
Encryption:
C = (P + k) mod 26, whereP= plaintext letter index (A=0),k= shift. -
Decryption:
P = (C - k) mod 26 -
Example Decryption:
Ciphertext:
ZICVTWQNGRZGVTWAVZHCQYGLMGJShift
k = 17Decrypt each letter:
Z(25) →(25 - 17) mod 26 = 8→II(8) →(8 - 17) mod 26 = 17→R... continue for all letters.
Result:
I HOPE YOU ARE WELL AND GOOD HEALTH(with spaces inserted).
[!TIP] Exam Step: Always convert letters to 0-25 indices, apply formula, convert back. Show at least 3-4 letter conversions.
II. AUTHENTICATION & INTEGRITY
A. Hash Functions & Message Digests
Cryptographic Hash Functions Properties
-
Pre-image Resistance: Given hash
h, hard to find anymsuch thathash(m)=h. -
Second Pre-image Resistance: Given
m1, hard to findm2≠m1with same hash. -
Collision Resistance: Hard to find any two distinct messages
m1, m2withhash(m1)=hash(m2). -
Deterministic: Same input → same output.
-
Fixed Output Size: e.g., SHA-512 → 512-bit digest.
-
Avalanche Effect: Small change in input → large change in output.
SHA-512 Algorithm Steps
-
Preprocessing:
-
Append
1bit, then0bits, then 128-bit message length (in bits). -
Result length ≡ 1024 mod 1024 (multiple of 1024-bit block).
-
-
Parsing: Break message into 1024-bit blocks
M¹, M², .... -
Initialize Hash Values (H⁰): Eight 64-bit constants from square roots of first 8 primes.
-
For each block:
-
Prepare 80-word message schedule
W[0..79]from block. -
Initialize working variables
a..hwith current hash value. -
For
t=0..79:T1 = h + Σ1(e) + Ch(e,f,g) + K[t] + W[t] T2 = Σ0(a) + Maj(a,b,c) h = g; g = f; f = e; e = d + T1; d = c; c = b; b = a; a = T1 + T2 -
Update hash:
H[i] = H[i-1] + variable[i]for i=0..7.
-
-
Output: Concatenate final
H⁷as 512-bit digest.
[!TIP] SHA-512 Order for Same Digest: Finding collisions is computationally infeasible (birthday attack requires ~2²⁵⁶ operations). Pre-image attack requires ~2⁵¹² operations.
B. Message Authentication Codes (MACs)
MAC Definition: A short tag generated from a message and a secret key, providing integrity and authentication.
HMAC (Hash-based MAC) Construction
-
Uses a cryptographic hash function
H(e.g., SHA-256). -
Formula:
HMAC(K, m) = H( (K⁺ ⊕ opad) ∥ H( (K⁺ ⊕ ipad) ∥ m ) )where:
-
K⁺= key padded/truncated to hash block size. -
ipad= 0x36 repeated,opad= 0x5C repeated. -
∥= concatenation.
-
-
Steps:
-
Pad key to block size
B(e.g., 64 bytes for SHA-256). -
Compute inner hash:
inner = H( (K⁺ ⊕ ipad) ∥ m ). -
Compute outer hash:
HMAC = H( (K⁺ ⊕ opad) ∥ inner ).
-
Comparison Table
| Feature | Plain Hash | MAC | Digital Signature |
|---|---|---|---|
| Key Used | No | Yes (symmetric) | Yes (asymmetric) |
| Provides | Integrity only | Integrity + Authentication | Integrity + Authentication + Non-repudiation |
| Verification | Anyone can compute | Requires shared secret | Anyone with public key can verify |
| Example | SHA-256 | HMAC-SHA256 | RSA-PSS, ECDSA |
C. Digital Signatures
Mechanism using Public-Key Cryptography
-
Signing:
-
Sender computes hash of message:
h = hash(m). -
Encrypt hash with private key:
sig = h^d mod n(RSA) or generate signature via ECDSA algorithm.
-
-
Verification:
-
Receiver decrypts signature with public key:
h' = sig^e mod n. -
Compute hash of received message:
h = hash(m). -
If
h' == h, signature valid.
-
Importance in Secure Communication
-
Authentication: Confirms sender identity.
-
Integrity: Any change in message invalidates signature.
-
Non-repudiation: Sender cannot deny sending (only they possess private key).
-
Used in code signing, contracts, SSL/TLS certificates.
Digital Signature Standards (DSS)
-
NIST standard: DSA (Digital Signature Algorithm) based on discrete logarithm problem.
-
Later standards: RSA-PSS, ECDSA (Elliptic Curve DSA).
