BLOGGER TEMPLATES AND TWITTER BACKGROUNDS »

Monday, October 26, 2009

Lec6:Security in Applications

Electronic Mail Security

• E-mail – what it is and how it works.

• E-mail security threats.

• Secure e-mail standards and products - PGP and S/MIME.


E-mail – what it is and how it works

• What is an e-mail?

An e-mail is a message made up of a string of ASCII characters in a format specified by RFC 822

• Two parts, separated by blank line:

The header: sender, recipient, date, subject, delivery path,…

The body: containing the actual message content.

Example

From:zaki.masud@utem.edu.my

To: mothman@utem.edu.my

Cc: shahrinsahib@utem.edu.my

Subject: RFC 822 example

Date: Fri, 25 Aug 2008 13:58:49

This is just a test message to illustrate RFC 822. It’s not very long and it’s not very exciting. But you get the point.


Security provided in E-mail

• Confidentiality

• Data origin authentication

• Message integrity

• Non-repudiation of origin

• Key management


MIME = Multipurpose Internet Mail Extensions

Extends the capabilities of RFC 822 to allow e-mail to carry non-textual content, non-ASCII character sets, long messages.

Uses extra header fields in RFC 822 e-mails to specify form and content of extensions.

Supports a variety of content types, but e-mail still ASCII-coded for compatibility.

Specified in RFCs 2045-2049.


Example of MIME message

From: j.bloggs@rhul.ac.uk

To: Kenny.Paterson@rhul.ac.uk

Subject: That document

Date: Wed, 13 Nov 2002 19:55:47 -0000

MIME-Version: 1.0

Content-Type: multipart/mixed; boundary="---next part"

------next part

Content-Type: text/plain; charset="iso-8859-1"

Content-Transfer-Encoding: 7bit

Kenny, here’s that document I said I’d send. Regards, Joe

------next part

Content-Type: application/x-zip-compressed; name=“report.zip"

Content-Transfer-Encoding: base64

Content-Disposition: attachment; filename= “report.zip"

rfvbnj756tbGHUSISyuhssia9982372SHHS3717277vsgGJ77JS77HFyt6GS8

------next part—


How E-mails Transported?


MUA: Mail User Agent (Mail Client)

MTA: Mail Transport Agent (Mail Server)




E-mail Security Threats

• Two main group:

Threats to the security of e-mail itself

Threats to an organisation that are enabled by the use of e-mail.

• Loss of confidentiality.

E-mails are sent in clear over open networks.

E-mails stored on potentially insecure clients and mail servers.

Ensuring confidentiality may be important for e-mails sent within an organisation.

• Loss of integrity.

No integrity protection on e-mails; body can be altered in transit or on mail server.

• Lack of data origin authentication.

Is this e-mail really from the person named in the From: field?

How many Kenny.Paterson’s are there?

Recall SMTP directly over telnet allows forgery of all e-mail fields!

E-mail could also be altered in transit.

Even if the From: field looks fine, who was logged in as Kenny.Paterson when the e-mail was composed?

Sharing of e-mail passwords common.

• Lack of non-repudiation.

Can I rely and act on the content? (integrity)

If so, can the sender later deny having sent it? Who is liable if I have acted?

Example of stock-trading via e-mail.

• Lack of notification of receipt.

Has the intended recipient received my e-mail and acted on it?

A message locally marked as ‘sent’ may not have been delivered.


Threats Enabled by E-mail

Disclosure of sensitive information

It’s easier to distribute information by e-mail than it is by paper and snail mail.

Disclosure may be deliberate (and malicious) or unintentional.

Disclosure may be internal or external (e-mail crosses LANs as well as the Internet).

Disclosure may be of personal, inappropriate, commercially sensitive or proprietary information.

Can lead to loss of reputation and ultimately dismissal of staff.


S/MIME

• Originated from RSA Data Security Inc. in 1995.

• Further development by IETF S/MIME working group at:

www.ietf.org/html.charters/smime-charter.html.

• Version 3 specified in RFCs 2630-2634.

• Allows flexible client-client security through encryption and signatures.

• Widely supported, e.g. in Microsoft Outlook, Netscape Messenger, Lotus Notes.


PGP

• PGP=“Pretty Good Privacy”

• First released in 1991, developed by Phil Zimmerman, provoked export control and patent infringement controversy.

• Freeware: OpenPGP and variants:

www.openpgp.org, www.gnupg.org

• Commercial: formerly Network Associates International, now PGP Corporation at www.pgp.com

• OpenPGP specified in RFC 2440 and defined by IETF OpenPGP working group.

www.ietf.org/html.charters/openpgp-charter.html

• Available as plug-in for popular e-mail clients, can also be used as stand-alone software.

• Functionality similar to S/MIME:

encryption for confidentiality.

signature for non-repudiation/authenticity.

• One level of processing only, so less flexible than S/MIME.

• Sign before encrypt, so signatures on unencrypted data.

Sigs can be detached and stored separately.

• PGP-processed data is base64 encoded and carried inside RFC822 message body.


Web Security


• Web security includes:

Security of server

Security of client

Network traffic security between a browser and a server

• SSL/TLS

• SSH

• SET


SSL/TLS

SSL/TLS widely used in Web browsers and servers to support ‘secure e-commerce’ over HTTP.

Built into Microsoft IE, Netscape, Mozilla, Apache, IIS

The (in)famous browser lock.

SSL architecture provides two layers:

SSL Record Protocol

Provides secure, reliable channel to upper layer.

Upper layer carrying:

SSL Handshake Protocol, Change Cipher Spec. Protocol, Alert Protocol, HTTP, any other application protocols.


SSL/TLS Applications

• Secure e-commerce using SSL/TLS.

• Client authentication not needed until client decides to buy something.

• SSL provides secure channel for sending credit card information, personal details, etc.

• Client authenticated using credit card information, merchant bears (most of) risk.

• Very successful (amazon.com, on-line supermarkets, airlines,…)

• Secure e-commerce: some issues.

No guarantees about what happens to client data (including credit card details) after session: may be stored on insecure server.

Does client understand meaning of certificate expiry and other security warnings?

Does client software actually check complete certificate chain?

Does the name in certificate match the URL of e-commerce site? Does the user check this?

Is the site the one the client thinks it is?

Is the client software proposing appropriate ciphersuites?


SSH – Secure Shell


Initially designed to replace insecure rsh, telnet utilities.

Secure remote administration (mostly of Unix systems).

Extended to support secure file transfer and e-mail.

Latterly, provide a general secure channel for network applications.

SSH-1 flawed, SSH-2 better security (and different architecture).


• SSH provides security at Application layer.

Only covers traffic explicitly protected.

Applications need modification, but port-forwarding eases some of this (see later).

Built on top of TCP, reliable transport layer protocol.


SSH Applications


• Anonymous ftp for software updates, patches...

No client authentication needed, but clients want to be sure of origin and integrity of software.


• Secure ftp.

E.g.upload of webpages to webserver using sftp.

Server now needs to authenticate clients.

Username and password may be sufficient, transmitted over secure SSH transport layer protocol.

• Secure remote administration.

SysAdmin (client) sets up terminal on remote machine.

SysAdmin password protected by SSH transport layer protocol.

SysAdmin commands protected by SSH connection protocol.

• Guerilla Virtual Private Network.

E.g. use SSH + port forwarding to secure e-mail communications.


