Afrikaans
Akan
Albanian
Amharic
Arabic
Armenian
Azerbaijani
Basque
Belarusian
Bemba
Bengali
Bihari
Bosnian
Breton
Bulgarian
Cambodian
Catalan
Cebuano
Cherokee
Chichewa
Chinese (Simplified)
Chinese (Traditional)
Corsican
Croatian
Czech
Danish
Dutch
English
Esperanto
Estonian
Ewe
Faroese
Filipino
Finnish
French
Frisian
Ga
Galician
Georgian
German
Greek
Guarani
Gujarati
Haitian Creole
Hausa
Hawaiian
Hebrew
Hindi
Hmong
Hungarian
Icelandic
Igbo
Indonesian
Interlingua
Irish
Italian
Japanese
Javanese
Kannada
Kazakh
Kinyarwanda
Kirundi
Kongo
Korean
Krio (Sierra Leone)
Kurdish
Kurdish (Soranî)
Kyrgyz
Laothian
Latin
Latvian
Lingala
Lithuanian
Lozi
Luganda
Luo
Luxembourgish
Macedonian
Malagasy
Malay
Malayalam
Maltese
Maori
Marathi
Mauritian Creole
Moldavian
Mongolian
Myanmar (Burmese)
Montenegrin
Nepali
Nigerian Pidgin
Northern Sotho
Norwegian
Norwegian (Nynorsk)
Occitan
Oriya
Oromo
Pashto
Persian
Polish
Portuguese (Brazil)
Portuguese (Portugal)
Punjabi
Quechua
Romanian
Romansh
Runyakitara
Russian
Samoan
Scots Gaelic
Serbian
Serbo-Croatian
Sesotho
Setswana
Seychellois Creole
Shona
Sindhi
Sinhalese
Slovak
Slovenian
Somali
Spanish (Latin American)
Sundanese
Swahili
Swedish
Tajik
Tamil
Tatar
Telugu
Thai
Tigrinya
Tonga
Tshiluba
Tumbuka
Turkish
Turkmen
Twi
Uighur
Ukrainian
Urdu
Uzbek
Vietnamese
Welsh
Wolof
Xhosa
Yiddish
Yoruba
Zulu
Welcome to our lecture on cryptography, if you want to be a good cybersecurity specialist, you must
have a good understanding of the fundamental concepts involved in cryptography.
Cryptography is the study and application of methods and techniques to protect information by using codes
for secure communication.
So the bottom line in cryptography is to ensure secure communication between two parties.
Cryptography is broadly categorized into two main categories, symmetric and asymmetric.
We are going to start with symmetric encryption concepts.
Symmetric encryption is also called private-key encryption, and it uses the same key for encryption
as well as decryption, and that is why it is called symmetric, because the same key is used both
at the source and at the destination.
It also uses the same cipher.
Cipher is a word which is an alternate for algorithms, is used for encryption and decryption.
So the same algorithm is used at the source for encrypting data and the same algorithm is used at the
destination for decrypting the data. Now key lengths determine the strength of encryption.
And usually the longer the better.
Some popular private key ciphers include AES, RC5 and TwoFish.
Let's have a look at how symmetric encryption actually works.
So we have a source which wants to send data to a destination and it wants to encrypt the data before
sending it.
So at the source, we have a plain text file, which means it is an encrypted text and anybody can read
it.
So basically, we use a key, which is kind of a secret code which helps us encode this plaintext.
In addition to the key, we need an algorithm which is basically going to take the key and the plaintext
data and it's going to do some steps, some operations in order to provide us with the ciphertext,
which is basically the encrypted text.
So using the key and the algorithm with plain text as the input, we get a ciphertext as output and
this completes the encryption part.
Now, the basic aim of encryption was so that we could transmit data over the public Internet without
compromising its confidentiality.
So that's exactly what we did.
We converted plaintext into ciphertext and then the ciphertext, which is basically encrypted data.
And even if somebody gets a copy of it while it is flowing over the Internet, they would still not
be able to easily break it because it's encrypted.
Now at the destination, the destination has received a cipher text, which is encrypted text, and
the process now needs to be reversed.
So at the destination, it needs to use exactly the same key which was used to encrypt the data.
Consider it exactly like a numbered lock.
So you really need to line up exactly those same numbers if you want to unlock it.
So using the exact same key and using the exact same algorithm, we can decrypt this data so we can
work the ciphertext back into plain text.