III. KEY MANAGEMENT & PROTOCOLS
A. PGP (Pretty Good Privacy)
Architecture & Services
-
Confidentiality: Hybrid encryption (session key encrypted with recipient's public key).
-
Authentication: Digital signatures using sender's private key.
-
Compression: Applied before encryption (ZIP).
-
Email Integration: Works with MIME.
PGP Message Format
[Signature] (optional)
[Session Key] (encrypted with recipient's public key)
[Encrypted Data] (compressed message encrypted with session key)
DiagramCANVAS: PGP message block structure showing signature, encrypted session key, and encrypted data sections
Operations Workflow
-
Sending:
-
Generate random session key.
-
Compress message.
-
Encrypt compressed message with session key (symmetric, e.g., AES or IDEA).
-
Encrypt session key with recipient's public key.
-
Optionally sign message hash with sender's private key.
-
Combine into PGP message.
-
-
Receiving:
-
Decrypt session key with own private key.
-
Decrypt message with session key.
-
Decompress.
-
Verify signature if present using sender's public key.
-
B. SSL/TLS Protocol Suite
SSL Record Protocol Services
-
Confidentiality: Symmetric encryption (AES, 3DES).
-
Integrity: MAC (HMAC) or AEAD.
-
Authentication: Optional via certificates (X.509).
SSL Handshake Protocol (Step-by-Step)
-
Client Hello: Client sends supported cipher suites, TLS version, random
R_C. -
Server Hello: Server chooses cipher suite, sends TLS version, random
R_S, certificate. -
Key Exchange:
-
If RSA: Client generates premaster secret, encrypts with server's public key, sends.
-
If Diffie-Hellman: Server sends DH parameters, signed.
-
-
Finished:
-
Both compute master secret from premaster +
R_C+R_S. -
Derive session keys (client/server write keys, MAC keys).
-
Exchange
Finishedmessages encrypted with session keys.
-
SSL Connection vs. SSL Session
| SSL Session | SSL Connection | |
|---|---|---|
| Definition | Negotiated security parameters (keys, cipher suite) | Actual data transfer association |
| Lifetime | Longer (can be reused) | Shorter (per connection) |
| Components | Session ID, peer cert, cipher spec, master secret | Read/Write keys, sequence numbers |
| Reuse | Yes (session resumption) | No (new connection) |
| Role in Web | Reduces handshake cost for repeated visits | Each HTTP request/response may use new connection |
[!TIP] Exam Distinction: Session = negotiated state (can be reused). Connection = active data flow (uses session keys).
C. IPSec (IP Security)
Goals & Services
-
Confidentiality: ESP encryption.
-
Data Integrity: AH/ESP authentication.
-
Authentication: AH/ESP.
-
Anti-replay: Sequence numbers + sliding window.
Security Associations (SA)
-
Definition: Unidirectional logical connection providing security services.
-
Parameters: SPI (Security Parameter Index), IP destination address, security protocol (AH/ESP), mode, keys.
-
Management: Manual or via IKE (Internet Key Exchange).
Authentication Header (AH)
-
Provides integrity and authentication (no encryption).
-
Transport Mode: AH protects IP payload (and selected header fields) but not IP header. Used end-to-end.
-
Tunnel Mode: AH protects entire original IP packet + new IP header. Used for gateways.
Encapsulating Security Payload (ESP)
-
Provides confidentiality, integrity, authentication.
-
Transport Mode: ESP trailer encrypts payload, authenticates payload + ESP header (but not outer IP header).
-
Tunnel Mode: Entire original IP packet encrypted and authenticated, encapsulated in new IP packet.
DiagramCANVAS: IPSec transport vs tunnel mode showing original packet, ESP/AH trailer, new IP header
D. SET (Secure Electronic Transaction)
Protocol Goals
-
Confidentiality: Payment info encrypted (only bank sees).
-
Integrity: All messages authenticated.
-
Cardholder Authentication: Via digital signature.
-
Merchant Authentication: Via certificate.
-
No merchant sees card number (critical for trust).
Participants & Roles
| Participant | Role |
|---|---|
| Cardholder | Customer with credit card |
| Merchant | Seller |
| Issuer | Bank that issued card |
| Acquirer | Merchant's bank |
| Payment Gateway | Processes payments for merchant |
| Certification Authority (CA) | Issues digital certificates |
SET Transaction Flow with Dual Signature
-
Cardholder obtains certificates (from CA, Issuer).
-
Order Info (OI) + Payment Info (PI) created.