SET


• SET = an open encryption and security specification designed to protect credit card transactions on the internet

• Use SSL to secure the communication links

• Main requirements

Confidentiality of payment and ordering information

Integrity of all transmitted data

Authentication of cardholder

Authentication of merchant




SET Security Issues


• Two pairs of PKs per entity

One pair for signing

One pair for exchanging keys

• Assumes full PKI is available

Including revocation

• Merchant does not see payment instrument used


How the Web Works – HTTP

• Hypertext transfer protocol (http).

• Clients request “documents” (or scripts) through URL.

• Server response with “documents”.

• Documents are not interpreted by http.

• Stateless protocol, request are independent.


Web Vulnerabilities


• http://www.w3.org/Security/Faq

• Revealing private information on server

• Intercept of client information

• Execute unauthorized programs

• Denial of service


How to Secure the Web

• Authentication:

Basic (username, password)

Can be used along with cookie

Digest

• Access control via addresses

• Multi-layered:

S-http (secure http), just for http

Proposed by CommerceNet, pretty much dead

SSL (TLS), generic for TCP

https: http over SSL

IPSec


HTTP Authentication – Basic


• Client doesn’t know which method

• Client attempts access (GET, PUT, …) normally

• Server returns

“401 unauthorized”

Realm: protection space

• Client tries again with (user:password)

Passwords in the clear

Repeated for each access


From Basic Authentication to Forms and Cookies


• Not all sites use basic authentication

• Many instead ask the user to type username/password into a HTML form

• Server looks up the user and sends back a cookie

• The browser (client) resends the cookie on subsequent requests


HTTP Access Control - Digest


• Server sends www-authenticate parameters:

Realm

Domain

Nonce, new for each 401 response

E.G. H(client-IP:timestamp:server-secret)

Algorithm

E.G., MD5

• Client sends authorization response:

Same nonce

H(A1), where a1=user:realm:password, and other information

Steal H(A1)

Only good for realm


HTTPS


• HTTPS = Secure Hypertext Transfer Protocol

• HTTPS is a communications protocol designed to transfer encrypted information between computers over the World Wide Web (WWW)

• Essentially an implementation of HTTP

• Commonly used Internet protocol using an SSL

• Used to enable online purchasing or the exchange of private information and resources over insecure networks


Why HTTPS combines with SSL and How?


• HTTPS combines with SSL to enable secure communication between a client and a server

• Steps:

Client requests a secure transaction and informs the encryption algorithms and key sizes that it support (by assessing a URL with HTTPS)

Server sends the requested server certificate (encrypted server’s public key, list of supported ciphers and key sizes in order of priority)

Client then generates a new secret symmetric session key based on the priority list sent by the server. Client compares the certificate issued by CA and confirmed that certificate is belongs to the server intended for communication

If valid and certificate confirmed, client encrypts a copy of the new session key it generated with the server public key obtained from the certificate. Then, client sends the new encrypted key to server

Server decrypts the new session key with its own private key.

Upon completed, both client and server have the same secret session key and use to secure communication and data transport.


Secure File Transfer Protocol (S/FTP)


• S/FTP is an interactive file transfer program

• Similar to ftp

• Performs all operations over an encrypted ssh transport

• Use many features of ssh such as public key authentication and compression

• S/FTP connects and logs into the specified host, then enters an interactive command mode


END OF LECTURE 6


Review Question ( Lab 6 )

1. Discuss the potential perpetrators that can threaten Network security and it goal for attacking network services.

In general network security can been said as a prevention from nosy people from getting data they are not authorized or worse yet, modify messages intended for other recipients. It is concerned with people trying to access remote services that are not authorized to use. Most problems are intentionally caused by malicious people trying to gain some benefit or bring harm to someone else.

2. Network security problems can be divided roughly into FOUR (4) intertwined areas, List and explain in details each area.

· Secrecy, also called confidentiality, has to do with keeping information out of the hands of unauthorized users. It protects against disclosure of information to entities not authorized to have that information. Entities might be people or organization.

· Authentication deals with determining whom you are talking to before revealing sensitive information or entering into a business deal.

· Non-Repudiation deals with signatures. It protects user against the threat that the value or existence of the data might be changed in a way inconsistent with the recognized security policy.

· Integrity control how can you be sure that a message you received was really the one sent and not something that a malicious adversary modified in transit.

3. What is the significance difference between the wireshark output in Task 1 and Task 2; explain in detail the function of IPSec in Task 2?

During Task 1, wireshark successful captured both username and password in File Transfer Protocol (FTP). Username = ‘administrator’ and Password = ‘abc123’. But all these things not happen in Task 2, this is because both username and password are already encrypted even the data are captured. This is because in the Task 2, we using IPSec to secure FTP Transaction. IPSec is one of the solutions to safeguard the transmission of data over FTP from being seen by an unauthorized user. It will protect the information from being manipulated.

4. What is the benefit of using IPSec?

IPSec is typically used to attain confidentiality, integrity, and authentication in the transport of data across insecure channels. Though it's original purpose was to secure traffic across public networks, it's implementations are often used to increase the security of private networks as well, since organizations cannot always be sure if weaknesses in their own private networks are susceptible to exploitation. If implemented properly, IPSec provides a private channel for sending and exchanging vulnerable data whether the data is email, ftp traffic, news feeds, partner and supply chain data, medical records, or any other type of TCP/IP based data.

5. Explain what are AH and ESP in IPSec protocol suite?

· Authentication Header (AH): ties data in each packet to a verifiable signature (similar to PGP email signatures) that allows you to verify both the identity of the person sending the data and that the data has not been altered.

· Encapsulation Payload (ESP): scrambles the data (and even certain sensitive IP addresses) in each packet using hard core encryption. So a sniffer somewhere on the network doesn’t get anything usable.

6. Explain in detail how to enable IPSec option in a Linux environment.

There are different methods in order to enable IPSec in Linux platform. One of the simplest methods to is installing and enables a program named ipsec-tools. IPSec-tools is a package that based on Kame Project’s OpenBSD tools. The newest stable versions 0.72 that can be download at

http://sourceforge.net/projects/ipsec-tools/files/ipsec-tools/0.7.2/.

Methods of Installation:

1) Firstly download ipsec-tools-0.7.2.tar.gz or other version of ipsec-tools from http://sourceforge.net/projects/ipsec-tools/files/ . After download, saves the file on any folder in hard drive and open the terminal and targeted the folder where the ipsec-tools is saved.

2) Make sure that the current user have privilage as root. Switch user to root with “#su root” and includes the password in order to access root account.