And this is called the decryption.
And this is how the source is able to encrypt plaintext data into ciphertext transmitted over the Internet.
And then the destination is able to get back to plain text from the ciphertext.
Perhaps the single most important factor which can determine the strength of encryption is the key length.
The longer the key, the better.
So let's say you have a password with X number of characters for every character you can select, either
from A to Z, which are basically 26 different alphabet or digits 0-9 which are ten. So
26 + 10 = 36 possibilities for each of these cells or each of these characters.
But computers, they need digital numbers, they understand binary numbers.
So we always talk about bits.
So we talk about key lengths in terms of bits. Since we're talking about binary,
so every cell or every bit can either be 0 or it can be 1.
So if you have a key which spans n-bits, then it means you have 2 raised to the power n different
combinations possible.
Let's have a look at the comparison table, which shows us how increasing key lengths make breaking encryption
difficult.
So let's say if you are selecting a key length of 56-bits, which means that you have to 2 raised to the
power 56 different combinations, and using a good state of the art computer, you can break it in 20
hours.
But if you increase the key length to 128, the possible combinations now jump to 2 raised to the
power 128 and it would take 5 x 10 raised to the power 17 years to break it using the same computer,
and say if you increase the key length to 256 bits, then you have 2 raised to the power 256
different combinations, which would take 7 x 10, raised to the power 56 years.
So nearly impossible to break.
So the bottom line that we need to understand is that it is always advisable and in fact recommended
to use long key lengths.
A very popular and state of the art symmetric encryption scheme is AES - advanced encryption standard.
It is so strong that it is even acceptable for military purposes.
AES offers various key lengths, starting from 128, 192 up to 256 bits. The key determines the strength
of the encryption.
So obviously AES-256 would be considered stronger compared to a AES-192, for instance.
AES has several implementations and it's widely adopted in the industry and it is used in a large
number of applications. In contrast to symmetric encryption,
we also have another type of encryption, which is asymmetric encryption, also known as public key
cryptography.
Now, the main difference between asymmetric and asymmetric is that in symmetric encryption, both the
sender and the receiver used the same secret key.
But the problem with those type of encryption is that let's say you want to communicate with 100 different
people, then obviously you need to have 100 different private keys and it becomes difficult to scale
it, right?
So the solution to that is public-key cryptography.
So what happens in public cryptography is that let's say you have a plain text document.
So what you're going to do is that you're going to use the public key of the destination.
So the destination, let's say it's a server.
It has shared its public key, you know, which is known to everyone in the world.
And you basically encrypt your document using this public key.
Right?
So now the thing is that with asymmetric encryption, anything that has been encrypted with the public key,
it can only be decrypted by a private key, which is secret.
Right.
So it's like asymmetric.
You're not using the same key for encryption and decryption.
You're using two different keys.
So if you want to send a message to a destination, which you want to make sure that it's encrypted,
you need to encrypt it using the public key of the destination and then send this message over the Internet.
So even if somebody eavesdrops, you know, on this message right here, it's not a problem.
So at the destination, the destination is going to use its private key.
Now, this one is secret.
And it is only known to this, you know, the destination.
And once it basically decrypts this.
So basically we have completed the decryption part of the process.
Now, a couple of points to keep in mind.
The first being that you cannot decrypt a message or a file that has been encrypted using a public key,
using the public key again.
So it only works with public key encryption, decryption with private key, and vice versa.
Right? now, another important point, which I want to clarify, which confuses a lot of people, is
that so let's see what happens if we go the other way around.
So, for example, if the destination encrypts a document using his private key then it is not basically encrypting
it for the sake of secrecy, because everybody in the world, they have the public key and they can
simply decrypt it.
Right? In this case, what we call this is called digitally signing the document, which basically means
that this guy is making sure that if I encrypt a document using my private key, then only my public
key can be used to decrypt it.
So it's just sort of an assurance that this was, you know, signed by me.
So this document is really coming from me.
Now, that's what we call digital signatures.
So in a nutshell, just to reiterate, in public key cryptography or asymmetric cryptography, if you
want to ensure confidentiality, then you'll be using the public key of the destination to encrypt the
message which the destination can then decrypt using his private key.
And these two keys are different.
You won't be able to decrypt a message which has been encrypted to the public using the public key again.
Right.
So that ensures confidentiality.