-
Dual Signature:
Sig = Sign(Priv_C, hash(OI) ∥ hash(PI)). Links OI and PI without revealing each to other parties. -
Cardholder sends:
-
OI (encrypted with merchant's public key)
-
PI (encrypted with payment gateway's public key)
-
Dual signature (both can verify)
-
-
Merchant sees OI, verifies dual signature, forwards PI to gateway.
-
Gateway decrypts PI, verifies dual signature, processes payment.
DiagramCANVAS: SET transaction showing dual signature linking OI and PI, separate encryption paths
IV. NETWORK SECURITY INFRASTRUCTURE
A. Firewalls
Classification & Types
| Type | Operation | Example | Advantages | Disadvantages |
|---|---|---|---|---|
| Packet Filtering | Examines packet headers (IP, port) against rule set. Stateless. | iptables |
Fast, transparent | No payload inspection, spoofable |
| Circuit-Level Gateway | Monitors TCP handshake; creates virtual circuit. | SOCKS proxy | Hides internal IP, stateful for sessions | No payload inspection |
| Application-Level Gateway (Proxy) | Intercepts & inspects application-layer data. Acts as intermediary. | HTTP proxy, FTP proxy | Deep inspection, authentication | Slow, per-application |
| Stateful Inspection | Tracks connection state (TCP flags, sequence). Combines packet filtering with state table. | Modern firewalls | Better security than stateless | Resource-intensive |
| Personal Firewall | Host-based, controls apps' network access. | Windows Defender Firewall | Protects single host | Not for network perimeter |
Firewall Merits & Demerits
-
Merits: First line of defense, access control, logging, network segmentation.
-
Demerits: Cannot stop internal threats, encrypted traffic bypass, misconfiguration risks, single point of failure.
Firewall vs. Trusted Operating System
| Aspect | Firewall | Trusted OS |
|---|---|---|
| Security Model | Network perimeter (external threats) | Mandatory Access Control (internal subjects/objects) |
| Enforcement | Packet filtering, proxies | Security kernel, reference monitor |
| Focus | Traffic filtering | Information flow control |
| Example | iptables, Cisco ASA | SELinux, Trusted Solaris |
B. Intrusion Detection Systems (IDS)
Intrusion Definition: Unauthorized access or misuse of system/resources.
Network-Based IDS (NIDS) Architecture
DiagramSEARCH: network-based IDS architecture diagram showing sensors, management server, database
-
Sensors: Capture packets (promiscuous mode).
-
Management Server: Analyzes data, generates alerts.
-
Database: Stores events, signatures.
-
Operation: Sensors → Management → Alert/Log.
Host-Based IDS (HIDS)
-
Installed on individual hosts.
-
Monitors system logs, file integrity (Tripwire), process behavior.
-
Example: OSSEC, Wazuh.
IDS vs. Firewalls
| Feature | Firewall | IDS |
|---|---|---|
| Action | Prevent (block traffic) | Detect & alert (passive) |
| Placement | Network perimeter | Network or host |
| Focus | Known bad (blacklist) | Anomaly/signature detection |
| Response | Active (drop packets) | Passive (log, alarm) |
Parameter Pattern Matching
-
Detection technique: Compare packet headers/payloads against signature database.
-
Example: Snort rules matching specific byte patterns.
-
Limitation: Only detects known attacks; evadable via polymorphism.
C. Malware Defense
Types of Malicious Software
| Type | Behavior | Propagation |
|---|---|---|
| Virus | Attaches to executable, requires user action | Human-mediated |
| Worm | Self-replicating, exploits vulnerabilities | Network-based |
| Trojan | Disguised as legitimate software | Social engineering |
| Ransomware | Encrypts files, demands ransom | Phishing, exploits |
| Spyware | stealthy monitoring | Bundled software |
| Rootkit | Hides presence, deep system access | Exploits, social engineering |
| Bot | Turns host into zombie (botnet) | Worm/virus |
Role of IDS and Firewalls
-
Firewalls: Block malicious traffic (ports, IPs), prevent worm propagation.
-
IDS: Detect malware communication (C&C traffic), file integrity changes (HIDS), anomaly patterns.
-
Combined: Firewall blocks known bad; IDS alerts on suspicious activity that bypasses firewall.
V. WIRELESS & MOBILE SECURITY
A. Wireless LAN (WLAN) Security
Security Challenges
-
Open medium → eavesdropping easy.
-
Rogue access points.
-
Weak default configurations.
-
Jamming/DoS.
-
Client misassociation.
WLAN Protocol Stack & MPDU Format
DiagramSEARCH: 802.11 MAC frame structure MPDU showing frame control, duration, addresses, sequence control, payload, FCS
-
MPDU (MAC Protocol Data Unit):
-
Frame Control (type, subtype, flags)
-
Duration
-
Addresses (up to 4)
-
Sequence Control
-
Payload (LLC data)
-
FCS (CRC)
-
Access Point Security in Public Networks
-
Risks: Evil twin attacks, eavesdropping, captive portal bypass.