3) Extract the file by using command “# tar zxf ipsec-tools-x.y.z.tar.gz” with the x.y.z as the version of the ipsec tools. Example: “# tar zxf ipsec-tools-0.7.2.tar.gz”

4) Next, target the terminal to ipsec-tools-x.y.z (x.y.z = version of ipsec-tools) by using “# cd (location of ipsec-tools folder)”

5) Proceed to install ipsec-tools by using command:

# ./configure --prefix=/usr --sysconfdir=/etc

# make

# make install


6) Wait until installation of ipsec-tools complete

7) For Ubuntu user, user can automatically download and install ipsec-tools by using “sudo apt-get install ipsec-tools” command

Writing the configuration file:

1) Before running ipsec-tools, configuration file must be writing first. The configuration should be name as /etc/ipsec.conf

2) Below is the example of ipsec.conf:

# Configuration for 192.168.1.100

# Flush the SAD and SPD

flush;

spdflush;

# Attention: Use this keys only for testing purposes!

# Generate your own keys!

# AH SAs using 128 bit long keys

add 192.168.1.100 192.168.2.100 ah 0x200 -A hmac-md5

0xc0291ff014dccdd03874d9e8e4cdf3e6;

add 192.168.2.100 192.168.1.100 ah 0x300 -A hmac-md5

0x96358c90783bbfa3d7b196ceabe0536b;

# Security policies

spdadd 192.168.1.100 192.168.2.100 any -P out ipsec

esp/transport//require

ah/transport//require;

spdadd 192.168.2.100 192.168.1.100 any -P in ipsec

esp/transport//require

ah/transport//require;


3) For the example configuration above, the configuration are made for host that using 192.168.1.100 address that interconnect with host that use 192.168.2.100 address. The configuration implements MD5 type encryption that uses 0xc0291ff014dccdd03874d9e8e4cdf3e6 key for connection from 192.168.1.100 to 192.168.2.100 and using 0x96358c90783bbfa3d7b196ceabe0536b key from incoming connection from 192.168.2.100 to 192.168.1.100. Make notes that, the key above are for experiment purposed, make sure that user generated other key for actual use. Next, user need to add security policy that allows outgoing and incoming connection by using #spdadd command.

4) After finish writing configuration, make sure that user change access control of the configuration file in order to been unreadable by other person by using #chmod command. For save use, “chmod 750 ipsec-tools.conf” which allowing full control for owner and only read and execute access for group use while the other should not be able to see the configuration file.

Enabling the IPSec-tools program

1) After finishing writing the configuration, user can enable the IPSec-tools which following the configuration file by using “# setkey -f /etc/ipsec.conf” commands.

2) User also can enable permanently the ipsec-tools by adding “/usr/sbin/setkey -f /etc/ipsec.conf” on /etc/rc.d/rc.local file

7. Are there any other methods to secure FTP connection other than using IPSec? (List at least 3 methods)

i. SQL Server Integration Services)

ii. SFTP (secure FTP with SSH2 protocol)

iii. FTPS (FTP over SSL) site


Lab 5: Web Application Security

WHAT IS WEB APPLICATION SECURITY??

Web application or simply called webapp is an application that can be accessed using a web browser over a network, either the Internet or within the Local Area Network. It is developed using browser-supported language such as HTML, JavaScript, PHP, ASP and etc. The script produced is then rendered by common web browser. Web application let user to access application or system anywhere and at any time provided the user is connected to a network connection and there is a web browser installed on the machine. This ease of usage makes webapp popular among Internet user. Moreover the ability to update and maintain web applications without distributing and installing software on potentially thousands of client computers contribute to the popularity of the webapp. Nowadays webapp is used for accessing mail, online banking, online shopping, online reservation, wikis and many other functions.

An increase in the usage of web applications is directly related to an increase in the number of security incidents for them. Even though the server is patch with the latest version of the software, the network are installed with the latest firewall system and Intrusion detection system is deployed to monitor the network, if the web application itself is lack of security features the vital information stored in its content is still expose to intrusion. A Web application system should be carefully and safely develop because it is the first line of defense, any fault or flaws in it development stage, the server configuration and even the scripting used in it development can bring a major loop hole that can be manipulated by intruder to be used as the backdoor to the entire network.

WebGoat and WebScarab

WebGoat = Simulation toolkit used to demonstrate how we can exploit the vulnerabilities of a poorly design web application.

WebScarab = Tool for everyone who need to expose the working of an HTTP(S) based application, whether to allow the developer to debug otherwise difficult problems, or to allow a security specialist to identify vulnerabilities in the way that application has been designed or implemented.

Web Application Hacking simulation using WebGoat and WebScarab


Step 1: Copy the WebGoat-OWASP_Standard-5.2.zip and extract it to the C:\ drive.
Step 2: Open the C:\ WebGoat-5.2 folder and open the webgoat.bat to start the apache tomcat J2EE.

Step 3:Open an IE 6.0 web browser or a firefox web browser and type http://localhost/WebGoat/attack.

Step 4: Login as User Name: guest Password: guest

Step 5: Open webscarab-selfcontained-20070504-1631.jar

Step 6: If the WebScarab does not open do install the JDK module (jdk-6u4-windows-i586-p.exe) to your computer.

Step 7: Once the WebScarab started, you should see the interface as figure 5.4

Step 8: Next Configure the Web browser proxy starting so that it listen to 127.0.0.1 (localhost) port 8008.

Step 9: Go to WebScarab and click on the intercept tab and enable the intercept request checkbox but disable the intercept response checkbox. This will enable the intercept features of the WebScarab in which it will intercept any request signal from the web browser.

Step 10: Close your previous web browser, open it again and type in http://localhost/WebGoat/attack.

Step 11: WebScarab will intercept your request to visit the website by prompting an Edit request window as depicted in figure 5.6. This prompted window shows the request data that you send to the web server.

Step12: The text field indicated by the arrow shows the text field containing the data you send to the web server and it can be modified.(in some of the following task you need to modified the content of the text field to help you solve the problem in lesson.

Step13: For this task do not changes the text field value just click the [Accept changes] button to view the WebGoat main page.

Step 14: Each time you click on a submit button or a link on the webpage, the Edit request window will always appear, so make sure you click on Accept changes button to view your request page display on the browser.


Getting started with WebGoat and WebScarab

Step 1: Click on [Start WebGoat]

Step 2: Click on the Introduction | How to work with WebGoat menu.

Step 3: Read and follow the instruction given in the WebGoat.


XSS Attack

Step 1: Click on the Cross Site Scripting (XSS) | Phising with XSS menu

Step 2: Apply the script below to the text field in order to create a false login page so that you can harvest the username and password keyed in by the user.

Step 3: Once you hit the Search button you will see a comment page containing a place for you to login. This login page is created using the java script above.

Step 4: Try login in with any username and password; if this is a real phishing website you would not get the prompted message on your screen but the value you supplied might be send across the world to a server that gather the login information.

Step 5: Next click on the Cross Site Scripting (XSS) | Reflected XSS Attacks menu.

Step 6: In this lesson some prevention mechanism has been build in the script, some field have a validation toward the character you supplied. It will reject any tag symbol you used, however there are still some that is not protected. By using the script below find which the text field that can be exploited using XSS attack?



Injection Flaws

Step 1: Click on the Injection Flaws | Numeric SQL Injection menu, refer figure 5.10.

Step 2: From the combo list choose a weather station and click the [Go!] button, (Do not forget to click on the accept changes button of the edit request windows) you will get the information for the country you select.

Step 3: To apply the Injection flaws you need to choose a new country and click [Go!] button. Before clicking the [Accept changes] button on the edit request windows, in the [URLEncoded] tab, add the value station variable with

Step 4: Once the value is changed, click [Accept changes] button. The entire data is displayed on the screen. This shows that by manipulating the input field that is not properly design we can display the entire data in the database.

Step 5: Repeat this task on the Injection Flaws | String SQL Injection. Use the right input for this problem and compare the result. (Hint: The input should be a string).


Malicious File Execution

Step 1: Click on the Injection Flaws | Command Injection menu, refer figure 5.14.


Step2: By choosing the lesson plan to view and clicking on [View] button, user will be shown the content of the lesson. This exercise will manipulate the input field by adding the input with a command line instruction.

Step 3: Select a new lesson and click [View]. Before clicking the [Accept changes] button add the following command to your HelpFile variable value


Step 4: Once you click the [Accept changes] button the following output will be displayed on the screen.