But if the flow is the other way around, if this destination is encrypting a document using the private
key, then it just means that he's making sure that, you know, telling people that I have signed this
document because everybody can decrypt this document using the public key.
This is public knowledge.
Right?
So in this case, we're not talking about confidentiality or secrecy.
Now, a couple of important points, which I would like to reiterate.
The first is that if you want to ensure confidentiality, so basically what you need to do is that you
need to encrypt the data using the public key of the destination or the receiver.
And at the receiving end, the receiver is going to use the secret private key for decrypting the data.
And please keep in mind, the private key is completely different from the public.
Now the point that we're trying to make is that the data that has been encrypted by public key cannot
be
decrypted with the public, and it must use the private key at the destination for decryption.
Now, on the other hand, if a sender is using his private key to encrypt something, then it's not
really for secrecy because, you know, everybody in the world has the public key and they can simply
decrypt it. In that sense,
it is just digitally signing a document, which basically means that the sender is saying that,
OK, here is this document.
I have encrypted completely, you know, full document or maybe a small part of it and add to basically
general public and simply use the public key of that sender and then decrypt or, you know, check whether
this document actually came from the sender or not.
The point being that only his public key can be used to decrypt this document, not somebody else's.
So that's the key point to understand.
The magic is basically in special mathematical operations, which allow the use of two different types
of keys.
So basically the difference between asymmetric and asymmetric being that in symmetric we have exactly
the same key at both the sender and the receiver.
However, in asymmetric encryption, we're basically using two different keys.
So one of the reasons why we needed asymmetric encryption was because private keys cannot always be
safely exchanged on public networks like the Internet.
So asymmetric encryption is required to create that initial trust, the initial encrypted end to end
communication channel over which you can even exchange symmetric keys and then use them later on for
encryption or decryption.
But for the initial secure and encrypted channel, you definitely need asymmetric encryption.
Another reason why you may want to consider asymmetric encryption is because symmetric keys are not
really scalable.
So imagine if you are a user and you want to communicate with different entities, so you'll be requiring
n different symmetric keys if you're using asymmetric encryption because you need a different key
for it, one communication for it, or two you need a different key and so on.
And so if you're talking to ten people, you need and different symmetric keys.
So imagine if you want to communicate with thousands of different servers, you'll need thousands of
different keys.
So it is obviously not a scalable solution.
Now, contrast that with asymmetric encryption.
So if you're using asymmetric, you just need 2 keys and that's it.
So one is the private key, which would be used by A.
And the second is the public key, which is published to all the users.
And it is public.
Some popular asymmetric solutions include the Diffie-Hellman, which is used for key exchange between two
entities.
We also have RSA, which is used for actual encryption or decryption, and we have ECC,
which is again used for actual encryption and decryption.
And there are several others available as well.
A quick recap on the differences between asymmetric and asymmetric encryption, so in symmetric encryption,
we always use the same key for encryption as well as for decryption.
But in asymmetric encryption, we use different keys, private and public.
And symmetric encryption, encryption and decryption algorithms or ciphers are exactly the same,
but in asymmetric encryption, we have different encryption and decryption algorithms because we are
using different keys for encryption and for decryption.
A major problem with symmetric encryption is that it is not always possible to exchange keys safely
because to start the encryption process, the two ends need to have the same key and there is no way
to exchange these keys without incurring some sort of risk.
In contrast, asymmetric encryption can be done on public networks.
In fact, it is designed for communication over public networks.
One advantage of symmetric encryption is that it's very fast, whereas asymmetric encryption is slow
and one of the reasons is because it's using different encryption and decryption techniques.
Now, systematic encryption is very fast, so what we normally do is that we create the initial secure
channel using asymmetric encryption, but once that is in place, we exchange symmetric keys or session
keys and then we use symmetric encryption for quick and efficient encryption, decryption of data at
the two ends.
But for the initial establishment of the trust of the secure channel, we use asymmetric encryption.
And then within that tunnel or within that channel, we can exchange symmetric keys as well.
Another difference between the two encryption schemes is that for offering the same strength, symmetric
encryption requires smaller key lengths compared to asymmetric encryption.
And this stems from the fact that asymmetric encryption is designed to allow for two different keys
to encrypt and decrypt.
So that's why we generally need longer keys in asymmetric encryption in order to provide the same level
of safety as asymmetric encryption.
So that concludes our lecture.
I'll see you in the next one.
Can't find what you're looking for?
Get subtitles in any language from opensubtitles.com, and translate them here.