-
Mitigations:
-
WPA2-Enterprise: 802.1X with EAP (e.g., PEAP, EAP-TLS). Individual user auth.
-
Captive Portals: Web-based auth, but traffic not encrypted (use HTTPS).
-
Client Isolation: Prevent inter-client communication.
-
Rogue AP Detection: Wireless IDS/IPS.
-
B. Wireless Application Protocol (WAP) Security
WAP Architecture
DiagramSEARCH: WAP architecture diagram showing mobile device, WAP gateway, web server
-
Client: WAP-enabled phone.
-
WAP Gateway: Protocol conversion (WSP/WTLS → HTTP/SSL), content adaptation.
-
Web Server: Origin server.
WTLS (Wireless Transport Layer Security)
-
Analogy to SSL/TLS but optimized for wireless:
-
Smaller packet sizes (avoid fragmentation).
-
Faster handshake (optional client cert).
-
Supports datagram (UDP-like) via record layer.
-
-
Role: Provides confidentiality, integrity, authentication between mobile device and gateway.
-
Limitations:
-
Weak cryptography (early versions allowed export-grade RSA).
-
Gateway terminates WTLS → gap in end-to-end security (gateway sees plaintext).
-
Short certificates (for small devices).
-
Security Issues in WTLS
-
End-to-End Gap: Gateway decrypts, may re-encrypt with SSL → server sees gateway as client.
-
Weak Ciphers: Early WTLS allowed 40-bit RC2.
-
Certificate Handling: Limited storage on devices → often gateway stores certs.
-
Version Vulnerabilities: WTLS 1.0 had flaws (like SSL 2.0).
VI. APPLICATION & ADVANCED TOPICS
A. Virtual Private Networks (VPN)
Definition & Core Concept
-
VPN: Extends private network across public infrastructure via tunneling and encryption.
-
Tunneling: Encapsulating packets within other packets.
-
Encryption: Confidentiality (IPsec, SSL).
Types of VPNs
| Type | Use Case | Typical Technology |
|---|---|---|
| Remote Access VPN | Individual user to corporate network | SSL VPN, PPTP, L2TP/IPsec |
| Site-to-Site VPN | Connect two networks (e.g., branch offices) | IPsec (tunnel mode), GRE over IPsec |
VPN Technologies
-
PPTP: Point-to-Point Tunneling Protocol. Weak encryption (MPPE), vulnerable.
-
L2TP/IPsec: L2TP for tunneling, IPsec for encryption/authentication. More secure than PPTP.
-
SSL VPN: Uses HTTPS (TCP 443). No client software (browser-based). Granular access control.
B. Biometric & Smart Card Authentication
Biometric Authentication
-
Methods: Fingerprint, iris, face, voice, vein.
-
Process:
-
Enrollment: Capture biometric, extract features → template (stored).
-
Verification/Identification: Capture live sample, compare to template via matching algorithm.
-
-
Advantages: Hard to forget/lose, non-transferable.
-
Challenges: False accepts/rejects, template theft, privacy concerns, cost.
Smart Cards
-
Physical: Plastic card with embedded chip (contact or contactless).
-
Logical Security: Stores certificates, private keys (often in secure element).
-
Authentication Mechanism:
-
Something you have (card) + something you know (PIN) → two-factor.
-
Card performs cryptographic operations (private key never leaves card).
-
-
Types: Memory cards, microprocessor cards (e.g., EMV, government ID).
C. Web Traffic Security Approaches
| Approach | Layer | How it Works | Typical Use |
|---|---|---|---|
| SSL/TLS | Application (HTTPS) | End-to-end encryption between client & server | Web browsing, email (IMAPS) |
| IPsec | Network | Encrypts entire IP packet (transport/tunnel mode) | Site-to-site VPN, remote access |
| Application-Layer Gateway | Application | Proxy inspects & filters application data (e.g., HTTP proxy) | Content filtering, authentication |
Contextual Application:
-
SSL/TLS: When you need end-to-end security between client and server (e.g., online banking).
-
IPsec: When securing network-to-network traffic (e.g., connecting branch offices) or all traffic from a remote user.
-
Application Gateway: When you need deep inspection (e.g., blocking malicious web content, enforcing authentication).
[!TIP] Exam Comparison: SSL/TLS secures specific application (port 443). IPsec secures all IP traffic (transparent to apps). Gateway acts as intermediary for specific protocols.