Lec 5:SECURITY IN NETWORK

Definition

A computing network is a computing environment with more than one independent processors.
May be multiple users per system. Distance between computing systems is not considered (a communications media problem) Size of computing systems is not relevant.


What is a Network can Provide?

~ Logical interface function

~ Sending messages

~ Receiving messages

~ Executing program

~ Obtaining status information

~ Obtaining status information on other network users and their status

Type of Network

One way to categorize the different types of computer network designs is by their scope or scale. For historical reasons, the networking industry refers to nearly every type of design as some kind of area network. Common examples of area network types are:

  • LAN - Local Area Network
  • WLAN - Wireless Local Area Network
  • WAN - Wide Area Network
  • MAN - Metropolitan Area Network
  • SAN - Storage Area Network, System Area Network, Server Area Network, or sometimes Small Area Network


Three Network Topologies

The network topology describes the method used to do the physical wiring of the network. The main ones are bus, star, and ring.

  1. Bus - Both ends of the network must be terminated with a terminator. A barrel connector can be used to extend it.
  2. Star - All devices revolve around a central hub, which is what controls the network communications, and can communicate with other hubs. Range limits are about 100 meters from the hub.
  3. Ring - Devices are connected from one to another, as in a ring. A data token is used to grant permission for each computer to communicate.

There are also hybrid networks including a star-bus hybrid, star-ring network, and mesh networks with connections between various computers on the network. Mesh networks ideally allow each computer to have a direct connection to each of the other computers. The topology this documentation deals with most is star topology since that is what ethernet networks use.

Who Couse Security Problem

Ã’
Ã’~Hacker
Ã’~Spy
Ã’~Student
Ã’~Businessman
Ã’~Ex-employee
Ã’~Stockbroker
Ã’~Terrorist

Network Security Control

Ã’~Encryption
Ã’~Strong Authentication
Ã’~IPSec,VPN,SSH
Ã’~Kerberos
Ã’~Firewall
Ã’~Intrusion Detection System (IDS)
Ã’~Intrusion Prevention System (IPS)
Ã’~Honeypot

Encryption

Encryption is the most effective way to achieve data security . To read an encrypted file, you must have access to a secret key or password that enables you to decrypt it. Unencrypted data is called plain text; encrypt data is referred to as cipher text


Hacking And Preventation

Ã’~motivated by thrill of access and status
É @hacking community a strong meritocracy
É @status is determined by level of competence
Ã’~benign intruders might be tolerable
É @do consume resources and may slow performance
É @can’t know in advance whether benign or malign
Ã’~IDS / IPS / VPNs can help counter
Ã’~awareness led to establishment of CERTs
É @collect / disseminate vulnerability info / responses

Covering Track

Ã’~Every activity is logged
~Syslog, accesslog, eventlog,





AUTHENTICATION & ACCES CONTROL

AUTHENTICATION


  • Verification of identity of someone who generated some data.
  • Relates to identity verification.

  • classifications of identity verification:
    #by something known e.g. password
    #by something possessed e.g. smart card, passport
    #by physical characteristics (biometrics) e.g. finger prints, palm prints, retina, voice
    #by a result of involuntary action : signature



  • Requirements – must be able to verify that:
    ¤Message came from apparent source or author
    ¤Contents have not been altered
    ¤Sometimes, it was sent at a certain time or sequence



  • Protection against active attack (falsification of data and transactions)



PASSWORD


¨Protection of passwords
¤Don’t keep your password to anybody
¤Don’t write or login your password at everywhere
¤Etc.
¨Choosing a good password
¤Criteria:
-Hard to guess and easy to remember
¤Characteristics of a good password
-Not shorter than six characters
-Not patterns from the keyboard
-Etc.
¨Calculations on password
¤Password population, N =rs
¤Probability of guessing a password = 1/N
¤Probability of success, P=nt/N


***Support for password compliance reporting and strong authentication
-OneSign gives organizations a variety of powerful tools for password authentication, including:
*Automated password generation and changes, including the ability to generate strong random passwords on behalf of end-users.
*Self-service password reset - enabling users to securely reset their own passwords.
*Password authentication policy implementation.
*Built-in support for strong authentication options such as fingerprint biometrics, smart cards. proximity cards, USB tokens, and more.
*Pre-built and customized reports that track password authentication and access and provide data on who accessed what, how, when, and from where
*Audit logs of access and password change activity, delivering the information IT departments need to enhance and enforce compliance across the enterprise.
*Support for end-user workflow including shared workstations and fast user switching.


***Techniques for guessing passwords***
-Try default passwords.
-Try all short words, 1 to 3 characters long.
-Try all the words in an electronic dictionary(60,000).
-Collect information about the user’s hobbies, family names, birthday, etc.
-Try user’s phone number, social security number, street address, etc.
-Try all license plate numbers
-Use a Trojan horse
-Tap the line between a remote user and the host system.



BIOMETRIC


¨The term is derived from the Greek words bio (= life) and metric (= to measure)
¨Biometrics is the measurement and statistical analysis of biological data
¨In IT, biometrics refers to technologies for measuring and analysing human body characteristics for authentication purposes
¨Definition by Biometrics Consortium – automatically recognising a person using distinguishing traits

#How does it works?
¨Each person is unique
¨What are the distinguishing traits that make each person unique?
¨How can these traits be measured?
¨How different are the measurements of these distinguishing traits for different people


#Biometric Technologies
¤
Fingerprint biometrics – fingerprint recognition
¤
Eye biometrics – iris and retinal scanning
¤Face biometrics –
face recognition using visible or infrared light (called facial thermography)
¤Hand geometry biometrics – also
finger geometry
¤Signature biometrics – signature recognition
¤Voice biometrics –
speaker recognition

#Classification of biometric methods
¨Static
¤Fingerprint recognition
¤Retinal scan
¤Iris scan
¤Hand geometry
¨Dynamic
¤Signature recognition
¤Speaker recognition
¤Keystroke dynamics

#Biometric system architecture
¤Data collection
¤Signal processing
¤Matching
¤Decision
¤Storage
¤Transmission



#Biometric system model







ACCES CONTROL


¨“The prevention of unauthorized use of a resource, including the prevention of use of a resource in an unauthorized manner“
¤central element of computer security
¤assume have users and groups
nauthenticate to systemassigned access rights to certain resources on system







Requirements
¨reliable input
¨fine and coarse specifications
¨least privilege
¨separation of duty
¨open and closed policies
¨policy combinations, conflict resolution
¨administrative policies




Elements
¨subject - entity that can access objects
¤a process representing user/application
¤often have 3 classes: owner, group, world
¨• object - access controlled resource
¤e.g. files, directories, records, programs etc
¤number/type depend on environment
¨• access right - way in which subject accesses an object
¤e.g. read, write, execute, delete, create, search

Friday, September 25, 2009

LEC 3 MODERN CRIPTOGRAPHY

1.0 - Introduction:

Cryptography is the science of devising methods that allow information to be sent in a secure form in such a way that the only person able to retrieve this information is the intended recipient.

The basic principle is this: A message being sent is known as plaintext. The message is then coded using a cryptographic algorithm . This process is called encryption (see Fig. 1). An encrypted message is known as ciphertext, and is turned back into plaintext by the process of decryption.

fig1.gif

Fig. 1

It must be assumed that any eavesdropper has access to all communications between the sender and the recipient. A method of encryption is only secure if even with this complete access, the eavesdropper is still unable to recover the original plaintext from the ciphertext.

