Symmetric Cryptosystems
Symmetric cryptosystems use the same key material for all operations (that is, the same key to encrypt and decrypt). Symmetric cryptosystems include symmetric encryption and message authentication with the help of hashes.
Symmetric Encryption
Symmetric encryption occurs when the same key is used for both encryption and decryption, as Figure 1-5 shows. This key is called the shared key or session key.
Figure 1-5 Symmetric Encryption
|
Plaintext: |
Encryption |
Ciphertext: |
Decryption |
Plaintext: |
||||
|
Hello |
%z$*@ |
Hello |
Networks use multiple symmetric encryption algorithms: the more recent Advanced
Encryption Standard (AES), the older Data Encryption Standard (DES), or RC4.
Because all entities must use the same shared key, secure key distribution is required.
Indeed, if the shared key is compromised, confidentiality no longer exists.
Key distribution can happen in two ways:
• Out of band. Where the key is secretly sent outside the channel used for data communication (for example, it's sent by post or transmitted by fax).
• In band. Where the key is secretly transferred within the same channel used by the encrypted data. Multiple secure key-distribution algorithms exist: Diffie-Hellman (DH) used by IPsec, Microsoft Challenge Handshake Authentication Protocol version 2 (MS-CHAPv2), Transport Layer Security (TLS), and so on. For security purposes, they are often combined with authentication.
Hashing Functions
Encryption is not the only purpose of symmetric cryptosystems; they can also check data origin. Figure 1-6 depicts another symmetric cryptosystem: the cryptographic hashing function. This is a mathematical function applied to a long data block, and the result is a small piece of data—typically, only 128 or 196 bits.
The cryptographic hash function must have specific properties:
• A change of a single bit in the input must result in a completely different hash.
• From the hash, it must be impossible to compute back the original input.
Hash Message Authentication Code
Cryptographic hash functions can be used for message data-origin validation (sometimes called authentication) when combined with a shared key, as Figure 1-7 shows. This is called Hash-based Message Authentication Code (HMAC). The underlying reasoning is that only the entities that know the shared key can generate HMAC; no other parties can generate it. Therefore, this proves that the message has been originated by an entity who has access to the shared key.
Figure 1-7 HMAC
Shared key
Hash Function
Hash Function
The message's originator computes the hash value of the concatenation of the shared key and the message. This hash is then transmitted together with the message to all recipients.
The recipients simply execute the same computation and compare the computed hash against the received one. If they match, this proves
• Integrity. If the message was changed during transmission, the cryptographic hash value would differ.
• Data origin (authentication). Without possession of the secret key, no one else would be able to compute the cryptographic hash before transmission.
This is not a digital signature. Any owner of the shared key can compute the hash. So, all the key owners can pretend that another owner has computed the hash. This means that everyone can repudiate a message that he originated, even if he computed the cryptographic hash. To have a digital signature, no one should be able to repudiate a message that he originated. (This is nonrepudiation, which the next section describes.)
Continue reading here: Ethernet Frame Formats
Was this article helpful?