There is a big difference between security and obscurity. If a message is left for somebody in an airport locker, and the details of the airport and the locker number is known only by the intended recipient, then this message is not secure, merely obscure. If however, all potential eavesdroppers know the exact location of the locker, and they still cannot open the locker and access the message, then this message is secure.

In the last few decades cryptographic algorithms, being mathematical by nature, have become sufficiently advanced that they can only be handled by computers. This in effect means that plaintext is binary in form, and can therefore be anything; a picture, a voice, an e-mail or even a video - it makes no difference, a string of binary can represent any of these. This paper discusses all cryptography from a binary standpoint.


2.0- Cryptographic algorithms

The actual mathematical function used to encrypt and decrypt messages is called a cryptographic algorithm or cipher. This is only part of the system used to send and receive secure messages. This will become clearer further on when specific systems are discussed in detail.

2.1 - Restricted algorithms

If, as with most historical ciphers, the security of the message being sent relies on the algorithm itself remaining secret, then that algorithm is known as a restricted algorithm. These have a number of fundamental drawbacks (Ref. 3).
  • The algorithm obviously has to be restricted to only those people that you want to be able to decode your message. Therefore a new algorithm must be invented for every discrete group of users.
  • A large or changing group of users cannot utilise them, as every time one user leaves the group, everyone must change algorithm.
  • If the algorithm is compromised in any way, a new algorithm must be implemented.

2.2 - Key-based algorithms

Practically all modern cryptographic systems make use of a key. Algorithms that use a key system allow all details of the algorithm to be widely available. This is because all of the security lies in the key. With a key-based algorithm the plaintext is encrypted and decrypted by the algorithm which uses a certain key, and the resulting ciphertext is dependant on the key, and not the algorithm. This means that an eavesdropper can have a complete copy of the algorithm in use, but without the specific key used to encrypt that message it is useless.

2.2.1 - Symmetric Algorithms

Symmetric algorithms have one key that is used both to encrypt and decrypt the message, hence their name. In order for the recipient to decrypt the message they need to have an identical copy of the key. This presents one major problem; unless the recipient can meet the sender in person and obtain a key that way, then the key itself must be transmitted to the recipient and is thus susceptible to eavesdropping.

There are two types of symmetric algorithms. Stream ciphers operate on plaintext one bit at a time. Block ciphers operate on groups of bits called blocks which are generally 64 bits long.

Two symmetric algorithms, both block ciphers, are considered in this paper - the Data Encryption Standard (DES) and the International Data Encryption Algorithm (IDEA) .

2.2.2 - Public-Key Algorithms

Public-key algorithms are asymmetric, that is to say the key that is used to encrypt the message is different to the key used to decrypt the message. The encryption key, known as the public key is used to encrypt a message, but the message can only be decoded by the person that has the decryption key, known as the private key.

This type of algorithm has a number of advantages over traditional symmetric ciphers; it means that the recipient can make their public key widely available - anyone wanting to send them a message uses the algorithm and the recipient’s public key to do so. An eavesdropper may have both the algorithm and the public key, but will still not be able to decrypt the message. Only the recipient, with their private key can decrypt the message.

A disadvantage of public-key algorithms is that they are more computationally intensive than symmetric algorithms, and therefore encryption and decryption take longer. This may not be significant for a short text message, but certainly is for long messages or audio/video.

This paper describes the two public-key algorithms, the RSA algorithm , and the Pretty Good Privacy (PGP) hybrid algorithm .

2.3 - One Time Pads:

The one-time pad was invented by Major Joseph Mauborgne and Gilbert Bernam in 1917, and is an unconditionally secure (i.e. unbreakable) algorithm. The theory behind a one-time pad is simple. The pad is a non-repeating random string of letters. Each letter on the pad is used once only to encrypt one corresponding plaintext character. After use the pad must never be re-used. As long as the pad remains secure, so is the message. This is because a random key added to a non-random message produces completely random ciphertext, and there is absolutely no amount of analysis or computation that can alter that. If both pads are destroyed then the original message will never be recovered. There are two major drawbacks: Firstly, it is extremely hard to generate truly random numbers, and a pad that has even a couple of non-random properties is theoretically breakable. Secondly, because the pad can never be reused no matter how large it is, the length of the pad must be the same as the length of the message - fine for text, but virtually impossible for video.

2.4 - Steganography

Steganography is not actually a method of encrypting messages, but hiding them within something else to enable them to pass undetected. Traditionally this was achieved with invisible ink, microfilm or taking the first letter from each word of a message. This is now achieved by hiding the message within a graphics or sound file. For instance in a 256-greyscale image, if the least significant bit of each byte is replaced with a bit from the message then the result will be indistinguishable to the human eye (Ref. 1). An eavesdropper will not even realise a message is being sent. This is not cryptography however, and although it would fool a human, a computer would be able to detect this very quickly and reproduce the original message.

2.5 - Cryptanalysis

Cryptanalysis is the science (or black art!) of recovering the plaintext of a message from the ciphertext without access to the key. In cryptanalysis, it is always assumed that the cryptanalyst has full access to the algorithm. An attempted cryptanalysis is known as an attack, of which there are four major types:
  • Ciphertext-only: The only information the cryptanalyst has to work with is the ciphertext of various messages all encrypted with the same algorithm.
  • Known-plaintext: In this scenario, the cryptanalyst has access not only to the ciphertext of various messages, but also the corresponding plaintext as well.
  • Chosen-plaintext: The cryptanalyst has access to the same information as in a Known-plaintext attack, but this time may choose the plaintext that gets encrypted. This attack is more powerful, as specific plaintext blocks can be chosen that may yield more information about the key. An Adaptive-chosen- plaintext attack is merely one where the cryptanalyst may repeatedly encrypt plaintext, thereby modifying the input based on the results of a previous encryption.
  • Chosen-ciphertext: The cryptanalyst is able to repeatedly choose ciphertext to be decrypted, and has access to the resulting plaintext. From this they can try to deduce the key.
(Ref. 3)

2.6 - Algorithm security

There is only one totally secure algorithm, the one-time pad . All other algorithms can be broken given infinite time and resources. Modern cryptography relies on making it computationally unfeasible to break an algorithm; this means that whilst it is theoretically possible, the time-scale and resources involved make it completely unrealistic.

If an algorithm is presumed to be perfect, then the only method of breaking it relies on trying every possible key combination until the resulting ciphertext makes sense. This type of attack is called a brute-force attack. The field of parallel computing is perfectly suited to the task of brute force attacks, as every processor can be given a number of possible keys to try, and they do not need to interact with each other at all except to announce the result. A technique that is becoming increasingly popular is parallel processing using thousands of individual computers connected to the Internet. This is known as distributed computing.

However strong or weak the algorithm used to encrypt it, a message can be thought of as secure if the time and/or resources needed to recover the plaintext greatly exceed the benefits bestowed by having the contents. This could be because the cost involved is greater than the financial value of the message, or simply that by the time the plaintext is recovered the contents will be outdated.


3.0 - Operations used by algorithms

Although the methods of encryption/decryption have changed dramatically since the advent of computers, there are still only two basic operations that can be carried out on a piece of plaintext - substitution and transposition. The only real difference is that whereas before these were carried out with the alphabet, nowadays they are carried out on binary bits.

3.1 - Substitution

Substitution operations replace bits in the plaintext with other bits decided upon by the algorithm, to produce ciphertext. This substitution then just has to be reversed to produce plaintext from ciphertext. This can be made increasingly complicated. For instance one plaintext character could correspond to one of a number of ciphertext characters (homphonic substitution), or each character of plaintext is substituted by a character of corresponding position in a length of another text (running cipher).

3.2 - Transposition

Transposition (or permutation) does not alter any of the bits in plaintext, but instead move their positions around within it. If the resultant ciphertext is then put through more transpositions, the end result is increasingly secure.

3.3 - XOR

XOR is an exclusive-or operation. It is a Boolean operator such that if 1 of two bits is true, then so is the result, but if both are true or both are false then the result is false.

e.g.

0 XOR 0 = 0
1 XOR 0 = 1
0 XOR 1 = 1
1 XOR 1 = 0
A surprising amount of commercial software uses simple XOR functions to provide security, including the USA digital cellular telephone network and many office applications, and it is trivial to crack (Ref. 3). However the XOR operation, as will be seen later in this paper, is a vital part of many advanced cryptographic algorithms when performed between long blocks of bits that also undergo substitution and/or transposition.


4.0 - Algorithms in detail:

4.1 - DES

The US National Bureau of Standards (NSB) published the Data Encryption Standard in 1975. Created by IBM, DES came about due to a public request by the NSB requesting proposals for a standard cryptographic algorithm that satisfied the following criteria:
  • Provides a high level of security
  • The security depends on keys, not the secrecy of the algorithm
  • The security is capable of being evaluated
  • The algorithm is completely specified and easy to understand
  • It is efficient to use and adaptable
  • Must be available to all users
  • Must be exportable
DES has now been in world-wide use for over 20 years, and due to the fact that it is a defined standard means that any system implementing DES can communicate with any other system using it. DES is used in banks and businesses all over the world, as well as in networks (as Kerberos) and to protect the password file on UNIX Operating Systems (as CRYPT(3)).
The Algorithm:
DES is a symmetric, block-cipher algorithm with a key length of 64 bits, and a block size of 64 bits (i.e. the algorithm operates on successive 64 bit blocks of plaintext). Being symmetric, the same key is used for encryption and decryption, and DES also uses the same algorithm for encryption and decryption.

First a transposition is carried out according to a set table (the initial permutation), the 64-bit plaintext block is then split into two 32-bit blocks, and 16 identical operations called rounds are carried out on each half. The two halves are then joined back together, and the reverse of the initial permutation carried out. The purpose of the first transposition is not clear, as it does not affect the security of the algorithm, but is thought to be for the purpose of allowing plaintext and ciphertext to be loaded into 8-bit chips in byte-sized pieces (Ref. 3).

In any round, only one half of the original 64-bit block is operated on. The rounds alternate between the two halves.

One round in DES consists of:
Key transformation:
The 64-bit key is reduced to 56 by removing every eighth bit (these are sometimes used for error checking). Sixteen different 48-bit subkeys are then created - one for each round. This is achieved by splitting the 56-bit key into two halves, and then circularly shifting them left by 1 or 2 bits, depending on the round. After this, 48 of the bits are selected. Because they are shifted, different groups of key bits are used in each subkey. This process is called a compression permutation due to the transposition of the bits and the reduction of the overall size.
Expansion permutation:
After the key transformation, whichever half of the block is being operated on undergoes an expansion permutation. In this operation, the expansion and transposition are achieved simultaneously by allowing the 1st and 4th bits in each 4 bit block to appear twice in the output, i.e. the 4th input bit becomes the 5th and 7th output bits (see Fig. 2).

The expansion permutation achieves 3 things: Firstly it increases the size of the half-block from 32 bits to 48, the same no of bits as in the compressed key subset, which is important as the next operation is to XOR the two together. Secondly, it produces a longer string of data for the substitution operation that subsequently compresses it. Thirdly, and most importantly, because in the subsequent substitutions the 1st and 4th bits appear in two S-boxes (described shortly), they affect two substitutions. The effect of this is that the dependency of the output bits on the input bits increases rapidly, and so therefore does the security of the algorithm.

Fig. 2 - The Expansion Permutation.

XOR:
The resulting 48-bit block is then XORed with the appropriate subset key for that round.
Substitution:
The next operation is to perform substitutions on the expanded block. There are eight substitution boxes, called S-boxes. The first S-box operates on the first 6 bits of the 48-bit expanded block, the 2nd S-box on the next six, and so on. Each S-box operates from a table of 4 rows and 16 columns, each entry in the table is a 4-bit number. The 6-bit number the S-box takes as input is used to look up the appropriate entry in the table in the following way. The 1st and 6th bits are combined to form a 2-bit number corresponding to a row number, and the 2nd to 5th bits are combined to form a 4-bit number corresponding to a particular column. The net result of the substitution phase is eight 4-bit blocks that are then combined into a 32-bit block.

It is the non-linear relationship of the S-boxes that really provide DES with its security, all the other processes within the DES algorithm are linear, and as such relatively easy to analyse (Ref. 3).

Fig. 3 - The S-box substitution (adapted after Ref. 3)

Permutation:
The 32-bit output of the substitution phase then undergoes a straightforward transposition using a table sometimes known as the P-box.
Finally:
After all the rounds have been completed, the two ‘half-blocks’ of 32 bits are recombined to form a 64-bit output, the final permutation is performed on it, and the resulting 64-bit block is the DES encrypted ciphertext of the input plaintext block.
Reversal (decryption):
Decrypting DES (if you have the correct key!) is very easy. Thanks to its design, the decryption algorithm is identical to the encryption algorithm - the only alteration that is made, is that to decrypt DES ciphertext, the subsets of the key used in each round are used in reverse, i.e. the 16th subset used first.
Security of DES:
Unfortunately, with advances in the field of cryptanalysis and the huge increase in available computing power, DES is no longer considered to be very secure. There are algorithms that can be used to reduce the number of keys that need to be checked, but even using a straightforward brute-force attack and just trying every single possible key there are computers that can crack DES in a matter of minutes. It is rumoured that the US National Security Agency (NSA) can crack a DES encrypted message in 3-15 minutes (Ref. 3).

If a time limit of 2 hours to crack a DES encrypted file is set, then you have to check all possible keys (2^56) in two hours, which is roughly 5 trillion keys per second. Whilst this may seem like a huge number, consider that a $10 Application-Specific Integrated Circuits (ASICs) chip can test 200 million keys per second, and many of these can be paralleled together (Ref. 2). It is suggested that a $10 million investment in ASICs would allow a computer to be built that would be capable of breaking a DES encrypted message in 6 minutes (Ref. 2).

It is the conclusion of this author that DES can no longer be considered a sufficiently secure algorithm. If a DES-encrypted message can be broken in minutes by supercomputers today, then the rapidly increasing power of computers means that it will be a trivial matter to break DES encryption in the future (when a message encrypted today may still need to be secure).

4.2 - IDEA

IDEA was created in its first form by Xuejia Lai and James Massey in 1990, this was called the Proposed Encryption Standard (PES). In 1991, Lai and Massey strengthened the algorithm against differential cryptanalysis and called the result Improved PES (IPES). The name of IPES was changed to International Data Encryption Algorithm (IDEA) in 1992.IDEA is a symmetric, block-cipher algorithm with a key length of 128 bits, a block size of 64 bits, and as with DES, the same algorithm provides encryption and decryption.

IDEA consists of 8 rounds using 52 subkeys. Each round uses six subkeys, with the remaining four being used for the output transformation.

The subkeys are created as follows:
Firstly the 128-bit key is divided into eight 16-bit keys to provide the first eight subkeys. The bits of the original key are then shifted 25 bits to the left, and then it is again split into eight subkeys. This shifting and then splitting is repeated until all 52 subkeys (SK1-SK52) have been created. (Ref. 5)

The 64-bit plaintext block is firstly split into four (B1-B4), a round then consists of the following steps:

(OB stands for output block)

OB1 = B1 * SK1 (multiply 1st sub-block with 1st
subkey)
OB2 = B2 + SK2 (add 2nd sub-block to 2nd subkey)
OB3 = B3 + SK3
OB4 = B4 * SK4 (multiply 3rd sub-block with 3rd subkey)
OB5 = OB1 XOR OB3 ( XOR results of steps 1 and 3)
OB6 = OB2 XOR OB4
OB7 = OB5 * SK5 (multiply result of step 5 with 5th subkey)
OB8 = OB6 + OB7 (add results of steps 5 and 7)
OB9 = OB8 * SK6 (multiply result of step 8 with 6th subkey)
OB10 = OB7 + OB9
OB11 = OB1 XOR OB9 (XOR results of steps 1 and 9)
OB12 = OB3 XOR OB9
OB13 = OB2 XOR OB10
OB14 = OB4 XOR OB10
The input to the next round, is the four sub-blocks OB11, OB13, OB12, OB14 in that order.

After the eighth round, the four final output blocks (F1-F4) are used in a final transformation to produce four sub-blocks of ciphertext (C1-C4) that are then rejoined to form the final 64-bit block of ciphertext.

C1 = F1 * SK49
C2 = F2 + SK50
C3 = F3 + SK51
C4 = F4 * SK52
Ciphertext = C1 & C2 & C3 & C4.
Security of IDEA:
Not only is IDEA approximately twice as fast as DES, but it is also considerably more secure. Using a brute-force approach, there are 2^128 possible keys. If a billion chips that could each test 1 billion keys a second were used to try and crack an IDEA-encrypted message, it would take them 10^13 years which is considerably longer than the age of the universe (Ref. 3). Being a fairly new algorithm, it is possible a better attack than brute-force will be found, which, when coupled with much more powerful machines in the future may be able to crack a message. However for a long way into the future, IDEA seems to be an extremely secure cipher.

4.3 - RSA

RSA, named after its three creators - Rivest, Shamir and Adleman, was the first effective public-key algorithm, and for years has withstood intense scrutiny by cryptanalysts all over the world.

Unlike symmetric key algorithms, where, as long as one presumes that an algorithm is not flawed, the security relies on having to try all possible keys, public-key algorithms rely on it being computationally unfeasible to recover the private key from the public key.

RSA relies on the fact that it is easy to multiply two large prime numbers together, but extremely hard (i.e. time consuming) to factor them back from the result (Ref. 6).

Factoring a number means finding its prime factors, which are the prime numbers that need to be multiplied together in order to produce that number. For example:

10 = 2 * 5
60 = 2 * 2 * 3 * 5
2^113 - 1 = 3391 * 23279 * 65993 * 1868569 * 1066818132868207
The algorithm:
Two very large prime numbers, normally of equal length, are randomly chosen then multiplied together.

N = A*B

T = (A-1) * (B-1)

A third number is then also chosen randomly as the public key (E) such that it has no common factors (i.e. is relatively prime) with T. The private key (D) is then:

D = E^-1 mod T

To encrypt a block of plaintext (M) into ciphertext (C):

C = M^E mod N

To decrypt:

M = C^D mod N

As an example:

1st prime (A) = 37

2nd prime (B) = 23

So,

N= 37*23 = 851

T = (37 - 1)*(23 - 1) = 36 * 23 = 792

E must have no factors other than 1 in common with 792.

E (public key) could be 5.

D (private key) = 5^-1 mod 792 = 317

To encrypt a message (M) of the character ‘G’:

If G is represented as 7 (7th letter in alphabet), then M= 7.

C (ciphertext) = 7^5 mod 851 = 638

To decrypt:

M = 638^317 mod 851 = 7

Security of RSA:
At this time, no more efficient method of cracking RSA is known than simply factoring N. An eavesdropper would have C and E, and so by factoring N could get M. Whilst computational speeds obviously affects how long it would take to factor N, the main determinant that is changing is mathematical theory. New, faster/better, methods for factoring numbers are constantly being devised, the current best for long numbers being the Number Field Sieve (Ref. 3). Prime Numbers of a length that was unimaginable a mere decade ago are now factored easily. Obviously the longer N is, the harder it is to factor, and so the better the security of RSA. Currently the longest decimal number to be factored is 130 digits, achieved in 1996 (Ref. 2). As theory and computers improve, so larger and larger keys will have to be used. The disadvantage in using extremely long keys is the computational overhead involved in encryption/decryption. This will only become a problem if a new factoring technique emerges that requires keys of such lengths to be used that necessary key length increases much faster than the increasing average speed of computers utilising the RSA algorithm.

Given that RSA has undergone so much scrutiny by cryptanalysts, the algorithm would seem to be secure, this means that RSA’s future security probably relies solely on advances in factoring techniques. It is recommended that, barring an astronomical increase in the efficiency of factoring techniques, or available computing power , a 2048-bit key will ensure very secure protection into the foreseeable future. For instance an Intel Paragon can achieve 50,000 mips (million operations per second), it would take a million of these six billion years to factor a 2048-bit key using current techniques. (Ref. 2)

4.4 Hybrid cryptography systems:

Even without using huge keys RSA is about 1000 times slower to encrypt/decrypt than DES, this has resulted in it not being widely used as a stand-alone cryptography system. However, it is used in many hybrid cryptosystems such as PGP. The basic principle of hybrid systems is to encrypt plaintext with a symmetric algorithm (usually DES or IDEA); the symmetric algorithm’s key is then itself encrypted with a public-key algorithm such as RSA. The RSA-encrypted key and symmetric algorithm-encrypted message are then sent to the recipient, who uses his private RSA key to decrypt the symmetric algorithm’s key, and then that key to decrypt the message. This is considerably faster than using RSA throughout, and allows a different symmetric key to be used each time, considerably enhancing the security of the symmetric algorithm.

4.4.1 - Digital signing:

A disadvantage of public-key cryptography is that anyone can send you a message using your public key, it is then necessary to prove that this message came from who it claims to have been sent by. A message encrypted by someone’s private key, can be decrypted by anyone with their public key. This means that if the sender encrypted a message with his private key, and then encrypted the resulting ciphertext with the recipient’s public key, the recipient would be able to decrypt the message with first their private key, and then the sender’s public key, thus recovering the message and proving it came from the correct sender.

This process is very time-consuming, and therefore rarely used. A much more common method of digitally signing a message is using a method called one-way hashing.

4.4.2 - One-way Hashing:

A one-way hash function is a mathematical function that takes a message string of any length (pre-string) and returns a smaller fixed-length string (hash value). These functions are designed in such a way that not only is it very difficult to deduce the message from its hashed version, but also that even given that all hashes are a certain length, it is extremely hard to find two messages that hash to the same value. In fact to find two messages with the same hash from a 128-bit hash function, 2^64 hashes would have to be tried. In other words, the hash value of a file is a small unique ‘fingerprint’.

H= hash value, f= hash function, M= original message/pre-string

H = f(M)

If you know M then H is easy to compute. However knowing H and f, it is not easy to compute M, and is hopefully computationally unfeasible.

As long as there is a low risk of collision (i.e. 2 messages hashing to the same value), and the hash is very hard to reverse, then a one-way hash function proves extremely useful for a number of aspects of cryptography.

If you one-way hash a message, the result will be a much shorter but still unique (at least statistically) number. This can be used as proof of ownership of a message without having to reveal the contents of the actual message. For instance rather than keeping a database of copyrighted documents, if just the hash values of each document were stored, then not only would this save a lot of space, but it would also provide a great deal of security. If copyright then needs to be proved, the owner could produce the original document and prove it hashes to that value.

Hash-functions can also be used to prove that no changes have been made to a file, as adding even one character to a file would completely change its hash value.

By far the most common use of hash functions is to digitally sign messages. The sender performs a one-way hash on the plaintext message, encrypts it with his private key and then encrypts both with the recipients public key and sends in the usual way. On decrypting the ciphertext, the recipient can use the sender’s public key to decrypt the hash value, he can then perform a one-way hash himself on the plaintext message, and check this with the one he has received. If the hash values are identical, the recipient knows not only that the message came from the correct sender, as it used their private key to encrypt the hash, but also that the plaintext message is completely authentic as it hashes to the same value.

The above method is greatly preferable to encrypting the whole message with a private key, as the hash of a message will normally be considerably smaller than the message itself. This means that it will not significantly slow down the decryption process in the same way that decrypting the entire message with the sender’s public key, and then decrypting it again with the recipient’s private key would.

The PGP system uses the MD5 hash function (Ref. 8) for precisely this purpose.


5.0 - Conclusions:

There is a place for both symmetric and public-key algorithms in modern cryptography. Hybrid cryptosystems successfully combine aspects of both and seem to be secure and fast. While PGP and its complex protocols are designed with the Internet community in mind, it should be obvious that the encryption behind it is very strong and could be adapted to suit many applications. There may well still be instances when a simple algorithm is necessary, and with the security provided by algorithms like IDEA, there is absolutely no reason think of these as significantly less secure.

An article posted on the Internet I once read, on the subject of picking locks, stated:

"The most effective door opening tool in any burglars toolkit remains the crowbar".

This also applies to cryptanalysis - direct action is often the most effective. It is all very well transmitting your messages with 128-bit IDEA encryption, but if all that is necessary to obtain that key is to walk up to one of the computers involved with a floppy disk then the whole point of encryption is negated. In other words, an incredibly strong algorithm is not sufficient. For a system to be effective there must be effective management protocols involved.


References and Bibliography:

  1. Johnson, N., Steganography, http://patriot.net/~johnson/html/neil/stegdoc/stegdoc.html
  2. Heath, J.. Survey: Corporate uses of Cryptography, http://www.iinet.net.au/~heath /crypto.html
  3. Schneier, B., Applied Cryptography Second Edition: protocols, algorithms, and source code in C, John Wiley & Sons, 1996, pp758.
  4. Mayo, S., How PGP works and the maths behind RSA, http://rschp2.anu.edu.au:8080/h owpgp.html
  5. Mayo, S., The IDEA Algorithm, http://rschp2.anu.edu.au:8080/ide a.html
  6. Sullivan, C., Makmur, M., RSA Algorithm Javascript, http://www.engr.orst.edu/~mak mur/HCproject/
  7. Dunlap, C., Programmers Crack RSA Encryption Code, http://www.techweb. com/wire/news/1997/10/1025rsa.html
  8. Rivest, R.L., The MD5 Message Digest Algorithm, RFC 1320, April 1992.

Tuesday, September 1, 2009

Ukhti, Ketahuilah Hukum Agamamu....

Ukhti muslimah …
Kehidupan itu tidak bisa diduga dan ajal kematian tidak diketahui. Tapi hidup pasti ada ujungnya. Apa yang mungkin ukhti kerjakan hari ini belum tentu bisa ukhti kerjakan esok hari.
Ketahuilah. Hari ini adalah waktu beramal, bukan waktu hisab. Dan esok adalah waktu hisab, bukan waktu beramal.

Sesungguhnya kesempatan hari ini jika tidak dimanfaatkan sebaik-baiknya belum tentu besok terulang kembali. Tidak pada setiap waktu dan kesempatan tersedia peluang untuk berbuat kebaikan. Maka jika memungkinkan, bersegeralah memanfaatkannya dan takutlah jika kesempatan itu lenyap dan engkau tidak memiliki kesempatan untuk kedua kali.

Ukhti muslimah …
Berbekallah dengan ketaqwaan. Karena engkau tidak tahu jika malam datang apakah engkau masih hidup saat fajar menjelang. Engkau tidak tahu apakah kehidupan kita berakhir dengan baik (husnul khotimah) ataukah sebaliknya. Engkau tidak tahu apakah mudah pertanggungjawaban amal kita di hadapan Allah ataukah sebaliknya.

Ketahuilah ukhti...,

bahwa sebaik-baik jalan yang bisa mengantarkanmu kepada kebahagiaan dan ketenangan di dunia, keselamatan dan keberuntungan di akhirat adalah ketaatan kepada Allah dan Rasul-Nya shallallahu ‘alaihi wa sallam.
Allah berfirman, yang artinya, “Dan barang siapa menaati Allah dan Rasul-Nya, maka sesungguhnya ia telah mendapatkan kemenangan yang besar.” (Qs. Al Ahzab: 71)


Tahukah ukhti di mana engkau bisa meraih jalan ketaatan yang benar dan diridhai Allah? Iaitu dengan menuntut ilmu syar’i. Bersegeralah meraih keselamatan dan disitulah keberuntunganmu. Bersegeralah menuntut ilmu syar’i ….

Ukhti muslimah...,
Sesungguhnya di antara kebaikan keislaman seorang wanita adalah mengetahui agamanya. Maka Islam mewajibkan para wanita mencari ilmu sebagaimana yang diwajibkan terhadap kaum laki-laki.

" Mencari ilmu itu fardhu (wajib) atas setiap muslim.” (HR Ahmad dan Ibnu Majah)
Perhatikanlah firman Allah, yang artinya,

“Adakah sama orang-orang yang mengetahui dengan orang-orang yang tidak mengetahui” (Qs. Az Zumar: 9)"

Allah akan meninggikan orang-orang yang beriman di antara kalian dan orang-orang yang diberi ilmu pengetahuan beberapa derajat.” (Qs. Mujadillah: 11)

Rasulullah shallallahu ‘alaihi wa sallam bersabda,
“Barang siapa meniti suatu jalan untuk mencari ilmu, maka Allah mudahkan baginya jalan menuju surga.” (HR. Muslim)

“Sesungguhnya para malaikat benar-benar meletakkan sayapnya kepada orang yang mencari ilmu, karena ridha terhadap apa yang dicarinya.” (HR. Ahmad dan Ibnu Majah)

“Barang siapa yang Allah kehendaki kebaikan pada dirinya, maka Allah pahamkan dia tentang masalah agama.” (HR. Bukhari Muslim)

Ukhti muslimah…
Jangan lagi menunda-nunda untuk mengerjakan perintah Allah. Jangan menunda-nunda untuk menuntut ilmu syar’i. Karena sungguh kita tidak tahu kapan nafas ini berhenti… dan bila ajal benar-benar menjemput kita saat ini juga, dengan hati yang bagaimanakah kita menghadap Allah… dengan amal yang manakah kita memohon keselamatan dari adzab-Nya…Ukhti, bersegeralah…